Intent survives the request
Cloud commits desired state before execution. A3S Flow resumes leases, retries, projections, and cleanup after interruption.
Persist intent once. Resume every operation. Run immutable A3S workloads through Box, publish exact Gateway policy, and keep the evidence needed to recover.
An API request records intent; it does not impersonate deployment work. Every transition emits durable evidence and can continue after interruption.
Validate tenant-scoped A3S ACL and commit desired state with an operation identity.
Core capabilities reuse one application model, one persistence boundary, and one Runtime path. Each status is read from the repository roadmap at build time.
Cloud commits desired state before execution. A3S Flow resumes leases, retries, projections, and cleanup after interruption.
Task, Service, build, network, mount, Secret, log, output, and cleanup behavior share one Runtime contract and one Box provider.
Resolve immutable source, build in isolation, validate complete OCI graphs, publish by digest, and retain signed SPDX and SLSA evidence.
Cloud owns domains, TLS, target generations, rollout thresholds, and complete snapshots. Gateway stays on the request path.
Receipt-gated batches, ordered logs, immutable chunks, claims, and native observations make replay explicit and inspectable.
Every control surface reuses the same commands, queries, authorization, idempotency, typed client, and API envelope.
Cloud decides and records. Box executes. Gateway serves live traffic. Power becomes one typed inference backend; none of them becomes a second control plane.
Tenancy · policy · placement · rollout · operations
Isolation · lifecycle · resources · local evidence
TLS · streaming · enforcement · healthy dispatch
Power Service · MicroVM / TEE execution evidence
Planned and in-progress capabilities are visible here by design. Their badges preserve the formal roadmap state instead of presenting them as shipped.
Compile immutable A3S Power Service profiles into Box-hosted MicroVM or TEE evidence without moving placement authority out of Cloud.
profile → power service → evidenceAdd build detection, workload profiles, previews, monorepo selection, and a bounded import path over the existing delivery loop.
detect → build → preview → promotePublish immutable, tenant-authorized assets through the same source, artifact, workload, and Gateway paths.
source → release → bind → operateConversations, executions, approvals, checkpoints, forks, and trajectories build on existing operations and outbound node control.
execute → approve → checkpoint → recoverDatabases and volumes add ownership, backup, restore, retention, and failure fencing without creating another scheduler.
claim → attach → protect → restoreAdd accelerator claims, OpenAI-compatible traffic, scoped keys, routing, exact shared limits, usage, and provider governance.
model → route → stream → accountFilter the complete delivery matrix. Historical gates retain useful evidence but still require Box re-certification before they can be presented as verified.
Boot control plane, PostgreSQL, tenancy, identity, Flow operations, outbox, projections, API, and web shell
Read evidence and dependenciesOrbit the 3D control plane, inspect exact ownership boundaries, and replay deployment, source delivery, traffic, recovery, and planned inference journeys.
Open interactive architectureStart with the current contract, then follow evidence—not claims.