FS architecture and the WORM backbone
Diffuse Leapfrog 2030 Doctrine and Glossary formatting
@@ -2,16 +2,16 @@ schema: foundry-doc-v1 type: topic slug: service-fs-architecture title: Service-FS Architecture: The WORM Backbone title: Service-FS Architecture: The {{gli|WORM}} Backbone audience: vendor-public bcsc_class: current-fact language: en paired_with: service-fs-architecture.es.md --- # Service-FS Architecture: The WORM Backbone # Service-FS Architecture: The {{gli|WORM}} Backbone `service-fs` is the per-tenant Write-Once-Read-Many (WORM) immutable ledger substrate. It serves as the durable backbone for the Foundry Three-Ring Architecture, providing the primary landing zone for all Ring 1 boundary-ingest services. Every critical record—including identity anchors, email communications, and document artifacts—is persisted through this substrate to guarantee tamper-evidence and long-term availability. `service-fs` is the per-tenant Write-Once-Read-Many ({{gli|WORM}}) immutable ledger substrate. It serves as the durable backbone for the Foundry Three-Ring Architecture, providing the primary landing zone for all Ring 1 boundary-ingest services. Every critical record—including identity anchors, email communications, and document artifacts—is persisted through this substrate to guarantee tamper-evidence and long-term availability. ## The Four-Layer Architecture @@ -19,7 +19,7 @@ To ensure modularity and survivability, `service-fs` is implemented as a decoupl * **L4: Anchoring (Workspace-Tier):** Monthly periodic work that anchors signed checkpoints to the public Sigstore Rekor log. * **L3: Wire Protocol:** The communication interface (HTTP/axum today; MCP long-term) that enforces per-tenant `moduleId` boundaries. * **L2: WORM Ledger API (Rust Trait):** The stable core contract (`append`, `read_since`, `checkpoint`) that survives changes to the layers above or below. * **L2: {{gli|WORM}} Ledger API (Rust Trait):** The stable core contract (`append`, `read_since`, `checkpoint`) that survives changes to the layers above or below. * **L1: Tile Storage Primitive:** The envelope-specific storage engine (POSIX on Linux; capability-mediated on seL4) utilizing the **C2SP tlog-tiles** format. ## Dual Boot Envelopes @@ -31,9 +31,9 @@ A core innovation of `service-fs` is its ability to operate across two distinct ## Durability and Compliance Foundry achieves structural WORM compliance by structurally denying record modification at the storage layer. This is reinforced by: Foundry achieves structural {{gli|WORM}} compliance by structurally denying record modification at the storage layer. This is reinforced by: * **C2SP tlog-tiles:** An open-standard text-based format ensuring 100-year readability. * **C2SP signed-note Checkpoints:** Compact, signed artifacts that prove the state of the ledger at any point in time. * **Audit-Log Sub-Ledger:** A dedicated WORM ledger that records every read event to satisfy SOC 2 processing integrity requirements. * **Audit-Log Sub-Ledger:** A dedicated {{gli|WORM}} ledger that records every read event to satisfy SOC 2 processing integrity requirements. This architecture ensures that `service-fs` remains portable, verifiable, and resilient to vendor obsolescence.