The Architecture Canontruth · evidence · projection
Diagram

Capban Pipeline

diagram-capban-pipeline · canon/diagrams/capban-pipeline.mmd

%% CapBan — security as a typed pipeline, not a bolt-on. Dangerous capability
%% (firewall mutation) confined to one idempotent, validated seam.
flowchart LR
    E["Event<br/>(typed at the boundary)"]
    I["Normalized Identity"]
    POL["Policy<br/>allowlist → denylist → score"]
    D["Decision<br/>carries its evidence"]
    EN["Enforcement<br/><b>single confined seam</b><br/>idempotent · validated · no shell"]
    A["Audit<br/>structured JSON → SIEM"]
    NFT[("nftables / k8s<br/>(only reachable here)")]

    E --> I --> POL --> D --> EN --> A
    EN -->|"idempotent apply"| NFT

Incoming References

Case Study 1
Law 1
Projection 3