The net's services, from the manifest this host was built from.
| auth | auth | auth.net.classifying.space | Kanidm — the net's issuer: persons, groups, one OAuth2 client per service |
| caddy | daemon | the front door: TLS for the canonical name, one route per declared prefix | |
| check | check | net-eval: safe nix calculations against the composition root; the checker builds every proposal and writes a verdict | |
| dns | daemon | Knot: the net's zone net.classifying.space, generated from this manifest | |
| instructions | face | instructions.net.classifying.space | the instructions store's MCP server: blocks rendered per consumer, proposals as branches |
| instructions.git | store | bare repository /srv/git/instructions.git, served by the git user over ssh and to group git over the filesystem | |
| net.git | store | bare repository /srv/git/net.git, served by the git user over ssh and to group git over the filesystem | |
| nihil.git | store | bare repository /srv/git/nihil.git, served by the git user over ssh and to group git over the filesystem | |
| oauth2-proxy | auth | GitHub sign-in in front of the promotion page — the interim gate until the net's issuer | |
| promote | page | promote.net.classifying.space | proposals on every store, promoted by a tap; shows the deploy and the checker's verdicts |
| reconciler | daemon | deploys main of /srv/git/net.git: switch, health check, record or roll back | |
| tarpit | daemon | endlessh-go: an ssh tarpit on a decoy port |