UDS Mesh — evidence-bound architecture
The mesh is a design for carrying trace context and receipt-shaped records across SZL roles. The two flagship source products are a11oy and killinchu. Provenance Anchor, Operator, Policy, vessels, and cross-pod wiring remain architectural or in-process roles unless an exact deployment witness says otherwise.
Current runtime boundary
The 2026-08-11 observation found a11oy readiness UNAVAILABLE, killinchu AVAILABLE_AT_OBSERVATION only at its health route, and Hatun-MCP UNAVAILABLE. No current distributed mesh, OTLP export, cross-pod traffic, or signed runtime receipt is claimed. See /status.
Architecture map
Evidence-class table
| Layer | What source describes | Current evidence |
|---|---|---|
| W3C trace context | traceparent/tracestate generation and propagation | Historical in-process observations only; no current cross-service witness |
| Receipt envelope | Trace-bound DSSE/Khipu-shaped record | Integrity fields may exist; runtime signing UNAVAILABLE unless exact bytes verify |
| OTLP | Export to a collector | NOT WIRED / UNAVAILABLE |
| Cross-pod mesh | Service discovery, mTLS, policy, retries | UNAVAILABLE |
| Role services | Operator, Policy, Provenance Anchor | No independent current deployment witness |
| Product readiness | a11oy / killinchu | Governed by /runtime-status.json |
Historical local observation — 2026-06-03
Prior project notes reported in-process trace headers and a local kind cluster response. Those notes did not establish a public distributed mesh and are not current availability evidence. They must not be relabeled LIVE; reproduce them at an exact source revision and preserve raw output before reuse.
Promotion gates
- Bind every service to an immutable source and image digest.
- Observe cross-pod requests with exact endpoint, trace IDs, and bounded timeouts.
- Export spans to a named collector and read them back.
- Preserve receipt bytes and classify integrity versus signature verification.
- Run failure/retry/mTLS/policy tests and retain results.
- Publish a source-bound deployment manifest and independent live readback.
Until all six close, the mesh remains an architecture with historical local evidence—not a distributed production service.