SKF Technical Brief

Signal Kernel Frameworks LLC  ·  Technical Brief

Signal Kernel Integrated Framework

On-premises automation for the picture and sound work a facility repeats every day. Five of the eight engines are audio. This is the version written for the person who has to put it on the floor, hand it to operators, and answer for it when a delivery is due.

Platform
Any M-series Mac
Hardware
Yours or supplied
Deployment
On-premises
Network
Air-gap capable
Storage
NFS / SMB / SAN
Install size
20 MB installer
77 MB on disk
Processors
5 audio, 3 picture
Version
3.5.2

01 What it does

It runs the jobs your team currently babysits

Unpack production sound, run the chain, sync it to picture, mix it to spec. Transcode, rescale, sequence, deliver, archive. The work that already happens in your facility, but scheduled across every Mac you own, recovered automatically when something dies, and without a person watching a progress bar to find out whether it worked.

Replaces

  • The watch-folder scripts nobody owns. The ones written by someone who left, that break when a filename has a space in it.
  • Per-seat transcode licensing. Replaced by capacity you size yourself: licensed per node, so what you pay tracks throughput rather than headcount.
  • Cloud transcode spend: compute, egress, and the storage you pay for twice because the media has to be up there to be worked on.
  • Hand-corrected audio, file by file. Applying the same treatment to every take, riding a mix to hit a loudness spec, and unpacking production sound by hand.
  • Per-file picture handwork: normalizing rasters, matching formats, and rebuilding the same deliverable set for every version and destination. The reason someone is in the building at 11pm before an airtime.

Does not replace

  • Your NLE or grading suite. Editors and colorists keep working exactly as they do now.
  • Your MAM or asset database. The SKIF is not the system of record for your media.
  • Your storage. It mounts what you already have. You are not buying a new SAN.
  • Your people. It removes the waiting, not the judgment.
The honest framing

Pipelines rarely fail inside a tool. They fail in the gaps between tools: the handoff, the naming, the "did that render actually finish." The SKIF is the layer that owns the gaps, with defined behavior when something goes wrong at 2am.

02 Where it sits

Between your storage and your deliverables. Nothing else moves.

Media stays on your volumes. The SKIF watches folders you nominate, runs work on machines you own, and writes results to folders you nominate. It adds no transport of its own. It moves no media over the network that your storage was not already moving.

COCKPIT SCHEDULING PROCESSING Operator facing UI Build graphs · Watch every job live live status from every machine, no refresh button Mac Mini #1 schedules + renders Mac Studio #2 renders Macbook Pro #3 renders Job state what ran, what failed, what each machine owns survives any reboot Engines: read and write your volume directly no network access · no credentials · one job each · stopped clean if they hang

Fig. 1:
Adding capacity means adding a Mac.
Existing machines are not reconfigured.

03 The engines

Eight processors, five of them audio

An operator wires these together in the cockpit to build a pipeline. No scripting, no command line, and each engine is a compiled binary that runs one job and exits. Picture has had render farms for twenty years. Audio never got one. That gap is why five of these eight engines are audio, and why most facilities have nothing to compare this half of the system against.

Audio

Picture

Job types you will see in the cockpit

mezz · proxy · rescale · composite · mix · dynamics · sync · print · pack · unpack · rename. The pipeline vocabulary is the same one your team already uses.

04 How work flows

A file lands. A deliverable appears.

Work enters by showing up in a location: a camera offload, a MAM export, an editor's audio stems, a drag from a shuttle drive. Everything after that is automatic.

01Lands A file appears in a workspace on your storage.
02Settles Nothing is touched until the copy has finished growing.
03Checked Anything malformed or unrecognized is set aside before it reaches a processor.
04Matched The workspace tells the system which show it is, and the show's preset says what to make.
05Claimed A machine with spare capacity takes it. Busy machines leave it for a free one.
06Runs Independent steps run at once; dependent steps wait. Progress is live in the cockpit.
07Delivered Output mirrors the input folder structure under the show's delivery location.
08Archived Source moves to its archive location on the policy the show defines. Final Outputs to Archive locations with metadata tagged.

Workspace = show

A workspace is a show. Media that lands in a given workspace gets that show's presets: no separate configuration to keep in sync, and no lookup table for someone to get wrong. Adding a show is adding a workspace.

No half-written deliverables

Output is assembled out of the way and moved into place in one atomic step. Your downstream delivery location never sees a partial file, including when a machine loses power mid-render.

05 Formats & codecs

What it reads and what it writes

No bundled third-party transcoder and no interpreted runtime anywhere in the encode path. That is why the whole system ships as a 20 MB installer, and why ProRes behaves exactly as it does everywhere else on your Macs.

