ContriveAtlas
neostory-schema-set/22snapshot a59c206cec9d
Open Observatory

Contracts and data · Replica and authority

Local work remains responsive while shared history is accepted exactly once

Every client authors against a durable local graph and outbox. Synchronization transports canonical mutations to a deployment authority, then reconciles accepted journal history back into each authorized replica without turning caches or queues into a second semantic store.

Product · Engineering · Operations
DeclaredImplementedObservedPlanned
neostory-schema-set/22snapshot a59c206cec9d

Contracts and data · Replica and authority

Local work remains responsive while shared history is accepted exactly once

Every client authors against a durable local graph and outbox. Synchronization transports canonical mutations to a deployment authority, then reconciles accepted journal history back into each authorized replica without turning caches or queues into a second semantic store.

Product · Engineering · Operations11 nodes · 10 directed relationships

What this view establishes

The architectural commitments

  1. The local graph is a real durable replica, not a disposable UI cache, so capture and play do not wait on the network.
  2. Only authority-accepted journal history becomes shared history; replay never re-enqueues remote writes.
  3. Blob queues, leases and caches coordinate bytes while semantic identity remains in ordinary graph records.
  4. A mutation keeps its identity across the store's own schema migration, and the authority names itself, so a new hostname is a rename rather than a re-offered journal.

Replica swimlanes

06

Local replica

local-commandimplemented

Local command

The product writes immediately against local contracts

sqlite-graphimplemented

SQLite graph

Durable record heads and local query semantics

outboximplemented

Durable outbox

Ordered local mutation envelopes awaiting acceptance

checkpointimplemented

Authority checkpoint

Last accepted journal sequence applied locally

local-blobsimplemented

Verified local blobs

Content-addressed bytes, cache policy and durable leases

sync-pumpimplemented

Sync pump

Pushes outbox pages and pulls accepted changes

01

Portable boundary

http-boundaryimplemented

Canonical HTTP

Portable bearer-authenticated mutation and query boundary

04

Authority

gateway-acceptimplemented

Gateway acceptance

Authenticates, authorizes, validates and deduplicates

record-headsimplemented

Record heads

Current authoritative entity and relationship revisions

journalimplemented

Append-only journal

Monotonic accepted history and high-water sequence

blob-authorityimplemented

Object authority

Authorized content-addressed upload and retrieval

Push, acceptance and checkpoint return

Local replicaPortable boundaryAuthorityLocal command to SQLite graph: commits. implemented.Local command → SQLite graph01 · commitsimplementedLocal command to Durable outbox: enqueues atomically. implemented.Local command → Durable outbox02 · enqueues atomicallyimplementedDurable outbox to Sync pump: ordered push. implemented.Durable outbox → Sync pump03 · ordered pushimplementedSync pump to Canonical HTTP: portable pages. implemented.Sync pumpCanonical HTTP04 · portable pagesimplementedCanonical HTTP to Gateway acceptance: authenticated request. implemented.Canonical HTTPGateway acceptance05 · authenticated requestimplementedGateway acceptance to Record heads: atomic head. implemented.Gateway acceptance → Record heads06 · atomic headimplementedGateway acceptance to Append-only journal: appends once. implemented.Gateway acceptance → Append-only journal07 · appends onceimplementedAppend-only journal to Authority checkpoint: accepted pull. implemented.Append-only journalAuthority checkpoint08 · accepted pullimplementedAuthority checkpoint to SQLite graph: applies without echo. implemented.Authority checkpoint → SQLite graph09 · applies without echoimplementedVerified local blobs to Object authority: verified transfer. implemented.Verified local blobsObject authority10 · verified transferimplemented

Connections and evidence

Open the 10-relationship source key

Numbers set an explanatory reading order. They do not measure runtime timing.

  1. 01

    Local commandSQLite graph

    commits

    implemented
  2. 02

    Local commandDurable outbox

    enqueues atomically

    implemented
  3. 03

    Durable outboxSync pump

    ordered push

    implemented
  4. 04

    Sync pumpCanonical HTTP

    portable pages

    implemented
  5. 05

    Canonical HTTPGateway acceptance

    authenticated request

    implemented
  6. 06

    Gateway acceptanceRecord heads

    atomic head

    implemented
  7. 07

    Gateway acceptanceAppend-only journal

    appends once

    implemented
  8. 08

    Append-only journalAuthority checkpoint

    accepted pull

    implemented
  9. 09

    Authority checkpointSQLite graph

    applies without echo

    implemented
  10. 10

    Verified local blobsObject authority

    verified transfer

    implemented

Connections and evidence

10 directed, source-backed relationships

Numbers set an explanatory reading order. They do not measure runtime timing.

  1. 01

    Local commandSQLite graph

    commits

    implemented
  2. 02

    Local commandDurable outbox

    enqueues atomically

    implemented
  3. 03

    Durable outboxSync pump

    ordered push

    implemented
  4. 04

    Sync pumpCanonical HTTP

    portable pages

    implemented
  5. 05

    Canonical HTTPGateway acceptance

    authenticated request

    implemented
  6. 06

    Gateway acceptanceRecord heads

    atomic head

    implemented
  7. 07

    Gateway acceptanceAppend-only journal

    appends once

    implemented
  8. 08

    Append-only journalAuthority checkpoint

    accepted pull

    implemented
  9. 09

    Authority checkpointSQLite graph

    applies without echo

    implemented
  10. 10

    Verified local blobsObject authority

    verified transfer

    implemented

What this view establishes

The architectural commitments

  1. The local graph is a real durable replica, not a disposable UI cache, so capture and play do not wait on the network.
  2. Only authority-accepted journal history becomes shared history; replay never re-enqueues remote writes.
  3. Blob queues, leases and caches coordinate bytes while semantic identity remains in ordinary graph records.
  4. A mutation keeps its identity across the store's own schema migration, and the authority names itself, so a new hostname is a rename rather than a re-offered journal.
15 repository sources behind this view
  • README.md
  • Sources/NeoStoryCore/GraphMutationExecutor.swift
  • Sources/NeoStoryHTTP/HTTPAuthorityTransport.swift
  • Sources/NeoStoryHTTP/HTTPBlobClient.swift
  • Sources/NeoStorySQLite/LocalBlobStore.swift
  • Sources/NeoStorySQLite/SQLiteGraphStore.swift
  • Sources/NeoStorySync/GraphSync.swift
  • docs/cross-platform-sync.md
  • docs/delegation/sync-dialect-results-2026-09-03.md
  • docs/scalable-authority-foundation.md
  • gateway/README.md
  • gateway/src/neostory_gateway/app.py
  • gateway/src/neostory_gateway/authentication.py
  • gateway/src/neostory_gateway/blob_store.py
  • gateway/src/neostory_gateway/postgres.py