Network and Gateway Architecture
Why this chapter matters
Gateways are the places where Stygia touches something beyond itself. This chapter makes those crossings deliberate, mediated, observable, and reversible, so connectivity can serve the civilization without dissolving its boundaries.
Continue to Sovereign Compute and Storage Integration to consider what the civilization must own and preserve.
Defines controlled exposure, segmentation, egress, ingress, mediation, and gateway evidence without selecting a live network.
- INFRA10-R001: Every gateway flow SHALL identify source, destination, purpose, identity, policy, scope, and expiry or review condition.
- INFRA10-R002: Untrusted or unexpected traffic SHALL be denied, contained, or explicitly escalated rather than silently admitted.
- INFRA10-R003: Gateway logs SHALL preserve material denials, transformations, failures, and uncertainty with integrity evidence.
- INFRA10-R004: Network reachability SHALL not create authority or permission.
- INFRA10-R005: Flow review SHALL identify data class, source and destination identity, purpose, policy decision, inspection, rate limits, expiry, and restoration criteria.
- INFRA10-R006: Unexpected, denied, transformed, failed, or uncertain traffic SHALL remain attributable and shall not be silently discarded.
- INFRA10-R007: Exceptions SHALL have a named authority, narrow scope, expiry, compensating control, and retrospective review.
- INFRA10-R008: A gateway design SHALL NOT configure live exposure, egress, ingress, interception, or external contact; it remains conceptual.
This Draft excludes live network configuration and exposure.
Flow review
Gateway review shall evaluate source and destination identity, data class, purpose, authentication, authorisation, inspection, rate and quota limits, error handling, and termination. Deny decisions and policy uncertainty shall remain auditable.
Failure cases
Open egress, confused-deputy routing, spoofed source identity, bypassed inspection, log loss, gateway compromise, and unreviewed exception are material failures. Recovery shall isolate the flow and preserve evidence before restoring access.
Operating model and evidence
Gateway architecture separates source, destination, identity, purpose, data class, policy, inspection, rate, quota, transformation, error, termination, and evidence. It tests expected, denied, malformed, replayed, spoofed, oversized, and unreviewed flows. Reachability is a technical property; it does not establish permission or authority.
Reviewers preserve denials, policy uncertainty, log loss, gateway compromise, confused-deputy paths, and exception history. Recovery isolates the flow, preserves evidence, and restores only the smallest verified path. An exception expires automatically unless a recorded authority renews it.
Interpretation cases
- Conforming: Flow identity, purpose, policy, data class, controls, expiry, denials, and restoration are linked.
- Prohibited: Reachability becomes authority or permission.
- Boundary: Uncertain traffic is denied or contained while evidence is preserved.
- Failure: Gateway compromise or log loss isolates the flow and pauses restoration.
- Loophole: An exception becomes permanent through repeated unreviewed renewal.
- Misuse: Gateway records enable unrelated surveillance or private disclosure.
- Care-control: Segmentation reduces exposure while preserving necessary access, notice, and review.
Design evidence
Flow review should identify data class, source and destination, identity proof, policy decision, inspection limits, rate controls, expiry, denials, and restoration criteria. A route that is reachable but not attributable remains unapproved.