Class Supported Notes
Mastering & delivery video ProRes Proxy · LT · 422 · 422 HQ · 4444 · 4444 XQ · H.264 · HEVC Mezzanine and proxy generation are first-class job types, not a preset trick
Containers .mov · .mp4 · .mxf · .avi · .mkv · .mpg · .mpeg · .webm Read side; delivery targets are set per preset
Camera RAW R3D · BRAW · ARRI (.ari/.arx) · CR2 · CR3 · NEF · ARW · RW2 · DNG RAW paths are gated behind their vendor SDKs and ship disabled. Enable them per site under your own vendor agreements
Stills & sequences EXR · TIFF · JPEG · PNG · HEIC · HEIF · JP2 · AVIF · BMP DPX is not currently supported. Ask us before assuming it, if that is your house interchange format
Audio WAV · BWF · polyphonic WAV · AIFF · FLAC · MP3 · OGG Mono through 5.1. Polywavs are de-interleaved to discrete mono and repacked on demand; WAV is the interchange format between audio engines
Loudness compliance LUFS · LKFS · true peak Measured and corrected inside the mix job, not bolted on as a separate QC pass. Target is set per show, so a European and a US delivery of the same program are two presets rather than two workflows
Production sound metadata iXML track names · BWF bext Carried through unpack and repack rather than dropped, so channel identity survives the trip from the recorder to the dub stage
Color transforms .cube LUTs Dropped into a categorized LUT library and referenced by name from any preset
Bring the awkward media to the pilot

Not the clean media. If there is a house format we do not read, you want to find that out on a Tuesday in your machine room, not in week three of a rollout. We would rather lose a deal in the pilot than in production.

06 When it breaks

It is 5pm. You deliver at 6. A render node dies.

This is the section that matters. Every row is implemented behavior with a bounded detection time. Not a support promise, not a roadmap item. Detection windows are configurable; shipped defaults are shown.

What happens Noticed within What the system does What it costs you
A render machine loses power ≤ 40 s Its work is released and picked up by the other machines automatically Re-render of what was in flight on that box
A render hangs and stops progressing ≤ 135 s Stopped cleanly and requeued. It does not sit at 47% until someone notices One file, re-rendered
A render fails on a bad file Immediately That file is marked failed; every other file in the batch keeps going One file, flagged for a human
The scheduling machine goes down Immediately Another machine takes over scheduling on its own Nothing
Someone cancels a batch mid-render Immediately Processes stopped on whichever machines hold them, partial files cleaned up Nothing
You need to reboot a machine Operator-initiated Drain it. It finishes what it holds, stops taking new work, and exits clean Nothing
The storage mount drops Per operation Affected jobs fail loudly and visibly; other shows keep running Jobs on that volume
A power cut takes the whole room On restart Orphaned processes and partial files are cleaned up; unfinished work is requeued In-flight renders only
Why this holds up

Work assignments are written down, not held in a running program's memory. That is why "a machine vanished" and "a machine was unplugged on purpose" take the same recovery path, the one you exercise every time you drain a node for maintenance. It is not an emergency path that only runs during emergencies.

07 Content security

Pre-release material never leaves the facility

The security question in this industry is not "can it be hacked from the internet."
It is "can I put an unreleased title on it and still pass my client's audit."

Posture

  • No outbound connection, ever. No license check-in, no update fetch, no usage telemetry. The cluster runs on an isolated VLAN with no route out and works normally.
  • No cloud copy of anything. Media is read from and written to your volumes. There is no vendor-side storage for it to be exposed from.
  • Processing engines are locked down. The binaries doing the work have no network capability compiled into them and no access to system credentials.
  • Cluster membership is not open. Joining requires a secret delivered out of band plus explicit roster admission. A machine on the LAN cannot join by guessing a name.
  • Signed and notarized by Apple, running under the hardened runtime, with destructive controls behind an administrator prompt.
  • Every asset is validated at the door and anything malformed is quarantined before an engine opens it.

