AENET ecosystems PUBLIC GATEWAY
Request a Pilot
GATEWAY READY
architecture K.PUBLIC.ARCHITECTURE

AENET ARCHITECTURE

AENET Architecture

How the AENET public gateway is composed: layers, data flow, API flow and the public/private boundary.

flows
9
layers
5
systems
19

SYSTEM STRUCTURE VISUAL

Public traffic, static web, public API, sanitized snapshots, and private boundary are shown as a one-way display path.

9flows 5layers 19systems
  1. D14.01INGRESSVisitor traffic enters the public edge.
  2. D14.02PUBLIC SURFACEWeb and API services remain routable.
  3. D14.03SNAPSHOT CONTRACTOnly sanitized data crosses the boundary.
  4. D14.04PRIVATE CORECore systems stay outside public routing.
  1. L01N01 → N02one-wayallowed
  2. L02N02 → N03one-wayallowed
  3. L03N03 → N04one-wayallowed
  4. L04N04 → N05blockednot-routable
  5. L05N05 → N06blockednot-routable

Legend

  • PUBLIC SURFACE
  • SNAPSHOT CONTRACT
  • PRIVATE BOUNDARY

Public Boundary

D20

AENET Wallet Boundary

AENET Cloud reads only the sanitized wallet snapshot. Below the private boundary, the wallet domain (node, ledger, treasury) prepares unsigned PSBT intents; the machine layer observes readiness; and the signing boundary hands unsigned intents to an external hardware signer. There is no live path from the public web into the wallet runtime.

  • AENET Cloud→Public snapshotpublic pages and read-only API read public-data/wallet/ only
  • Public snapshot→AENET WalletPRIVATE BOUNDARY — verified export only, one way
  • AENET Wallet→Node / Ledger / Treasurywallet domain manages receive and transfer-intent state
  • Wallet domain→Unsigned PSBTintents are prepared unsigned
  • Unsigned PSBT→External signerSIGNING BOUNDARY — physical confirmation on the hardware signer
  • Public side→AENET Walletforbidden: no proxy, no live query, no control
D21

Public / Private Boundary

Everything public sits on one side; the AENET Core sits on the other. The only sanctioned crossing is the export of sanitized snapshots through the snapshot contract. Early Access is the only public write path, and it writes only to D1 — never through the core.

  • Public gateway→Sanitized snapshotcore exports only sanitized data
  • Sanitized snapshot→Public pages / APIstatic + read-only
  • Public write path→D1early access registration only
  • Public side→AENET Coreforbidden: no proxy, no live query, no control

Data Flow

D30

Data Flow

Sanitized snapshots are exported one-way from the core, validated, versioned with a content hash and copied into web/public-data/. The UI and Public API read those snapshots. Anonymous traffic flows in the opposite direction as an observation signal and is reduced to aggregates.

  • AENET Core→Sanitized snapshotexport, one-way, contract-gated
  • Sanitized snapshot→public-data/*.jsonvalidation + version + contentHash
  • public-data/*.json→web/public-data/static host
  • web/public-data/→Public pages / APIrendered read-only
  • Visitor→Traffic channelanonymous observation events
  • Traffic channel→Public traffic summaryaggregates only, no raw publish
D31

Development Flow

Curated content (articles, research, development log, roadmap) and curated snapshots are validated by the content index builder, enveloped with version/generatedAt/contentHash, and copied into web/public-data/. Everything is then deployable as static assets. The verification suite gates every change.

  • content/ + public-data/→build-public-indexparse front matter, generate snapshots
  • build-public-index→public-data/*.jsonvalidate + envelope + hash
  • public-data/*.json→web/public-data/static copy
  • web/→Wrangler deploystatic assets to Cloudflare edge
  • Any change→npm run checkverification gates: boundary, routes, contracts
D32

Time Flow

The server clock feeds the public time service, which returns canonical UTC timestamps with an explicit quality (SERVER_UTC today). The UI shows a live time rail using one baseline fetch plus a monotonic client clock. Atomic verification is never claimed without a verified source.

  • Server clock (UTC)→Time servicecanonical source, SERVER_UTC quality
  • Time service→GET /api/v1/timetimestamp + quality, never fake precision
  • GET /api/v1/time→UI time railone baseline fetch + monotonic client clock
  • Atomic source→ATOMIC_VERIFIEDfuture — only when verified, atomicVerified=false today

Integration Fabric

D40

API Flow

The Public API is a bounded read-only surface. It reads public snapshots and services, returns a consistent envelope, rejects preview/private routes with 403, and routes the single write path (early access registration) to D1 — never to the core.

  • Client→GET /api/v1/*read-only public endpoints
  • GET /api/v1/*→Public snapshots + servicesstatus, time, architecture, queue, roadmap
  • Public snapshots + services→Clientconsistent JSON envelope
  • POST /api/v1/early-access/register→Validation + D1the only write path, never to the core
  • Client→/preview/* and private routes403 — intentionally unavailable
D41

Search Flow

Public knowledge (knowledge blocks, content, public-data, locales, templates) is compiled at build time by the Go Search Compiler into static HTML with metadata, JSON-LD, sitemaps, hreflang sets and canonical URLs. The static output lands in web/, and Cloudflare serves it at the edge. The worker still owns routing, API and security.

  • Knowledge + content + public-data→Go Search Compilerbuild-time compilation, deterministic
  • Go Search Compiler→web/en|th|zh-cnfull static HTML pages
  • Go Search Compiler→sitemap + robots + search-graphcrawl surface
  • web/→Wrangler deploystatic assets to Cloudflare edge
  • Crawlers→Cloudflare edgecrawlable, fast, static-first
D42

AENET Structure Channel Flow

The private .aenet channel registry keeps each channel connected to its existing entrypoint, state owner and structure owner. The root structure channel resolves the canonical authority map and structural knowledge. A public-safe review then projects only approved architecture facts into this repository, where the snapshot contract, graph validator and Go Search Compiler produce static pages for localhost and deployment. Private paths, state, logs, chat content, IDE control and runtime access never cross the boundary.

  • Registered .aenet channels→Channel structureOwnerevery channel resolves its existing owner; no parallel registry
  • structure.root→.aenet system authoritycanonical private structure lookup
  • .aenet structure authority→Public-safe reviewallow-list and sanitize architecture facts; no runtime state
  • Public-safe review→Architecture graph + snapshotcontract-gated, versioned, read-only projection
  • Architecture graph + snapshot→Go Search Compilervalidate coordinates, owners and public boundary
  • Go Search Compiler→/en/architecturestatic output served on localhost:5500 and deployable edge assets
  • Public site→.aenet private channelsforbidden: no live query, write, control or reverse route

Security Boundaries

D50

Public Gateway Architecture

Security boundary

One-way and read-only. The gateway can never query, proxy or control the core.

D51

Public / Private Boundary

Security boundary

forbiddenReverse: true. The core is labeled PRIVATE SYSTEM — NOT PUBLICLY ROUTABLE.

D52

Data Flow

Security boundary

Snapshots are sanitized before publish; raw traffic events are never published.

D53

AENET Wallet Boundary

Security boundary

forbiddenReverse: true. The wallet is labeled PRIVATE WALLET DOMAIN — NOT PUBLICLY ROUTABLE. Only sanitized snapshots cross.

Visual Maps

Continue exploring