Application-Aware Network segment
Make that truth application-aware.
Then start enforcing it.
Bring the application inventory into Network Truth, and start enforcing selected application intents through SRv6 micro-segmentation — at endpoints you control, over transit you do not.
SRv6 entry earned, not sold entry is always the free audit
Verified on stock Linux 6.8 — seventeen checks green, four documented limits, none failed. Never yet on an operator estate or router silicon. Every number here is a lab number.
0100 application-aware
Three steps, in this order.
The application inventory
Bring what you have. Application groupings are also proposed from the flow graph — with a seed, a confidence and the flows behind them — and a named approver promotes them, or not.
Application intents
Network Truth stops being address spaces and becomes this application may reach that one, on this service, owned by this team. Only a declared intent may widen policy.
Selected enforcement
A scoped perimeter, terminated in the Linux kernel on gateways, nodes or VMs. Compile. You apply. We verify. No write credentials; reversible in one route change.
Opened by a track record, not a signature — findings closed and verified clean, a named fabric owner, an agreed perimeter.
0200 the boundaries
What we publish rather than discover in production.
Between Network Truth and the first perimeter sits a plan, not a change window — a project with your integrator. The audit tells you whether it is worth doing at all.
e000 End.DT6 deliver
Start where it is already provable.
The free audit, read-only, on what runs today. The fabric is a later decision, taken on your own numbers.