Branch-shaped control
Give a child its own namespace, its own controller, and its own local admin — without authority beside or above its parent.
BOUNDED AUTHORITYZENOH NETWORK CONTROL / 001
A hierarchical Zenoh network is many Routers, under many owners, sharing one namespace. Scout gives every Branch a controller that states what it actually knows, changes Router configuration through a reviewed path, and delegates authority without giving it away.
CONTROL MODEL / SIX CAPABILITIES
Scout keeps Branch, Node, Router, Data Area, access, and change in one frame, and leaves the certificates, ACLs, and rendered artifacts one disclosure away.
Give a child its own namespace, its own controller, and its own local admin — without authority beside or above its parent.
BOUNDED AUTHORITYRender, validate, review, stage, apply, and observe a candidate, with the restart consequence and last-good recovery in view before you confirm.
INTENT TO EVIDENCEName a Data Area, choose a subject and an action, then read the default-deny native Zenoh ACL that Scout compiles from it.
SCOPED POLICYA partitioned controller keeps operating on what it owns. Remote state is labelled last-known until a fresh acknowledgement arrives.
PARTITION-AWAREEvery Branch issues its own local identities. Private keys stay out of the browser and out of the management API, and no controller signs for another Branch.
LOCAL TRUSTReachability, Router state, deployment outcome, identity, and observation age stay separate, so yesterday's nominal report stays yesterday's.
FRESHNESS FIRSTTHE CONSOLE / FOUR SCREENS
Scope, freshness, identity, and the distance between recorded intent and observed enforcement stay on screen. Every judgment names the evidence under it.
The overall judgment names the evidence it rests on, how old that evidence is, and the next useful action.
Router identity, process state, management link, agent, and certificate evidence stay distinct instead of collapsing into one health light.
The final review names the child, its owned prefix, its capabilities, and how far it may delegate — before anything is created.
The active revision, the deployment result, the effective configuration, and per-key provenance remain in one frame.
CONTROL PATH / INTENT TO ROUTER STATE
The browser never holds a private key or a writable Zenoh identity. The controller authorizes and compiles intent; signed, scoped commands travel a management path that stays independent of the Router being changed.
A local operator chooses a Branch, Node, setting, or access outcome in the browser.
The Branch controller checks operator scope, records the Change, and renders the effective candidate for the target Node.
Typed commands cross the independent management session with content, scope, issuer, and life bound together.
The Node agent validates locally, applies only what it owns, and reports fresh evidence back to the controller.
CURRENT RELEASE / v0.1
Everything below runs today, on one development machine, against real controllers, Node agents, and managed Zenoh Routers.
HQ, Vilnius, and Field each run their own controller, database, local issuer, local-admin sign-in, and admin origin.
One-time enrollment material, separate agent and Router identities generated on the host, replay refusal, and activation.
Typed settings through render, validate, stage, apply, restart, and observation, with last-good recovery when the health path fails.
Named key-expression regions compiled to default-deny native Zenoh ACLs and applied by the controller that owns the Router.
Explicit direction, delegated ceilings, per-side enforcement, and authenticated Field → Vilnius → HQ delivery proved by counts, sequences, and digests.
Frozen target sets, one wave per operator release, signed acknowledgements at every hop, and a held wave when a Router goes offline.
Expected, observed, and correlated links kept apart, each carrying the controller it came from and how old it is.
A root Branch that survives a restart, plus rendered systemd and launchd templates. Preview: Scout writes the files and installs nothing.
v0.1 is a development and evaluation profile: one host, no production packaging, no application payload inspection. The product walkthrough and command reference state the current surface in full.
RUN IT / ONE MACHINE
HQ, Vilnius, and Field: three Branch controllers, three Local Owners, three managed Routers, recursive topology, cross-Branch policy, authenticated traffic, and a rollout that stops on a Router it cannot reach.
scout doctor --artifact-root /opt/scout
scout run bootstrap-network release_root=/opt/scout root_state=/var/lib/scout/root root_bind=127.0.0.1 root_router_listen=tls/0.0.0.0:7436 root_router_advertise=tls/root.example:7436