SELF-HOSTED DESIRED-STATE CONTROL PLANE

Declare the state.Cloud converges the system.

Persist intent once. Resume every operation. Run immutable A3S workloads through Box, publish exact Gateway policy, and keep the evidence needed to recover.

F0VerifiedBX0In progress
Desired stateA3S ACL
Cloudcontrol plane
A3S ORMtyped SQL
A3S Flowdurable work
Node Agentoutbound mTLS
A3S Boxsole provider
Gatewaylive traffic
Evidencehealth · logs
Intent moves through durable control. Live traffic never crosses the Cloud control plane.
01 PostgreSQL truth through A3S ORM02 Outbound node control03 Box-only execution04 Gateway stays on the traffic path
THE CONVERGENCE LOOP

From desired state to observed truth

An API request records intent; it does not impersonate deployment work. Every transition emits durable evidence and can continue after interruption.

ACTIVE SYSTEM

A3S Boot API

Validate tenant-scoped A3S ACL and commit desired state with an operation identity.

convergence.trace
$ cloud observe operationintent.acceptedgeneration 01 · receipt durable · replay safe
CAPABILITY SYSTEM

One loop, not a pile of mechanisms

Core capabilities reuse one application model, one persistence boundary, and one Runtime path. Each status is read from the repository roadmap at build time.

DURABLE CONTROLF0

Intent survives the request

Cloud commits desired state before execution. A3S Flow resumes leases, retries, projections, and cleanup after interruption.

A3S Boot APIA3S ORMPostgreSQLA3S Flow
SOLE EXECUTION PATHBX0

Everything converges through Box

Task, Service, build, network, mount, Secret, log, output, and cleanup behavior share one Runtime contract and one Box provider.

A3S RuntimeA3S Boxgeneration fencing
SOURCE DELIVERYG0

Commit to signed evidence

Resolve immutable source, build in isolation, validate complete OCI graphs, publish by digest, and retain signed SPDX and SLSA evidence.

Git revisionOCI digestSPDXSLSA
MANAGED REACHABILITYH0

Gateway policy converges atomically

Cloud owns domains, TLS, target generations, rollout thresholds, and complete snapshots. Gateway stays on the request path.

managed TLSexact snapshotrollback
RECOVERY EVIDENCEBX0

Restart without inventing state

Receipt-gated batches, ordered logs, immutable chunks, claims, and native observations make replay explicit and inspectable.

receiptsordered logsclaimsreplay
ONE APPLICATION MODELC0

Web, CLI, REST, and MCP agree

Every control surface reuses the same commands, queries, authorization, idempotency, typed client, and API envelope.

RESTCLIWebmanagement MCP
PRODUCT BOUNDARIES

Clear authority at every hop

Cloud decides and records. Box executes. Gateway serves live traffic. Power becomes one typed inference backend; none of them becomes a second control plane.

Desired-state authorityF0

A3S Cloud

Tenancy · policy · placement · rollout · operations

Sole execution providerBX0

A3S Box

Isolation · lifecycle · resources · local evidence

Traffic data planeH0

A3S Gateway

TLS · streaming · enforcement · healthy dispatch

Typed inference backendPW0

A3S Power

Power Service · MicroVM / TEE execution evidence

CONTROLCloud stays off the live request path.TRAFFIC
NEXT HORIZONS

The platform that the same loop unlocks

Planned and in-progress capabilities are visible here by design. Their badges preserve the formal roadmap state instead of presenting them as shipped.

POWER BOUNDARYPW0

Confidential inference units

Compile immutable A3S Power Service profiles into Box-hosted MicroVM or TEE evidence without moving placement authority out of Cloud.

profile → power service → evidence
DEVELOPER WORKFLOWSP0

From repository to preview

Add build detection, workload profiles, previews, monorepo selection, and a bounded import path over the existing delivery loop.

detect → build → preview → promote
RELEASE CATALOGA0

Agents, MCPs, and Skills as releases

Publish immutable, tenant-authorized assets through the same source, artifact, workload, and Gateway paths.

source → release → bind → operate
AGENT EXECUTIONA1

Durable work with human checkpoints

Conversations, executions, approvals, checkpoints, forks, and trajectories build on existing operations and outbound node control.

execute → approve → checkpoint → recover
STATEFUL PLATFORMS0

State with explicit fencing

Databases and volumes add ownership, backup, restore, retention, and failure fencing without creating another scheduler.

claim → attach → protect → restore
INFERENCE PROFILEI0

Governed model serving

Add accelerator claims, OpenAI-compatible traffic, scoped keys, routing, exact shared limits, usage, and provider governance.

model → route → stream → account
LIVE PRODUCT ROADMAP

Every promise has a gate

Filter the complete delivery matrix. Historical gates retain useful evidence but still require Box re-certification before they can be presented as verified.

F0VerifiedROADMAP GATE

Foundation

Boot control plane, PostgreSQL, tenancy, identity, Flow operations, outbox, projections, API, and web shell

Read evidence and dependencies
INTERACTIVE SYSTEM MAP

See the whole Cloud in motion.

Orbit the 3D control plane, inspect exact ownership boundaries, and replay deployment, source delivery, traffic, recovery, and planned inference journeys.

Open interactive architecture
BUILD ON INFRASTRUCTURE YOU OWN

Make desired state durable.

Start with the current contract, then follow evidence—not claims.

View on GitHubDocumentation