Skip to content

The Tether

A private road shortens distance. It does not widen the gate.

Tether is the private-reachability Extension Domain, with WireGuard as its accepted transport. It may eventually appear as a LychD-managed WireGuard service or as an attachment to an externally managed private network.

Its state is Designed. Public interface and peer intent, secret-reference validation, bounded endpoint and route validation, revision fencing, and retained revocation tombstones are accepted law, not delivered Domain code. No Tether contract, Rune, VPN provider, live interface, enrollment, peer registry, key generation or rotation effect, network health, reconciliation adapter, or revocation effect ships. Generated deployment remains IPv4-loopback-only; the Extension port grammar accepts only 127.0.0.1:<host>:<container> and rejects UDP. Remote, proxied, tunneled, and untrusted-browser use is unsupported. Keep the Vessel on the same host, and do not tunnel or port-forward the current Altar. State of Work owns that boundary.

Managed path and peer custody

ADR 39 permits a managed Tether to manifest as a rootless service with narrow network capability and explicit UDP publication. Interface, listen port, address space, DNS behavior, routes, and peer limits remain Rune-owned intent.

The Tether service stays outside the shared application Pod and receives no broad mounts, application secrets, database credentials, or host-mutation authority. CAP_NET_ADMIN inside that Pod is not an acceptable shortcut.

An optional Gateway Host composes Tether only for a placement that needs a private routed road. Remote may bind one exact peer and route from the off-site Veil to one Core backend. Home does not require Tether when an exact local segment already supplies reachability. In neither placement does a tunnel grant authority or a default route into the home network.

The Codex may retain stable peer identity, public key, allowed addresses and routes, endpoint and keepalive policy, enabled or revoked state, and creation or rotation metadata. Private and preshared keys stay within the secret boundary; they never enter ordinary documentation, logs, QR history, or public peer records. Future typed operations under a host-owned run-operation verb may generate, admit, inspect, revoke, rotate, or export a short-lived client configuration or QR projection without adding a root CLI verb.

Reach attachment

The Reach deployment matrix gives Tether one exact consumer: reach.edge-home.public@1. Home-only and standalone outbound VPS use none. The split profile admits one named VPS peer, one exact address and route, explicit expiry and revocation generation, and one Tether-only private Veil backend for event admission, delivery claim, settlement, and health. It never uses 0.0.0.0/0, exposes the home Phylactery, Reach core, Altar, model API, Podman socket, Reactor, or forwards arbitrary VPS traffic through the sovereign host.

Tether holds only tunnel material. Root/VPS compromise still requires revoking that peer, separately rotating every resident application and operator credential, reconciling uncertain effects, and rebuilding the host; tunnel revocation alone is not containment.

Tunnel identity and exact routes

WireGuard proves possession of a tunnel key and encrypts packets. Human or process identity, object or effect authorization, consent, and device trust remain outside that proof. The host firewall selects each reachable listener; Veil may constrain route or transport policy, while Ward and the Vessel authenticate and authorize.

For Intercom, the conservative first designed road is a Veil-compiled HTTP route exposed only through Tether. Tether supplies private reachability; Veil canonicalizes ingress; Ward admits the peer; Intercom verifies and replay-fences the A2A envelope. None may impersonate the next layer or turn an advertised Spell or Scroll into authority.

A tunnel address, interface, peer key, or forwarded metadata contributes at most credential evidence. It cannot mint magus:*, widen a Sigil, or create an administrator. Bootstrap magus:* stays same-host only. Routes default to exact destinations; PostgreSQL, model APIs, container and Host lifecycle control, Oculus, audio, and Intercom remain closed unless their own policies admit them.

Revocation, rotation, and recovery

Binding validates peer-address overlap, route conflicts, key references, port collisions, and the generated service contribution. Revocation removes the peer from the live interface and persists revised intent. Rotation overlaps old and new credentials only with explicit operator authorization. Public peer and routing intent is versioned so restore or reconciliation cannot resurrect revoked or stale access. Failure is visible; privileged traffic never falls back to a public route.

Direct WireGuard avoids a mandatory hosted control plane, but CGNAT, blocked UDP, changing endpoints, roaming, endpoint metadata, and traffic analysis remain. Reachability may require fixed addressing, DNS, or a separately accepted rendezvous or relay. ADR 39 owns transport law; Security and the Ward own the trust boundary.