One private network: six services that make and carry the decisions, and one service for every agent and API of the story. Two face the internet: this site, and the federation's public records. The rest answer only to each other. Everything below is read from the services themselves when you open this page, not from a list kept by hand.
1The picture, live
Orange borders face the internet; the rest answer only on the private network. The mark on each box is that service answering when this page loaded; for the agents and APIs it is all of them answering. Both ways purpose can be checked are drawn, and the one in force now is marked.
Scroll sideways to see the whole picture.
2The services
| Service | What it does | Exposure | Runs | Now |
|---|---|---|---|---|
| Checking… | ||||
3The agents and APIs
Who vouches for whom, and who asks for a token for whom.
Scroll sideways to see the whole picture.
Every leaf of the federation runs as a service of its own, with its own keys and its own PEP, reached only inside the private network. The list comes from the federation's directory, and each was asked whether it is answering when this page loaded.
| Service | Organisation | Kind | In the story | Now |
|---|---|---|---|---|
| Checking… | ||||
4The decision, as deployed
5The model, as deployed
6What the pages are drawn from
7Not shown here
Hostnames and addresses inside the private network, credentials, and the layout of the hosting account. The federation's records are public by design, and its resolve endpoint is where every relier in the demo resolves; the policy engine, the purpose service and the model can be reached only from inside.
Run the demo
