The host is the narrow trusted edge, and the OS is a vtable
what a host owns · the six vtables · what it must never own
Mission foundation / System overview
The host boundary from edge node to service
Fathom connects MerTek applications to files, networks, processes, and deployed nodes through a small host interface. Transport, trust, and rollout choices are declared policy.
Inside the system
Each plate preserves the internal layout, paths, boundaries, and highlighted decisions. Use the short label first, then follow the lines through the system.
what a host owns · the six vtables · what it must never own
the frame bytes · the three tags · wire name to language verb
two lanes · transport_policy_verdict · the capability probe
accept → detect → bound → throttle → worker → frame
declared topology · cr_resolve · the epoch fence · the moving parts
declared inputs · the .tri Application · the delivery closure
two update paths · the rolling window · the three mechanisms
Key parts
These are the main boundaries, inputs, outputs, and failure rules. The examples show a specific use of each part.
The application uses a small, defined surface to reach the operating system. That reduces hidden dependencies and makes platform review easier.
The same workflow can run on a field computer and a data-center node through approved host adapters.
Transport, identity, and trust choices are stated as policy. Nodes do not invent a security posture at run time.
A disconnected team can use a local path, then move to an approved network path when contact returns.
Older and newer releases can operate during a controlled rollout. Shared message rules protect the mission while nodes change over time.
A fleet can update in waves without taking every operational node offline at once.
Uses
Pilot questions
Which environments must host the application
What communication paths are approved
How long mixed releases must work together