Hot Path Boundary
The rule-1 boundary — stateless verification above, stateful issuance below
%% The rule-1 boundary — stateless verification above, stateful issuance below
graph TB
subgraph hot["HOT PATH — stateless, core-independent (rule 1)"]
vor["Vör verification"]
jwks["cached JWKS"]
status["cached status list"]
jwks --> vor
status --> vor
end
subgraph issue["ISSUANCE SIDE — stateful, may read the strong domains"]
mod["Modgud — login · OAuth · session · SAML"]
fors["Forseti — authorization"]
relstore["Forseti relation store — second strong domain, own fence"]
core["Core — issuance · uniqueness · revocation"]
end
mod -->|writes| core
fors -->|fences| relstore
core -->|publishes| jwks
core -->|publishes| status