Skip to content

Quickstart

Install the CLI and run the local smoke path.

Install

Requires Go 1.25+.

go install github.com/fulcrum-governance/fulcrum-boundary/cmd/boundary@v0.13.1
boundary selftest
boundary demo github-lethal-trifecta
boundary demo command-secret-exfil
boundary test --path tests/fixtures/policy-test/cases

v0.13.1 is the current published release. Its prebuilt channels were produced by the tag-gated release pipeline: the Homebrew cask (brew install fulcrum-governance/tap/boundary, macOS only), release archives verified against SHA256SUMS, and the container image (ghcr.io/fulcrum-governance/boundary:v0.13.1). On Linux and Windows, use a release archive or the container image — Homebrew casks install only on macOS. See the canonical Install guide before choosing static versus cgo builds.

Expected MCP demo success signal:

actual action: DENY
reason: lethal_trifecta_detected
upstream_called=false

Expected Command Boundary demo success signal:

actual: DENY
executed=false
class=C6

No credentials are required. The selftest and demo use fixture data and do not perform live calls or real system mutation.

Boundary governs actions only when the route is forced through Boundary.

boundary test is the local developer-trust step: it evaluates local policy bundles against routed request fixtures and exits non-zero on unexpected verdicts. It is included in the published v0.13.1 release. See Policy Testing.

From Source

git clone https://github.com/Fulcrum-Governance/Fulcrum-Boundary.git
cd Fulcrum-Boundary
go run ./cmd/boundary selftest
go run ./cmd/boundary demo github-lethal-trifecta
go run ./cmd/boundary demo command-secret-exfil
go run ./cmd/boundary test --path tests/fixtures/policy-test/cases

Useful Local Gates

make selftest
make demo-github
make release-check