Stated precisely

  • We do not claim TPN certification. The defensible claim is that the architecture is built around the controls a TPN assessment looks for: isolation, no egress, access control, and an audit trail. We will walk your reviewer through each of them.
  • This is process isolation, not the macOS App Sandbox. Each job owns a process group that is terminated as a unit on timeout, cancel, or supervisor loss, so nothing is left orphaned.
  • Execution never goes through a shell. Engines are invoked with explicit arguments, and there is no interpreted or scripting layer in the execution path.
  • Audio Unit hosting is the one third-party surface, and it is yours. Video transcode loads no external code at all. The audio engines can host Audio Units you have installed, which requires the hardened-runtime relaxations any AU host needs. That component is scoped and documented; the reviewer pack has the exact entitlements.
  • Debug logging passes through a redactor so credentials do not reach disk, and system state is never parsed out of log output.
Assurance activity Result
Network threat review: adversary already on the studio LAN Completed August 2026 across the orchestrator, cockpit, mesh, and bundled database
Path from "on your network, no credentials" into the system None found
Automated test suites across the scheduler and mesh, re-run as part of that review 700 tests passing
For your security reviewer

The full threat-review findings register, the listener and port inventory, and the control-by-control mapping are available under NDA on request. We would rather hand your reviewer the document than have them reconstruct it from a port scan.

08 Storage & network

It mounts what you already have

No new storage tier, no ingest copy, no proprietary volume format. If the volume is visible in Finder, it is visible to the SKIF.

09 Capacity

Adding capacity is adding a Mac

Machines pull work when they have room rather than being assigned it. A busy machine stops taking jobs, so the work stays available for a free one, which is why an unbalanced room self-balances without anyone tuning it.

How it grows

  • New machine, four steps, done. Install, pick what the machine does, point it at storage, join it to the cluster. Identical whether the box is yours or arrived pre-imaged from us. Existing machines are not reconfigured and the cluster is not restarted.
  • Mixed hardware is fine. A laptop, a Mac mini, and a Studio can sit in the same cluster; each takes work at its own limit. There is no reference specification to source against.
  • Per-machine limits are yours to set: cap a suite machine at two jobs so it stays responsive for the artist sitting at it, and let the rack machines run flat out.
  • Each node carries a license. Cluster size is a commercial decision as well as a technical one, so size it against the throughput you need rather than the machines you happen to have idle.
  • Overnight is just capacity. Idle edit bays become render nodes without anyone re-planning the pipeline.

Where the ceiling actually is

  • Your storage bandwidth, in almost every case. A facility saturates its SAN long before it saturates scheduling.
  • Then your core count. The engines are compiled native code tuned for Apple Silicon, so throughput tracks the hardware closely and predictably.
  • Not the orchestrator. Scheduling, leader election, and recovery are not the bottleneck at facility scale. The architectural ceiling is 64 nodes per cluster, and there is no per-cluster fee, so the practical answer to "we outgrew it" is another cluster rather than a migration. You are licensed on nodes either way.
The number we will not invent

Streams per machine. It depends on codec, resolution, and your disks. Any figure we quote describes our storage, not yours. We would rather measure it on your hardware during the pilot.

10 Operating it

Who owns this once we have gone home?

The realistic answer for a facility with a small engineering team. There is no system to administer daily and nobody to hire.

Day to day

  • Operators use the cockpit. Building and editing a pipeline is wiring boxes together. The people who already run your workflows pick it up in an afternoon.
  • No daily administration. No queue to babysit, no service to restart on a schedule, no log rotation to configure.
  • Settings change live. Paths, shows, and concurrency limits are edited in the cockpit and take effect everywhere: no restarts, no config files to push.
  • Nothing to maintain in code. You are not taking on a codebase, a language, or a framework. It is a signed Mac installer.

Install & upgrade

  • One signed installer, 20 MB, containing everything: orchestrator, job database, cockpit, and all eight engines. It lands at 77 MB on disk. Nothing is downloaded at install time, which is what makes an air-gapped install a normal install.
  • Bring-up per machine: install, pick what the machine does, point it at storage, join it to the cluster. The fifth machine is the same four steps as the first.
  • Or it arrives done. Turnkey clusters ship pre-imaged and configured, so bring-up is racking them and pointing them at storage. Nobody on your side images anything.
  • Upgrades: drain a machine, update it, put it back. The facility keeps running on the rest, and the whole cluster fits in one maintenance window.
  • Rollback is reinstalling the previous package on a drained machine: the same four steps in the other direction.

11 Boundaries

What it does, and what it deliberately doesn't

The fastest way to lose a technical evaluator is to answer "what are the limits" with a benefit. Here is the real list, sorted, because "we can't" and "we chose not to" are very different answers and you deserve to know which one you are hearing.

Fixed by design

Load-bearing. These are why the rest works.

