The public-facing entrance and observation layer for the AENET ecosystem. It publishes sanitized snapshots, static pages, a public API and an anonymous traffic channel — nothing more.
One-way only. Public side can never reach the AENET Core. No accounts, no terminal, no file bridge, no agent or model surface. Secrets, private memory, internal logs and user data are forbidden by contract and by tests.
Data direction
Core-to-public one-way (export sanitized snapshot); public-to-core never. Early Access writes only to D1, never to the core.
One-way only. Public side can never reach the AENET Core. No accounts, no terminal, no file bridge, no agent or model surface. Secrets, private memory, internal logs and user data are forbidden by contract and by tests.
What
Give the public a read-only window into the AENET build while keeping the AENET Core completely unreachable.
Why
The AENET ecosystem needs a public presence that can never become an attack surface, a control channel or a privacy leak. AENET Cloud Public solves this with a one-way, snapshot-only, read-only boundary.
How
Core-to-public one-way (export sanitized snapshot); public-to-core never. Early Access writes only to D1, never to the core.
Serve static public pages (home, architecture, system map, research, development, status, roadmap, API, early access)
Publish sanitized public-data snapshots
Serve the read-only Public API v1
Accept anonymous traffic observation events
Host the Early Access waitlist (D1-backed)
Provide Public Time and Public Status services
Render one UI contract in web and Swift
Example
A visitor opens https://aenetcloud.com, reads the glossary and systems map, and calls GET /api/v1/time — every response is served from sanitized snapshots and nothing reaches the private core.
Inputs
Sanitized snapshots exported by the AENET Core (site, status, architecture, articles, roadmap)
Curated content in content/ (articles, research, development log, roadmap)
Anonymous traffic events from visitors
Outputs
Crawlable static HTML and JSON public-data
Read-only API responses
Public time and status
Aggregated anonymous traffic summary
Early access registration records (D1 only, never published)
A visitor learns what AENET is and what is being built
A developer reads the public API contract and endpoint documentation
A researcher reads public articles and the observation model
A visitor checks public status, time and the development queue
A person joins the Early Access waitlist
Limitations
Read-only by design: no accounts, no write channels to the core
Only sanitized snapshots — never live core state
Public Time quality is SERVER_UTC until an atomic source is verified
Traffic channel is disabled by default and is observation-only
Connected systems
AENET Core — The private AENET ecosystem. It is never publicly routable and may export only sanitized public snapshots to aenet-cloud-public through the snapshot contract.
AENET Wallet — Local-first, watch-only Bitcoin wallet architecture with external signing and Rust machine integration. A private operational system of the AENET ecosystem; the public side observes only sanitized snapshots.
Development Queue — The public view of what the AENET system is building — a state machine (DISCOVERED → SPECIFIED → BUILDING → VERIFYING → PREVIEW → RELEASED) with no fake progress percentages.
Early Access — The public waitlist for testing the AENET public gateway. Applicant records live only in D1, are never indexed, exported or published, and registration is fail-closed without Turnstile verification.
KAP Language — A declarative contract style used across this repository to describe the public site, navigation, content, layout, motion, time, traffic and early access in machine-readable files (.kap).
Public API — The read-only public API v1 of AENET Cloud Public. It serves public status, time, architecture, development queue, roadmap and early access — with a strictly bounded surface.
Public Snapshot Layer — The layer that publishes sanitized, pre-generated JSON snapshots (site, status, architecture, articles, roadmap, queue, topology, traffic summary) from public-data/.
Public Time — The public time service of AENET Cloud Public. It serves canonical UTC with an explicit quality, and never claims atomic verification without a verified atomic source.
RGBM — The semantic color role system of the AENET public UI. Components reference roles (navigation, action, insight, guard, system, warning) — never raw color names.
UI Contract — The single source of truth for the public UI structure — pages, navigation, components, coordinates, states, motion, colors, typography and locales — consumed by both the web and Swift renderers.
Visit Memory — Device-local continuity for AENET visitors: preferred locale, last route, visit count and read progress — stored in the browser only and never identifying a person.
XGRID — The adaptive spatial grid system of the AENET public UI: desktop 12 / tablet 8 / mobile 1 columns, content-intrinsic sizing, with a 1920x1080 canvas used only as a design reference.
Related research
The AENET Public Entrance — What this public entrance is, what the public may observe, and where the one-way boundary sits.
The Public Observation Model — Why the public side is an observation layer, and how anonymous traffic becomes a sanitized signal without becoming a control surface.
Questions people ask
These questions are answered by the content on this page.
What is AENET?
What is AENET Cloud?
How does the AENET public gateway work?
What can the public observe about AENET?
How does the public boundary protect the AENET Core?
Evidence
Verified states only — nothing on this page is a prediction.