3.6 KiB
NDC Device Plane
device-plane is the provider-neutral runtime boundary for physical devices.
It is intentionally separate from Foundry, Engine L2, External Data Plane and
the preserved Gelios integration.
Recorded runtime status: the private Synology foundation and the isolated Mini IPvlan relay are running through their reviewed artifacts. Synology has no public device listener; the Mini relay is LAN-addressable only and router/NAT exposure remains a separate manual gate. The admission-gate source below is prepared and staged, but has not yet been applied.
packages/device-protocol-contractowns safe discovery and presentation contracts.packages/arusnavi-b2-adapterowns the first model-profile evidence and a fail-closed framing boundary.services/device-control-coreowns the initial PostgreSQL schema, health boundary and disabled-by-default quarantine ingest.services/device-gatewayowns a disabled-by-default, loopback-only TCP evidence listener that sends no bytes and extracts no identifier until the official framing contract is known.docker-compose.device-plane.ymlpublishes only loopback health endpoints and keeps the raw TCP listener unpublished.- No device command can be built or sent.
- No real IMEI, ICCID, password, packet or provider credential is stored in this source tree.
The planned runtime services are:
device-control-core: contours, discoveries, devices, bindings, policy and audit;device-gateway: raw TCP sessions, bounded codecs and presence;device-postgres: private persistent state.
services/device-edge-relay is a separate, disabled-by-default runtime for the
dedicated Debian ingress host. It is an L4 byte relay: it neither decodes
ARUSNAVI B2, acknowledges a device nor holds a Core token, database credential
or command capability. The implemented backhaul forwards only through a
restricted outbound SSH path to the Synology Gateway loopback listener. The
reviewed ingress target gives only this container a fixed IPvlan L2 address on
the Mini's single Ethernet link, so the host Amnezia full tunnel stays intact
and Docker publishes no host port. The fixed relay address is
192.168.71.253, explicitly outside the documented Deco DHCP pool
192.168.68.50–192.168.71.250. See docs/IMPLEMENTATION_BASELINE.md for
the remaining activation gates. The staged admission update keeps the relay
opaque but requires a public IPv4 source and bounds its source table and bytes
per direction; it does not enable router/NAT exposure.
The standalone Hub application Device Core / Device Manager is the human
control-plane shell. Its server-owned BFF calls the disabled-by-default
management and query API in device-control-core; browsers never receive the
Core bearer token and never author actor, role, group or owner-scope headers.
The authorized project workspace exposes only bounded metadata for catalog,
routes/sessions, bindings, configuration state, command state, audit and access;
raw audit/configuration payloads, command parameters/transport refs, external
approval proofs, credential refs and restricted identifier digests remain in Core.
Foundry remains a downstream consumer for project-approved device data and is
not the device registry or administration boundary.
Run the foundation tests:
npm test
See IMPLEMENTATION_BASELINE.md for the placement, security and rollout contract.
The canonical runner registry and deterministic artifact builder live in
../infra/deploy-runner. The runner must be separately promoted and verified
before any Device Plane artifact is staged or planned.