Private mesh
Release-gatedRepository model: Mesh, peer, route, DNS, auth-key and relay coordination.
Release dependency: WireGuard/relay data plane and signed node identity.
Discoverable ownership for the durable SS-26 control plane without presenting an authenticated apply receipt as physical network proof.
Production authorization denies every network operation unless its exact method and route are explicitly released. The WireGuard node agent now records an authenticated, monotonic receipt after local apply, while physical tunnel, packet-flow and provider enforcement remain unverified.
Each domain needs retained real-environment, failure, rollback and observability evidence before controls can be enabled.
Repository model: Mesh, peer, route, DNS, auth-key and relay coordination.
Release dependency: WireGuard/relay data plane and signed node identity.
Repository model: Policy validation, compilation, versions, distribution and applied state.
Release dependency: Durable policy repository and signed distribution.
Repository model: ZTNA, secure web gateway, firewall-as-a-service, CASB and DLP control models.
Release dependency: Regional enforcement points and traffic-path evidence.
Repository model: Tunnels, QoS, probes, steering and failover intent.
Release dependency: Provider circuits, appliances and failover exercises.
Repository model: Residency constraints, validation and audit records.
Release dependency: Verified regional infrastructure and compliance evidence.
Repository model: Labs, nodes, links, snapshots, start/stop and validation.
Release dependency: Isolated execution environment and abuse controls.
Repository model: Paths, fault injection, namespaces, VPCs and subnets.
Release dependency: Production topology and protected operator workflow.
Repository model: Emergency policy, freeze, segmentation tests and workload isolation.
Release dependency: Strong-auth approvals and real segmentation evidence.
| Gate | Required result | Current state |
|---|---|---|
| Authorization | Object-scoped SpiceDB tuples and continuous-access decision | Local model only |
| Durability | Transactional Yugabyte repositories, outbox and reconciliation | Implemented · unverified |
| Apply receipt | Authenticated, idempotent, monotonic netmap version and redacted configuration digest | Implemented · unverified |
| Data plane | Signed node packages, real tunnels, packet enforcement and failure recovery | External lab absent |
| Operations | Load, soak, failover, rollback and regional telemetry | No retained evidence |