Documentation embedded in this build.
A federation across organisations
What it is for
Headquarters, a region and a partner lab: three organisations that have to work together and cannot merge their directories, because none of them will hand the others the keys to its own people. Each keeps its own authority and issues its own certificates.

Records carry the origin they came from, so nobody is asked to believe a record without knowing whose it is, and trusting a partner's certificates for the handshake never means adopting the partner's data. A lapse anywhere is visible rather than silent: when one authority goes quiet, what it published stops conferring anything past its budget, and the console names which authority went stale and when.
This is not one directory with tenants in it. Each authority is its own box.
The topology
A chain of authorities, and one peer beside it that is trusted for the handshake only.
HQ --signed bundle--> REGION --republished--> ENCLAVE
own authority own authority own authority
carries HQ's records carries both,
with HQ's origin origins intact
SIDE LAB (on the other diagonal)
own authority --root appended to the trust pool--> the handshake only
its DATA is never adopted
Every bundle carries an origin mark that survives each hop, and every hop has a freshness budget of its own.
Stand it up
$ make all-in-one-federated # HQ, region, the enclave and a partner lab
$ make kind-all-in-one-federated # the same chain on a kind cluster
Both leave a stack running and print a directory of every URL at the end. Expect a long first run: the composition mints its own PKI, stages every mount, pre-mints the first bundles and then walks its smokes in order.
What the smoke proves
The composition's first smoke is the cascade, and it is the federation's whole claim in one act: a record made live at headquarters through a door with no published port is drawn by the proxied console two hops away. Its Go twin is test/integration/federation/cascade_test.go, which proves the cascade and its provenance against the compiled binaries in seconds; the composed run asserts only what a composition adds — the port that is published, the address that is fixed, the mount that landed where the process reads.
Then, in order: a partner's credential refused at an edge whose trust pool is fixture only (cross_ca_login_test.go); two hierarchy models over artifacts minted at staging; a revocation list that reaches a container and comes into force on restart, with the responder answering on its published port (revocation_test.go); the authority lens, fetched at a fixed address, naming every authority and how fresh it is (lens_test.go); and the blast radius, which pauses one box and shows the two published readiness ports answering differently — the centre reports itself stale, the edge stays ready (blast_radius_test.go). The narrowness is the point being proved.
make kind-all-in-one-federated translates the same composition to manifests, applies it in waves, and runs the same phases against it.
Read on
make:all-in-one-federatedpins the whole chain: the cascade, the refused cross-authority login, the revocation, the lens and the blast radius.make:kind-all-in-one-federatedpins that the chain is not a property of compose.- The federated all-in-one, toured, in the technical collection, is the guided walk through the running stack, leg by leg, with the commands to type.
- The operator guide covers emitting the federation's names, the authority lens and what a stale publisher means.
- The edge fleet scenario is the same publication mechanism inside one organisation.