Whatever the solution — a shop counter, a clinic, a bank branch, a border post — four promises decide whether the work survives a bad day. On an ordinary OS each is a hope. Here each is a line the machine declares and the court checks before any device is switched on.
Always reachablea fixed address
The problem. A fridge trips the breaker; the router reboots; it hands the server a new address; the phones and tablets can no longer find it, and a morning's work is stranded.
The machine declares its own address and brings it up before any program runs. It is the same after every power cut, because it was never handed out by anyone.
A stable nameit serves its own names
The problem. The printer comes back on a different number after every outage, and someone re-types it into three devices before service can start.
The machine is the network's name-giver: the printer is reached by name, on a number nobody must remember or re-enter. The register cannot be lost, because it is the declaration.
A durable loga record that survives
The problem. Sales, doses, or filings kept only in a browser or in memory vanish when the address changes or the power drops — and an auditor has nothing to read.
The machine attaches a disk that keeps its data through a power cut before any program starts, and signs a record of every boot with a key only it holds, so a later change to that record cannot go unnoticed. The evidence is there, and nobody can alter it unseen.
Survives the cuttwo copies of the system, a hardware timer
The problem. A breaker, a bad update at 2 a.m., or a technician who unplugs your socket to plug in theirs — and the box does not come back, or comes back broken.
The machine keeps two copies of itself and a hardware timer. A new version is tried once; if it does not recognise its own boot, the box restarts into the one that worked. No one drives out to fix it.
For the programmer
The machine is its own configuration and its own documentation: one text file with a reason on every line, so there is no hidden state to reverse-engineer and no wiki to keep in sync. Write in the language you know — Luau, Python, JavaScript — and the same logic runs wherever the machine places it.
For the system administrator
No shell to secure and no packages to patch — most of what you usually guard is simply not there. A fleet is a set of files: versioned, diffable, and the source every box is built from. Updates are trials that roll back by hardware, and each box tells you what it is and whether its record is whole. Less to defend, and nothing that drifts overnight.
For the auditor
Because there is no shell, there is no undocumented change to hunt for — none can exist. Each program runs as its own declared identity, so who-may-do-what is written into the floor. And administrator access shows up as the absence of a line, not a choice buried in a setting. The machine answers the auditor in its own words.