the second phase
Stop reconciling five control planes.
Carry the path in the packet.
The audit and the assurance run on the network you have today. This is the other half: a managed migration that replaces per-flow state and middlebox reconciliation with an itinerary the packet carries itself.
It is a separate decision, taken on your own numbers, after the first two read-only weeks have shown what the estate actually looks like. Nobody should migrate to find out whether migrating is worth it.
SRv6 / uSID managed migration entry is always the core audit
0100 the allocator
The plan carves instructions, not labels.
The migration starts as an addressing plan, not a change window. The allocator assigns the locator block and the per-function segments, proposes them against the live routing table, and proves the result strands nothing — before a single route is written.
0200 what it buys
Three things you cannot get by writing more policy.
Network simplification
One reachability decision stops being written five times. The core holds the block as a single prefix and keeps no per-flow state, so the state that used to scale with pairs of endpoints simply stops existing.
Audit that stops sampling
Flow records are sampled, so assurance built on them describes the traffic it happened to catch. A segment counter increments on every packet that executes it — so “no undeclared segment ran” stops being an absence of alerts and becomes a provable negative: the counter is zero, and zero is a measurement.
Zero trust the network enforces
The path a workload may take is expressed in the network that already moves the packet, rather than in a stack of middleboxes bolted along the way and reconciled by hand afterwards.
5→1
sampled→every packet
0 bytes
added header, up to six segments an SRH carrying the same six adds 104 · RFC 8754 · RFC 8986The first is arithmetic about full-mesh topologies, presented as arithmetic. The second is the difference between a sampled flow record and a hardware counter. The third is a property of the uSID encoding, not a measurement of your network.
The honest description is that the destination address has become a program counter.
0300 the data path
One route in the core. Per-segment evidence at the edges.
The core carries the uSID block as an ordinary prefix and holds no per-flow state. Identity stays cryptographic at the endpoints — mTLS and SPIFFE — because an address you can read is one anyone can spoof.
End to end, once the path is declared
0400 the boundaries
What we publish rather than discover in production.
The data path runs natively on modern Linux — seventeen checks green on a stock 6.8 kernel, reproducible in three minutes. The useful output of that work was not the passes. It was the four boundaries, and they belong in the plan before they belong in an incident.
0500 what you can buy
Two offers, and neither is where you start.
Both are scoped as design-partner phases with published gates. The engagement that precedes them is the read-only audit on the core engine — which is also what tells you whether either of these is worth doing at all.
e000 End.DT6 deliver
See it against your own kit.
30–60 minutes. Read-only. We compare your declared intent to what is actually running, and hand back the gap list.
Nothing is installed to have this conversation.