Quickstart¶
Install the CLI and run the local smoke path.
Install¶
Requires Go 1.25+.
go install github.com/fulcrum-governance/fulcrum-boundary/cmd/boundary@v0.13.1
boundary selftest
boundary demo github-lethal-trifecta
boundary demo command-secret-exfil
boundary test --path tests/fixtures/policy-test/cases
v0.13.1 is the current published release. Its prebuilt channels were produced
by the tag-gated release pipeline: the Homebrew cask
(brew install fulcrum-governance/tap/boundary, macOS only), release archives
verified against SHA256SUMS, and the container image
(ghcr.io/fulcrum-governance/boundary:v0.13.1). On
Linux and Windows, use a release archive or the container image — Homebrew
casks install only on macOS.
See the canonical
Install
guide before choosing static versus cgo builds.
Expected MCP demo success signal:
actual action: DENY
reason: lethal_trifecta_detected
upstream_called=false
Expected Command Boundary demo success signal:
actual: DENY
executed=false
class=C6
No credentials are required. The selftest and demo use fixture data and do not perform live calls or real system mutation.
Boundary governs actions only when the route is forced through Boundary.
boundary test is the local developer-trust step: it evaluates local policy
bundles against routed request fixtures and exits non-zero on unexpected
verdicts. It is included in the published v0.13.1 release. See
Policy Testing.
From Source¶
git clone https://github.com/Fulcrum-Governance/Fulcrum-Boundary.git
cd Fulcrum-Boundary
go run ./cmd/boundary selftest
go run ./cmd/boundary demo github-lethal-trifecta
go run ./cmd/boundary demo command-secret-exfil
go run ./cmd/boundary test --path tests/fixtures/policy-test/cases
Useful Local Gates¶
make selftest
make demo-github
make release-check