ARCHITECTURE / SYSTEM BOUNDARIES

Platform architecture.

One public experience across existing, independently operated services. This page describes confirmed topology and important limits; it is not an authorization to access private infrastructure.

One entrance, several planes

The platform is a curated index, not an all-powerful execution gateway. Public HTML and JSON are served through an existing loopback HTTP application behind a TLS reverse proxy. Existing apps remain at their original URLs, and their authentication models are unchanged.

PlanePublic entryScope
Experience/suites/Apps, games, interfaces, guides and demos
Knowledge/atlas/Read-only atlas and public search
Local AI/frontiers/live/Bounded CPU inference with disclosed quotas
Factory/factory/Public catalog, simulation and documentation; no owner execution
Observability/mission-control/Sanitized status, not raw server telemetry
Publishing/launch/Approved public releases, tests and traceability
AdministrationNot publicCredential-gated operations, model management and private files

Provider and model separation

A provider-themed interface is not the same as an authorized connection to that provider. The live chat service reports twelve original workspace presets with local CPU Ollama as the backend. Proprietary external inference must have separate connection, billing/quota, permission and end-to-end receipts before it can be described as connected.

12 public workspace profilesLocal Ollama inferenceOfficial provider calls: unverified

Inspect live disclosures: workspace status, backend metadata, and capability map. These are public read-only projections; they can become stale.

Compatibility and delivery contract

  • Simple static HTML, CSS, JavaScript and versioned JSON. No browser extension, third-party script, framework build, account, or local installation.
  • Responsive layouts for desktop, tablets and small mobile screens; keyboard navigation, visible focus, a skip link, and reduced-motion preference.
  • Same-origin HTTPS links. Link-check probes use the HEAD method without authentication and never invoke write APIs.
  • Catalog data is an explicit allowlist of public paths. Newly published services are only added after review and a public-route test.
  • Provider connection status and public inference limits come from the actual public service metadata, not fabricated capability claims.

Isolation boundaries

No public route should allow arbitrary file access, privileged shell execution, credential retrieval, container administration, private model management, unrestricted inference, or automatic publishing. Existing sensitive services retain their current authenticated or loopback-only bindings. Never publish API keys, session cookies, backups or customer information as “public metadata.”

For broader capacity, implement per-provider adapter contracts and receipt-based verification behind an authenticated gateway before enabling paid or rate-limited external models. Add queue control, audit trails and rollback tests before opening public job execution.

Source of truth

/platform/catalog.json is the directory manifest. The original public API catalog remains independently available. Public link status proves an HTTP response only, not full operational acceptance.

← Return to platform