Architecture

Humans left. Machines right.

People change things in the management plane. Machines serve traffic in the runtime. Configuration flows one way across the line, and consumer traffic never crosses back.

What the split buys you

  • Control plane downEditing stops. Traffic keeps flowing. New pods still start.
  • Bad deployPods keep the last good generation and report the failure.
  • In-process executionRouting, policies, and JavaScript run inside the pod. Only what a policy has to look up leaves it.

What it does not

  • The backend is part of the runtimeConsumer identity, entitlements, and anything else a policy has to look up come from the gateway backend, with Redis in front. Run it with the same care as the gateways.
  • Policies decide the blast radiusA route that only proxies keeps serving from memory. A route that checks identity needs the backend or a warm cache.

Load-bearing rules

Two boundaries we keep.

These are how the product behaves, not a diagram that can go stale.

Control boundary

The control plane never talks to a gateway

Pods start and sync through the gateway backend, which is built for machines. The control plane has no path to a pod, and a pod has no path back.

So the control plane can be down, upgrading, or being restored, and traffic keeps flowing. New pods still start.

Runtime boundary

Last known good wins

A new generation is validated and compiled before it replaces the one in memory. If that fails, the pod keeps serving the previous generation, stays in the balancer, and reports the mismatch.

A bad deploy is a status to fix, never an outage.