Only Institute / Knowledge

Follow your curiosity.

AI sends your question and public excerpts to PrimeSwarm.

Try agent memory, governance, or a project name.

All Publications
article

Public, Chained, Provable — DGV Goes Live

A real Hetzner host, real DNS and OIDC, the T0/T1 revocation and delegation-cascade proofs re-run externally, plus hash-chained offline-verifiable receipts and SLSA provenance

Grigori Korotkikh 2026-09-19 11 min
DGVDeploymentRevocationDelegationEvidenceSLSARelease
Only Institute — Public, Chained, Provable — DGV Goes Live

Public, Chained, Provable — DGV Goes Live

The previous update ended with a specific, deliberate non-claim: "What this does not establish: a public host, DNS, real certificates, and a real OIDC issuer. The artifacts are ready; nothing is publicly deployed." That sentence no longer holds. This update replaces it with what we actually ran, against a real host, from outside the machine running it.

The gate is public

dgv-gate runs on a real Hetzner host, behind real TLS (Let's Encrypt, TLS 1.2/1.3 only — 1.0 and 1.1 correctly refuse to negotiate), at a real DNS name, with a real OIDC issuer. DGV_OIDC_ISSUER=https://accounts.google.com — the gate fetches Google's own .well-known/openid-configuration at boot and resolves the real jwks_uri itself. No mock issuer, no stub identity provider.

Two real, previously-undiscovered bugs surfaced only because this was a genuine external deployment, not a synthetic test: the Docker builder image was pinned below the Rust toolchain the workspace actually needs, and the jsonwebtoken crate defaulted to rejecting any real-world token with an aud claim even when no audience was configured — because no synthetic test had ever exercised a token with a real one. Both fixed at the source, not patched around.

The headline claim, proven externally

The whole gate exists for one sentence: permission to act is not continuing authority to act. Previously this was demonstrated as "production posture on our machines." Now it's a real external caller against a real host:

  1. A real Google-authenticated caller requests /govern — ALLOW, a signed token issued.
  2. That exact caller's authority is revoked, between the grant and the spend.
  3. /execute re-checks fresh at redemption — 403, authority_revoked_at_t1, signed.

No synthetic clock, no mocked identity, no local shortcut. The token was genuinely valid when issued and genuinely dead by the time it was spent, and the gate caught the difference from outside its own network.

Delegation, now proven the same way

An agent holding a live token can mint strictly narrower child tokens for other agents — proven externally this round, not just in the local test suite: a real Ed25519-signed delegation request, a child token that executes correctly under the delegatee's own identity, and three independent live rejections — wrong executor, a replayed single-use child token, and a delegation attempt whose params weren't a strict subset of the parent's. Then the actual point of the mechanism: revoking the delegator, live, cascades to deny a child token that was never even executed, mid-window — delegated_authority_revoked: ancestor … revoked.

Evidence you can check without trusting us

Three additions close a gap we found by reading a comparable open-source project's source rather than assuming our own was fine.

Referenced evidence is now actually verified. POST /evidence/artifacts accepted a content_ref and a declared SHA-256 with no way to ever confirm they matched — verified sat at false permanently, on pure trust. POST /evidence/artifacts/:id/verify now fetches an https:// reference itself, hashes it (capped, streamed, bytes never persisted), and flips verified on a real comparison. Proved live: a correct hash flips true, a deliberately wrong one gets 409 and stays false.

Decisions are hash-chained and verifiable offline. Every decision now links to the one before it under a locked chain-tail row — safe under concurrent load on both storage backends. GET /decisions/export returns a flat, signed batch; a standalone CLI verifier confirms chain contiguity, hash re-derivation, and the Ed25519 signature with no network access and no running gate required. We tested it against three separate tamper attempts — a modified parameter, a corrupted signature, a deleted record — and each was caught and correctly attributed to the right check.

The hash itself got more honest. compute_decision_hash() used to concatenate fields into a SHA-256 hash with no delimiters between some of them, and serialize parameters by insertion order rather than a canonical form — two logically identical parameter objects with keys in a different order produced different hashes. Fixed by adopting RFC 8785 (JCS) canonical serialization — the same standard a comparable Microsoft toolkit uses for its own signed receipts. Evidence artifacts can now also emit a SLSA v1.0 provenance predicate, so existing supply-chain tooling can consume them without custom integration.

A real gap found, and fixed, by scanning our own exposure

No Hetzner Cloud Firewall existed — the only thing preventing wider exposure was that nothing else happened to be listening, with zero network-level backstop against a future misconfiguration. Fixed: a baseline firewall now permits only 22/80/443. TLS quality, security headers, and rate limiting (exactly 100 requests per window under 110 real parallel authenticated requests, no drift) were all confirmed correct rather than assumed.

We now publish our own limitations document

Not a summary paragraph — a structured LIMITATIONS.md, in the same spirit as the honesty we praised in a competitor's equivalent document: what the decision chain does and doesn't prove against an operator with direct database access, the version boundary the hash-canonicalization fix creates, the still-unfixed peer-to-peer wire protocols, and the explicit admission that we haven't had a third-party red-team engagement yet.

What this does not establish

  • Single node. Peer gossip, quorum voting, and Merkle anti-entropy reconciliation are real, tested code — not yet proven against a second, genuinely independent, network-separated host. A test plan for that exists and is ready to run.
  • No penetration testing. Everything above is configuration and exposure verification — confirming the gate is set up correctly — not an adversarial attempt by an independent party to break in.
  • One static admin secret, not per-operator credentials with rotation.
  • Peer-to-peer canonical strings (gossip, quorum, delegation signing) still use the pre-JCS pipe-delimited format — a documented wire protocol external parties already reconstruct independently, so upgrading it is a coordinated version bump, not a quiet fix.

Where to look

  • docs/deploy/dgv-gate-hetzner.md — the full runbook, every command, real captured output
  • docs/deploy/costs.md — the actual monthly bill (~$7/mo)
  • docs/LIMITATIONS.md — nine dated, honest limitations
  • scripts/verify_decision_chain.py — the offline chain verifier
  • /threat-model — what we cover, what we don't, what we recommend for the gaps

The next milestones remain what they were: a second node for real quorum consensus, and an independent third-party audit. Evidence, not adjectives.


Back to Publications

Published by Only Institute