Simulation only · no credentials · no backend calls
Runtime admission console / issue 12
Trust is a
runtime decision.
Trace the contract gates that decide whether a tenant snapshot can activate. Every result is deterministic, publisher-bound, and fail-closed.
Select a trace
Run a compatibility scenario
Keyboard: 1–4
Admission result
Trusted snapshot activated
Fresh compatibility, lifecycle, secret, and migration evidence passed inside the tenant-exclusive switch.
Compatibility lockfile
Publisher-bound topology
Identity binds registry + namespace + component ID + publisher lineage — a namesake cannot substitute.
Operation pin
The fail-closed boundary
What the runtime checks
Contract & capability
Stable SemVer, negotiated floors, runtime capability requirements.
Migration ledger
Replay once, checkpoint safely, reconcile ambiguity explicitly.
Lifecycle authority
Latest authenticated policy can immediately close an old admission path.
Atomic activation
Generation CAS and durable operation pins isolate each tenant transition.