Infrastructure fabric since 1998
Sentinel Grid
The substrate everything else runs on.
A private compute and storage fabric spanning our sites, built on the assumption that any site can be unreachable at any time and that the institution must keep functioning while it is. Every record has custody in at least three places and can prove it.
Purpose
Keep institutional custody and compute functioning when any site is unreachable for an unbounded period.
Architecture
- Zero-trust between sites; no implicit intra-network authority
- Content-addressed storage with independent integrity audit
- Partition-tolerant by construction
- Full state reconstructible from any two surviving sites
Design constraints
- Must not require a permanent primary
- Must degrade honestly under split-brain
- Must not invent a single vendor kill-switch
Failure modes
- Confident divergence after long partition
- Silent bit-rot if audit cadence slips
- Operational pressure to temporarily 'trust the LAN'
Historical development
Designed after repeated seasonal isolation made commercial fabrics feel like optimism. Entered service 1998 (SEN-98-003).
Known limitations
- Does not make latency small
- Does not replace local competence at a site
- Cannot recover what was never written
We do not claim systems are perfect. We document how they fail.