Health Check & Service Discovery  ·  View 19 of 21  ·  Assurance

Trust Zones

Four zones, and the one control the whole design rests on sits at the ingest boundary.

Editable source SVG draw.io All views
Untrusted — outside the estate Third-party endpoints declared, never probed Public internet Workload zone — authenticated, least privilege Application instance may report only itself Envoy sidecar reports outcomes it saw Prober assigned targets only Control zone — privileged, audited Signal ingest attribution enforced Evaluator may deny service Policy API staged + budgeted Manual override rate-limited Record zone — write once Registry address ownership checked Audit log 5 years, immutable self only assigned only attributed actor + why versioned declared Trust Zones — Who May Deny Service To Whom External / third party Application we own Security / platform Interface / broker Data store synchronous event / async batch The control the design rests on sits at the ingest boundary: a signal that cannot be attributed to the instance it describes is discarded, and a registered address must be proved to belong to its registrant. v 1.0 · owner Reliability Architecture

Decisions

  • A signal that cannot be attributed to the instance it describes is discarded. Everything downstream assumes this held (ADR-15).
  • An instance may report only about itself; a prober only about its assigned targets. A compromised workload cannot mark a neighbour unhealthy.
  • A registered address must be proved to belong to its registrant, so an endpoint cannot be pointed at an attacker.

Assumptions

  • Workload identity via IRSA and instance profiles; mutual authentication on every control-plane path.
  • Resolution is authorised per caller-callee pair, so the registry is not a map of the estate.

Residual risk

  • The passive outcome channel is the one signal a workload cannot forge about itself — and a compromised caller can still lie about someone else. Ejection caps bound it; nothing removes it.