The Tether
A private road shortens distance. It does not widen the gate.
Tether is the private-reachability Extension Domain, with WireGuard as its accepted transport. It may eventually appear as a LychD-managed WireGuard service or as an attachment to an externally managed private network.
Its state is Designed. Public interface and peer intent, secret-reference validation, bounded
endpoint and route validation, revision fencing, and retained revocation tombstones are accepted
law, not delivered Domain code. No Tether contract, Rune, VPN provider, live interface, enrollment,
peer registry, key generation or rotation effect, network health, reconciliation adapter, or
revocation effect ships. Generated deployment remains IPv4-loopback-only; the Extension port grammar accepts only
127.0.0.1:<host>:<container> and rejects UDP. Remote, proxied, tunneled, and untrusted-browser
use is unsupported. Keep the Vessel on the same host, and do not tunnel or port-forward the
current Altar. State of Work owns that boundary.
Managed path and peer custody
ADR 39 permits a managed Tether to manifest as a rootless service with narrow network capability and explicit UDP publication. Interface, listen port, address space, DNS behavior, routes, and peer limits remain Rune-owned intent.
The Tether service stays outside the shared application Pod and receives no broad mounts,
application secrets, database credentials, or host-mutation authority. CAP_NET_ADMIN inside that
Pod is not an acceptable shortcut.
An optional Gateway Host composes Tether only for a placement that needs a private routed road. Remote may bind one exact peer and route from the off-site Veil to one Core backend. Home does not require Tether when an exact local segment already supplies reachability. In neither placement does a tunnel grant authority or a default route into the home network.
The Codex may retain stable peer identity, public key, allowed addresses and routes, endpoint and keepalive policy, enabled or revoked state, and creation or rotation metadata. Private and preshared keys stay within the secret boundary; they never enter ordinary documentation, logs, QR history, or public peer records. Future typed operations under a host-owned run-operation verb may generate, admit, inspect, revoke, rotate, or export a short-lived client configuration or QR projection without adding a root CLI verb.
Reach attachment
The Reach deployment matrix gives Tether one exact
consumer: reach.edge-home.public@1.
Home-only and standalone outbound VPS use none. The split profile admits one named VPS peer, one
exact address and route, explicit expiry and revocation generation, and one Tether-only private
Veil backend for event admission, delivery claim, settlement, and health. It never uses
0.0.0.0/0, exposes the home Phylactery, Reach core, Altar, model API, Podman socket, Reactor, or
forwards arbitrary VPS traffic through the sovereign host.
Tether holds only tunnel material. Root/VPS compromise still requires revoking that peer, separately rotating every resident application and operator credential, reconciling uncertain effects, and rebuilding the host; tunnel revocation alone is not containment.
Tunnel identity and exact routes
WireGuard proves possession of a tunnel key and encrypts packets. Human or process identity, object or effect authorization, consent, and device trust remain outside that proof. The host firewall selects each reachable listener; Veil may constrain route or transport policy, while Ward and the Vessel authenticate and authorize.
For Intercom, the conservative first designed road is a Veil-compiled HTTP route exposed only through Tether. Tether supplies private reachability; Veil canonicalizes ingress; Ward admits the peer; Intercom verifies and replay-fences the A2A envelope. None may impersonate the next layer or turn an advertised Spell or Scroll into authority.
A tunnel address, interface, peer key, or forwarded metadata contributes at most credential
evidence. It cannot mint magus:*, widen a Sigil, or create an administrator. Bootstrap
magus:* stays same-host only. Routes default to exact destinations; PostgreSQL, model APIs,
container and Host lifecycle control, Oculus, audio, and
Intercom remain closed unless their own policies admit them.
Revocation, rotation, and recovery
Binding validates peer-address overlap, route conflicts, key references, port collisions, and the generated service contribution. Revocation removes the peer from the live interface and persists revised intent. Rotation overlaps old and new credentials only with explicit operator authorization. Public peer and routing intent is versioned so restore or reconciliation cannot resurrect revoked or stale access. Failure is visible; privileged traffic never falls back to a public route.
Direct WireGuard avoids a mandatory hosted control plane, but CGNAT, blocked UDP, changing endpoints, roaming, endpoint metadata, and traffic analysis remain. Reachability may require fixed addressing, DNS, or a separately accepted rendezvous or relay. ADR 39 owns transport law; Security and the Ward own the trust boundary.