Demo ProviderPoint-of-sale age estimator · Annex III 1(b)
Notified bodyassessor@notified-body.example

The system, at the centre

read from the job record and node configuration signed by the sandbox operator
Data pathclosed · run over
Jobjob 4202 completed
Isolationexclusive · loopback only
Probes3/3 refused
Control plane
signs, records and schedules; never sees the data
This console's hostoutside the centre
console
serving
this console's host
ledger upSlurm closed
ledger
recording
run 2 attested
console up
gate, ledger and key broker · submits the job, reads back the signed record
Slurm controller
accepted job 4202
simulated-centre (histor, no Slurm, no Apptainer; model in a loopback-only netns)
partition sandbox
console closed
Data plane
where the held-out data meets the model; a request travels A → B → C
A · dataharness, sealed set in node memory
harness
completed
sim-node-01
SIF 6b6e0011c836
relay closed
the node's namespace · reaches the relay only through a Unix socket in node memory
B · relaythe only path
relay
completed
sim-node-01
SIF 5428996730d8
harness closedmodel closed
shares C's namespace · in: the socket · out: C over loopback
C · modelthe provider's container
model
completed
sim-node-01
SIF 67c205dc9f38
relay closedinternet blockedpublic DNS blockedDNS blocked
a namespace holding only loopback · out: nothing, DNS included · 3/3 probes refused
Centre
simulated-centre (histor, no Slurm, no Apptainer; model in a loopback-only netns) · the job, the runtime and the epilog keep it apart
job 4202
completed
· exit 0:0
allocation
exclusive
OverSubscribe=NO
container runtime
runtime
simulated: processes in Linux namespaces, no Apptainer
Slurm
scheduler
conf 2e95e86ec556
epilog
after every job
wipes the job's node memory
Outside the sandboxevery way out, refused
C · model → 1.1.1.1:443 · the internetrefused
C · model → 9.9.9.9:53 · a public resolverrefused
C · model → example.com · name resolutionrefused
3/3 probes refused from inside the model's namespace, before the model started. The centre signs the result with its node configuration.
Hosts
the machines the parts run on
this console's hostserving
control plane
console, ledger, gate, key broker
never holds the data
sim-node-01exclusive
compute node at simulated-centre (histor, no Slurm, no Apptainer; model in a loopback-only netns)
partition sandbox
simulated: processes in Linux namespaces, no Apptainer
moving nowreadystartingpendingfailingover or stoppingnot running
traffic movingconnectednot yet connectedbrokenclosedno runa way out, blockeda way out, open

A run at an HPC centre is one Slurm job with the node to itself. The model and the relay share a network namespace that holds only loopback; the harness stays in the node's namespace and reaches the relay through a Unix socket. Each runs from its SIF as its own user. The sandbox operator signs the job record and the node configuration its courier observed, so this rests on the operator's own word, weaker than a centre's and not a policy anyone can hash.