K05 assurance architecture

Live-Host Verification

Direct answer

Live-host verification begins only after confirmed deployment. It checks transport, headers, canonical routing, error behavior, exact release identity, and static-host configuration without treating page availability as evidence of autonomous-system operation.

Evidence boundary. These records describe architecture, control relationships, test requirements, and legal-source status. They do not certify a facility, authorize a mission, prove deployment, or replace current facility-specific engineering and legal review.

Current state

NOT OBSERVED

No owner-confirmed K05 deployment was available during package creation. DNS, TLS, server redirects, response headers, compression, cache behavior, Apache modules, permissions, and actual live route behavior therefore remain unverified.

Checks required after deployment

  • DNS and ACE/Unicode identity
  • TLS certificate and chain
  • HTTP to HTTPS redirect
  • canonical host redirect
  • representative status codes
  • content types
  • compression
  • cache behavior
  • CSP and security headers
  • robots and sitemap
  • custom 404
  • exact deployed version and manifest hash
  • no Passenger or application-runtime takeover

What a live page still would not prove

  • A page loading does not prove autonomous-system operation
  • A valid TLS certificate does not prove release identity
  • A deployed site does not prove a protected datacenter capability

Machine-readable verification template