  • Rendering runs on Apple Silicon. The engines are compiled native code, arm64 enforced at build. That is the tradeoff that buys the throughput, the determinism, and the 77 MB footprint. Any M-series Mac qualifies, down to a laptop, and we will supply the cluster if you do not run Apple hardware today.
  • Media is processed on mounted storage. Reads and writes are ordinary file operations against your volume, the same property that guarantees nothing leaves the building.
  • Every transform is deterministic. No AI and no generative steps in the delivery path. The same input produces the same output on every node, every run.
  • A cluster is one trust domain. There is no tenant isolation inside a cluster. Clients requiring hard separation get their own, which is a deployment decision rather than a licensing one.

Scope today

Real limits now, and an engineering conversation if they block you.

  • The cluster ships as Macs. The orchestrator is platform-portable and already branches on host OS for its metrics path; hosting it on your existing Linux or Windows infrastructure is a conversation we can have. The engines and the cockpit stay on Apple Silicon.
  • A cluster spans one network. Nodes in a cluster share a network and a job database, up to 64 of them. Run as many clusters as you need: per building, per client, per show. A single machine is a valid cluster, which is how a DIT cart or an OB truck deploys. What is not supported today is one cluster stretched across two sites over a WAN.
  • One shared job database per cluster. Bundled and local, but a component that must be up.
  • DPX is not currently supported. If that is your interchange format for VFX pulls, raise it on the first call. It is a format question, not an architectural one.
  • Deep archive hands off. Material moves to a named archive location; driving an LTO library stays with your existing archive tool.
  • No REST API today. Work is started by files arriving in a nominated location, job history is read from the database, and control lives in a local command interface on the node. If you need to drive it from your own orchestration over HTTP, raise it: that is a scoped addition, not an architectural change.

Our position

We can, we chose not to, and here is why.

  • No cloud object storage. Not a missing feature but a deliberate one. Half-supporting buckets would quietly reintroduce the egress bills and the custody question you are adopting this to eliminate.
  • No cloud burst. Same reasoning. The moment work can leave the building, every claim in section 07 becomes conditional.
  • Not a MAM. No catalog, no search, no proxy library, no metadata system of record. We orchestrate underneath the one you have.
  • No scripting or package-manager extensibility. You cannot drop a script into the execution path, and there is no dependency tree to resolve. Audio Unit hosting is the deliberate exception, because those are tools your engineers already own and chose.
Tell us which one blocks you

We will tell you plainly whether it is a configuration, an engineering conversation, a roadmap item, or a genuine architectural boundary, and we will not dress up the fourth as the third to keep a deal alive. If it is one of the middle two, bring it to the pilot and we will scope it in the room.

12 FAQ

The questions we actually get

Does this replace Resolve, Premiere, or Pro Tools?

No. It supplements them. Your creative tools stay exactly where they are. The SKIF handles the mechanical work around them: the transcodes, mixes, syncs, rasters, and deliveries that currently occupy a person and a machine. It is a force multiplier.

Can we put an unreleased title on it?

That is the deployment it was designed for: an isolated network with no route out, no cloud copy, and media that never leaves your volumes. Section 07 has the exact posture, and the full control mapping is available to your reviewer under NDA.

What happens to our shows if your company disappears?

Media is on your storage in standard formats, and the system keeps working with no connection to us. There is no license server to phone home to and no hosted service to switch off. Perpetual licensing is available for exactly this reason, alongside subscription, and we will put whatever you need on the table and in writing before you commit.

How long before an operator is productive?

Building a pipeline is wiring boxes together in the cockpit, and the vocabulary is the one your team already uses. In practice an operator who runs your transcodes today is building their own graphs the same day. We would rather you measure that yourself during the pilot than take our number for it.

Do we need a dedicated person to run it?

No. There is no daily administration, no queue to babysit, and no code for your team to maintain. Machines are drained for maintenance the same way you would drain any render node, and settings change live from the cockpit.

Can we keep using our existing render farm alongside it?

Yes. It is additive and touches nothing it is not pointed at. The SKIF's own rendering nodes are M-series Macs, so a Windows farm runs beside it rather than inside it, and we can supply those nodes if you do not have them. If you want the orchestrator itself hosted on your existing Linux or Windows infrastructure, see section 11. That part is portable and is a conversation we can have.

What do we do when something goes wrong at 2am?

Most failures requeue without a human. Section 06 is the complete list of what the system does on its own, with the detection windows. Support tiers, response commitments, and the escalation path are set out in the commercial terms rather than in a brief.

How does the cost compare to what we spend now?

The comparison worth making is your current personnel hours spent on manual changes, recurring spend, meaning cloud compute, egress, and per-seat licensing, against hardware, power, and node licensing here. We include our own line item in that model. We will build it with your actual invoices rather than quote a generic savings percentage.