the second phase

Stop reconciling five control planes.
Carry the path in the packet.

The audit and the assurance run on the network you have today. This is the other half: a managed migration that replaces per-flow state and middlebox reconciliation with an itinerary the packet carries itself.

It is a separate decision, taken on your own numbers, after the first two read-only weeks have shown what the estate actually looks like. Nobody should migrate to find out whether migrating is worth it.

SRv6 / uSID managed migration entry is always the core audit

0100 the allocator

The plan carves instructions, not labels.

The migration starts as an addressing plan, not a change window. The allocator assigns the locator block and the per-function segments, proposes them against the live routing table, and proves the result strands nothing — before a single route is written.

Locator and segment assignment — a solved allocation, not a spreadsheet: the block, the per-node locators and the per-function segments, derived from the estate the audit already mapped.
Routes and segments as code — the plan is an artifact under version control, reviewed like code, with one approved write path to the network. Every change is a proposal that passes the same gate.
The strands-nothing check — a reachability proof run before anything is applied. If the plan would isolate a prefix, a tenant or a management path, it fails here rather than at 03:00 on a change night.
Reversible by construction — the core carries the block as an ordinary prefix. Backing out is a route replace, not a project.

0200 what it buys

Three things you cannot get by writing more policy.

Network simplification

One reachability decision stops being written five times. The core holds the block as a single prefix and keeps no per-flow state, so the state that used to scale with pairs of endpoints simply stops existing.

Audit that stops sampling

Flow records are sampled, so assurance built on them describes the traffic it happened to catch. A segment counter increments on every packet that executes it — so “no undeclared segment ran” stops being an absence of alerts and becomes a provable negative: the counter is zero, and zero is a measurement.

Zero trust the network enforces

The path a workload may take is expressed in the network that already moves the packet, rather than in a stack of middleboxes bolted along the way and reconciled by hand afterwards.

51

control planes carrying the same reachability decision

sampledevery packet

segment executions counted, not estimated a counter is a counter, at any volume

0 bytes

added header, up to six segments an SRH carrying the same six adds 104 · RFC 8754 · RFC 8986

The first is arithmetic about full-mesh topologies, presented as arithmetic. The second is the difference between a sampled flow record and a hardware counter. The third is a property of the uSID encoding, not a measurement of your network.

The honest description is that the destination address has become a program counter.

0300 the data path

One route in the core. Per-segment evidence at the edges.

The core carries the uSID block as an ordinary prefix and holds no per-flow state. Identity stays cryptographic at the endpoints — mTLS and SPIFFE — because an address you can read is one anyone can spoof.

End to end, once the path is declared

One flow, one declared artifact, three stages A declared band across the top drops intent into three stages. On the left, a cluster encapsulates the payload with a segment list. In the middle, the transit fabric executes one instruction per hop with no per-flow state. On the right, the far cluster decapsulates and the payload lands in a tenant routing table. declared route & segment objects · one approved change path · the SID list this flow may use cluster a encapsulate app data + SID list identity at the pod transit fabric one route for the whole domain 0100 0200 0300 e000 one instruction per hop · no per-flow state cluster b decapsulate SID spent app data into the tenant table Six hops fit in the destination address itself: no added header, no MTU erosion, no hardware header-parsing requirement. The honest description is that the destination has become a program counter. RFC 8986.

0400 the boundaries

What we publish rather than discover in production.

The data path runs natively on modern Linux — seventeen checks green on a stock 6.8 kernel, reproducible in three minutes. The useful output of that work was not the passes. It was the four boundaries, and they belong in the plan before they belong in an incident.

Ingress MTU is an explicit deployment step — encapsulated mode costs exactly 40 bytes of path MTU, and that cost black-holes TCP silently: path MTU discovery does not rescue it. Setting the ingress MTU is a line in the plan, not a surprise.
Zero added bytes is a property of transit, not of your hosts — a stock, unmodified host cannot originate a native uSID carrier. The zero-byte figure describes fabric transit and SR-aware endpoints, and we do not claim it for a host-terminated deployment.
Counters prove segments, not jurisdictions — per-segment counters prove which segments executed. Mapping a segment to a legal jurisdiction is an inference layer designed with you, and we say so rather than let the counter carry the claim.
Lab figures are lab figures — throughput measured on virtual interfaces on one machine is a substrate check, not a performance promise about your silicon. Your numbers come from your estate.

0500 what you can buy

Two offers, and neither is where you start.

Fabric simplification & migration plan SRv6 — the locator plan, the routes and segments as code, and one approved write path. Reversible, and it strands nothing.
In-tenant zero-trust fabric SRv6 — host-terminated segments over any IPv6 transit, including one you do not own. One deployment step is explicit rather than discovered: the ingress MTU.

Both are scoped as design-partner phases with published gates. The engagement that precedes them is the read-only audit on the core engine — which is also what tells you whether either of these is worth doing at all.

e000 End.DT6 deliver

See it against your own kit.

30–60 minutes. Read-only. We compare your declared intent to what is actually running, and hand back the gap list.

Nothing is installed to have this conversation.

See it on your estate — read-only