Building patterns for a vault standard on the Canton Network, written in Daml.
These reference implementations are extracted from the on-ledger core of VaultKit, a vault product operated by Moonsong Labs. This repository implements each as a separate, tested Daml package so the design can inspire vault standards and implementations on Canton.
Each directory under patterns/ holds a pattern's packages, tests, and README
with the problem, parties, contracts, and invariants.
| Pattern | Description |
|---|---|
vault-access |
A general KYB attestation and per-vault permission, each revocable by the manager. The permission's Deposit choice validates access and holdings, opens a token-standard allocation, and creates the deposit request in one transaction. |
pluggable-component |
A Daml interface with an abstract function that a host contract calls without knowing which template implements it, so behavior can be swapped without redeploying the host. Fee models (IFee) are the worked example. |
public-private-split |
A public-private DAR file split for logic that must stay private or changes often. Three layers with one dependency direction: interface, public, and private. Counterparties vet the interface and public packages; the manager vets all three. Private changes never touch the public layer. Comes with a two-participant sandbox (make sandbox-public-private). |
Patterns are not audited and intended as design references only. Each one showcases a single design solution on its own.
vault-example/ is a vault demo based on VaultKit
that shows the patterns above working together. It composes access control,
pluggable components, and the public-private split into one deposit,
investment, valuation, and redemption flow.
Daml SDK 3.5.2 through dpm.
make build
make testFor one pattern, use make build-<pattern_folder> or
make test-<pattern_folder>, including the folder's numeric prefix:
make build-01-vault-access
make test-03-public-private-splitEach build includes the selected pattern's production packages. Each test
command builds those packages first and runs the selected pattern's tests.
Patterns are self-contained. make build and make test cover all patterns
and the vault example. To run only the example:
make build-vault-example
make test-vault-examplemake sandbox-public-private runs the two-participant demo from the
public-private-split pattern. CI runs the same check with make sandbox-smoke.
It needs Java 17 or newer and a Canton 3.5 runtime JAR; see the
pattern's README.
Without a local SDK, the Dockerfile provides the toolchain:
docker build -t canton-vaults-dev .
docker run --rm -v "$PWD":/workspace -w /workspace canton-vaults-dev make build testMIT. See LICENSE.
