Skip to content
filpgf.io Kernel
Kernel · Program overview

What keeps the network running.

Kernel funds the functions Filecoin depends on to keep producing blocks, proving storage, and staying observable. It is treated as a near-fixed cost rather than a growth bet: the goal is not more features, it is that nothing essential quietly stops being maintained.

Tier Functions SLA met · 90d Funding posture

Irreplaceable

Only provider. Network halts without it. No substitute exists.

5

4 listed

96.3%

3 measured

Must fund — non-negotiable

Essential

Network-critical, but alternatives exist. We need at least one.

24

14 listed

96.0%

13 measured

Fund for redundancy — 2+ implementations

Important

Load-bearing. Multiple dependents. Silent failure cascades.

Pending

Not yet inventoried

No data

Fund maintenance, not features

Nice to have

Enriches the ecosystem. Network survives without it.

Pending

Not yet inventoried

No data

Discretionary
Objective

Keep the floor from moving

Most of what Filecoin runs on is maintained by small teams, and much of it has no second implementation. When one of those goes unfunded, nothing breaks on the day it happens — the repo just goes quiet, the maintainer moves on, and the network carries a dependency nobody is watching. Kernel exists to make that failure mode visible and to pay for it not to happen.

The program starts from a map, not a wishlist. Every capability the network needs is written down as a function, independent of which repo currently provides it. Each function is placed in a tier according to how replaceable it is, and each tier carries a different funding posture — some are non-negotiable, some are funded for redundancy, some are funded only for maintenance.

Funding follows an annual term with audits rather than milestones, because keeping something working is a continuous obligation and not a deliverable. Teams are assessed against agreed metrics for resilience and operational continuity: is the function still healthy, still maintained, still measurable.

Kernel funds

  • Maintenance of functions the network cannot operate without
  • A second implementation where a single one is a systemic risk
  • Monitoring, testnets, and incident response that keep the network observable
  • Security and upgrade work required to stay production-safe

Kernel does not fund

  • New features or product expansion — that is Revenue Development
  • Exploratory or unproven work — that is R&D
  • Functions with no maintainer willing to report health metrics
Timeline

One term, two audits

Kernel grants run on an annual term. Audits fall mid-term and at close, and each one checks the agreed resilience metrics rather than a feature list.

Next round opening

FY27 intake opens October 2026

Applications close in November, awards are published in December, and the new term begins in January. Existing grantees re-apply on the same cycle.

  1. Jan 2026

    FY26 term begins (complete)

  2. Apr 2026

    Mid-term audit cleared (complete)

  3. Aug 2026

    Health reporting continuous (in progress)

  4. Oct 2026

    Close-out audit · FY27 intake opens (upcoming)

  5. Nov 2026

    Applications close (upcoming)

  6. Dec 2026

    Awards published (upcoming)

  7. Jan 2027

    FY27 term begins (upcoming)

Categories

Four tiers, set by what happens without it

A function's tier is decided by substitutability, not by how much anyone likes it. That single judgement then drives how much scrutiny it gets, whether redundancy is required, and how negotiable the budget is.

Irreplaceable

5 functions

Only provider. Network halts without it. No substitute exists.

Ledger, resource, and programmability — what the blockchain and the physical-storage-backed ledger need in order to keep running at all.

Example
Distributed randomness beacon — without it, block production stops.
Posture
Must fund. Non-negotiable security requirements. Audits milestone-gated.

Essential

24 functions

Network-critical, but alternatives exist. We need at least one.

Core offerings — disk space from miners, storage primitives in smart contracts — that let participants engage with the irreplaceable components.

Example
Testnets: the network continues without them, but at least one is needed to stage and rehearse upgrades.
Posture
Fund for diversity that ensures uptime — maintain two or more implementations. Budget negotiable.

Important

inventory pending

Load-bearing. Multiple dependents. Silent failure cascades.

Supports and improves access to the critical components, and speeds up development of revenue-generating work.

Example
A testnet faucet: it makes test FIL easy to get, but the network runs without it.
Posture
Fund maintenance, not features. Flag any repo with zero active developers.

Nice to have

inventory pending

Enriches the ecosystem. Network survives without it.

Initiatives that encourage additional growth, where having even one instance may matter for basic ecosystem support.

Example
F3: the network exists without it, but it improves UX considerably and encourages growth.
Posture
Discretionary. Fund only where aligned with the sustainability strategy.
Terms

What these words mean here

Kernel uses a few words in a specific way. Getting them straight is most of understanding the program.

Kernel
The funding program covering work the network cannot operate without. Funded as a near-fixed cost on an annual term with audits, not against milestones.
Function
A capability the network needs, named by what it does rather than by which repo provides it. Functions outlive implementations — the function survives when the code that serves it is replaced.
Dependency
A library, service, or system a function relies on to work. A dependency with one maintainer and no substitute is a risk to every function above it.
Tier
How replaceable a function is, from Irreplaceable to Nice to have. Tier sets the funding posture and whether redundancy is required.
Health metric
A measurable indicator with an agreed target, reported by the maintaining team. Functions without one cannot be assessed and are marked not measured.
SLA met · 90d
The share of the last 90 days a function's health metrics stayed within target. A rolling window, so it reflects current condition rather than a single check.
Domain
The area of the stack a function sits in — blockchain core and physical storage, coordination and hardening, storage market middleware, UX/DX.
Single maintainer
A function maintained by exactly one team. Tolerable at lower tiers, a named risk at the top two, where the posture calls for two or more independent implementations.