Service Fabric Phase 6 — implemented notes
Short checklist of what landed in the v6 merge (see also service-fabric-phase6.md and the full operator guide service-fabric.md).
- Identity-aware service policy compiled from FluxVM's existing ipcache.
- Default allow/deny, explicit allow/deny identities and audit-only mode.
- Envoy HTTP/gRPC transparent redirect contract with TC as the redirect owner.
- XDP handoff (
XDP_PASS) for L7-enforced services. - Bypass-mark consumption in TC to prevent redirect loops.
- Distributed Fabric policy fanout with previous-state snapshot and rollback.
- BPF queue assisted HA mutation events for forward conntrack/NAT creates.
- Direct userspace
bpf(BPF_MAP_LOOKUP_AND_DELETE_ELEM)queue drain with cross-service dispatch into the owning journal. - Existing v5 snapshot-diff journal retained as the correctness backstop.
- Separate program generation 6 while preserving BPF service schema 4, with fail-closed policy restore during reload.
Ownership remains unchanged: FluxVM owns node-local packet/runtime mechanics; Fabric owns distributed service/policy/HA/routing intent; Envoy owns application parsing.
Examples: examples/service-fabric-v6/.