The category, defined

Declared Infrastructure

There are two kinds of infrastructure: declared, and archaeological. One can answer for itself. The other is answered for — at 3am, from logs, by whoever remembers. This page is the strict definition of the first kind, published by the people who run the reference implementation.

declared infrastructure — n.

Infrastructure in which every running thing is preceded, governed, and continuously judged by its declaration — so that "what is running?" and "what should be running?" are one query with one answer.

The three laws

Strict, on purpose. Most vendors fail all three.

"Declarative" describes tooling — how you write configs. Declared describes the infrastructure itself — a state it is in, or is not. These are the tests. A system that fails any one of them is not Declared Infrastructure, whatever its brochure says.

LAW 01

Declaration precedes existence

Nothing runs that wasn't declared first. Identity, address, role, and certificate are consequences of the declaration — derived, never chosen, never retrofitted.

LAW 02

The declaration is a runtime authority

Not documentation. Not a diagram. The declaration is queried, enforced, and diffed against reality continuously. If your source of truth can be stale, it isn't a source of truth — it's a diary.

LAW 03

Undeclared reality is corrected or refused

A port nobody declared, a cert nobody issued, a host nobody minted — drift is closed or rejected, never quietly absorbed into a new normal.

The lineage

The market keeps a CMDB. We never did.

This category wasn't invented for a brochure. Our source of truth has been called the DDB — the Declarative Database — since the first node, because it never worked like the thing the market keeps.

A CMDB — theirs

Records what someone once believed was true.

Populated after the fact. Audited quarterly. Wrong by Tuesday. The place where documentation goes to die — and where every 3am investigation starts, because nothing else even claims to know.

The DDB — ours

Decides what is allowed to exist.

The declaration comes first; the infrastructure is its consequence. Our certificate authority won't sign for a machine the DDB doesn't know. Our DNS publishes what the DDB derived. Our agents judge every node against what the DDB declared. It cannot go stale, because reality is downstream of it.

Claims & receipts

Outlandish, and checkable. That's the point.

Every claim below sounds like marketing and is literally true. We can afford this game because declaration makes each one demonstrable on demand — ask, and we'll show you the one that sounds most impossible.

We ship clouds on USB sticks.

Plug one into bare metal; come back to a sovereign cloud — hypervisors, DNS, certificates, message bus, and a live map of all of it. It's how we build our own sites.

Our network is readable as a database.

Every machine, address, VLAN, and certificate is a row you can query. Declare a node and its hostname is derived by math, not chosen by a person.

Failures confess in under a second.

Restart a service on camera and watch the map change before your SSH prompt returns. Monitoring reconstructs; awareness already knows.

Our address space spells our name.

The ULA prefix decodes to "cnTnc" in hex. A joke — and a receipt: addressing so deliberate there was room for one.

The vendor test

Three questions. Ask us first.

Take these to any vendor claiming the word "declarative" — including us. We publish the test because we're the only ones who want you to ask.

Q1

Can anything run that wasn't declared?

If yes — their infrastructure isn't declared, it's documented. A state file is a memory, not an authority.

Q2

Show me declared vs. running. Live. Right now.

Not a report from the last scan — the continuous diff. This is the column no one else can render.

Q3

What happens to undeclared reality?

If the answer is "it gets imported," drift just became the new baseline. Ours gets corrected or refused — and somebody doesn't get paged.