Skip to content

UDS Mesh — the nervous system

The SZL substrate is modeled as a body. Two flagships ship today — a11oy (the policy + receipt heart) and killinchu (drone-intelligence courier) — alongside three roadmap/frontier roles: the Provenance Anchor (convergent memory sync), the Operator (decision/receipt console), and the Policy drift detector (fail-closed safety gate). Two structural organs complete the anatomy (skeleton = vessels / deployment fabric, wires = the W3C-traceparent nervous signal). The mesh is the nervous system that carries trace context + DSSE receipts between them.

Honest status legend

LIVE = wired and verified in-process · IN-PROC = real within a single organ, not cross-pod · ROADMAP = v0.4.0, not shipped. Honesty over checklist. The names amaru, rosie, and sentra are retired internal codenames; the honest roles are Provenance Anchor, Operator, and Policy. Roadmap components have no live Space today.

Wire status table (verified 2026-06-03)

WireEdgeWhat it carriesStatus
Ba11oy ↔ Policy (immune)gate verdict / inspectIN-PROC (Policy = roadmap role)
Ca11oy ↔ Operator (receipt stream)decision events + Khipu ingestROADMAP (Operator not deployed)
DW3C traceparentreal trace-id/span-id generation + propagationLIVE in-process; cross-Space broker NOT wired
Ea11oy ↔ Provenance Anchor (cortex sync)decision SSE eventsIN-PROC (in-memory ring buffer)
Fa11oy ↔ vessels (receipts)DSSE receipts into Khipu DAGLIVE (in-process)
OTLPany organ → collectorOTEL span exportNOT WIRED — schema only (roadmap)
cross-podorgan ↔ organ over k8s ServicemTLS service mesh (Istio Package CR)ROADMAP v0.4.0 (verified: in-cluster ClusterIP call times out today)

What is real vs. aspirational

Real, verified live (2026-06-03):

  • a11oy emits real W3C trace contexttraceparent: 00-<trace>-<span>-01, tracestate: szl=<span>, plus an x-szl-wire-d: LIVE marker — on every HTTP response. Incoming trace_id is preserved across the request (propagation verified).
  • a11oy binds that traceparent into every DSSE Khipu receipt envelope (verified by decoding the base64 DSSE payload — the traceparent is embedded).
  • Span schemas are published under a szl.mesh.* envelope as internal topic identifiers (a11oy.graph, plus reserved keys for the roadmap roles); these are technical schema names, not user-facing product names.
  • In-cluster proof: a11oy runs 1/1 Ready in the szl-stress kind cluster and serves {"status":"ok"} on port 7860.

Honest gaps (not yet wired):

  • No OTLP export. No opentelemetry package, no exporter, no collector — spans are a documented schema, not a live telemetry signal.
  • DSSE receipts are UNSIGNED today (signatures: []) — the cosign private key (SZL_COSIGN_PRIVATE_PEM) is not present in the runtime.
  • Cross-pod organ traffic is NOT wired. An in-cluster ClusterIP call times out; there is no Istio Package CR / service-discovery wiring in the bundle charts.
  • The Operator, Provenance Anchor, and Policy roles are roadmap — they have no live Space today; only a11oy and killinchu ship.

Until modules actually call each other across pods and spans are exported, this is a live in-process governance signal, not distributed telemetry — honestly short of a full service mesh. See uds-bundles/mesh/docs/roadmap/MESH_INTERCONNECT.md.


Sources: uds-bundles/mesh/schemas/spans/, MESH_INTERCONNECT.md, and the flagship szl_provenance.py / szl_wire.py runtime. Verified live by the uds-fully-operational squad. Λ Conjecture 1 (not a theorem) · 749/14/163 v11 LOCKED · SLSA L1 honest · Section 889 = 5 vendors.

Doctrine v11 LOCKED · 749/14/163 · kernel c7c0ba17 · Λ = Conjecture 1 · SLSA L1 honest. Math-grounded, Quechua-rooted, zero mysticism (PURIQ v12 agentic layer is additive).