Identity and Device
An account identifies the person or administrator. A registered Device identifies the endpoint using the App or ns. Neither alone decides every destination it can reach.
Operate NetSeed from explicit boundaries: accounts and Devices, one active Organization and Network Space, same-account system rules, directional cross-account Grants, independent NSGW roles and visible control events.
Each answers a different question. Keeping them separate prevents an online status or successful sign-in from being mistaken for authorization.
An account identifies the person or administrator. A registered Device identifies the endpoint using the App or ns. Neither alone decides every destination it can reach.
The Organization holds ownership and membership. The Network holds resources and access configuration. Their selected pair is the current Space, and only one Space is active.
L3 Node access covers an authorized machine and leaves the destination firewall final. L4 Service access narrows the destination to its declared protocol, host and port.
Same-account access to its own Nodes and private Services is system-managed. Cross-account sharing requires an explicit directional Grant to the selected resource.
Relay, Service Egress, Internet Exit and Public Ingress report readiness independently. A gateway being online does not mean every role is ready.
Administrative and system events expose actor, action, resource, time and outcome, with filters and event details for investigation.
The immutable same-account system rule lets an account use its own Nodes and private Services. Sharing with another account is a separate, directional decision represented by an explicit Grant.
System-managed access covers the account's own Nodes and private Services in the current Space.
A Grant selects the subject and resource direction. Reverse access is a separate decision.
The destination host firewall remains authoritative after a Node is authorized.
The declared Service limits the path to a specific protocol, host and port.
NSGW exposes four independent capabilities. Operations should alert on the required role and its current configuration, rather than treating the gateway's generic online state as proof of service readiness.
Supports a relay path when the selected connection needs it.
Provides egress from the gateway toward a configured private Service backend.
Carries an authorized IPv4 default route or selected IPv4 CIDRs when configured.
Accepts configured public L7 or L4 entry paths with their distinct authorization models.
Relayindependent readiness
ReadyService Egressindependent readiness
ReadyInternet Exitindependent readiness
CheckPublic Ingressindependent readiness
ReadyExample composition: online and per-role readiness are intentionally separate.
The Activity log is the primary record for administrative and system events. HMAC-signed Webhooks and external audit export can extend that workflow when configured, but they do not replace the source event or create a certification claim.
Use NSD for current configuration and Activity events, then use the product documentation for the exact recovery and response procedure.
每类边界回答不同问题。将它们分开,才能避免把在线状态或登录成功误认为已经获得资源访问权限。
账号标识人员或管理员,已登记设备标识使用 App 或 ns 的终端;二者都不能单独决定可访问的全部目的地。
组织承载所有权和成员,网络承载资源与访问配置。选中的组合就是当前空间,并且任何时刻只有一个空间处于活动状态。
L3 节点访问覆盖获授权机器,目的端防火墙仍是最终边界;L4 服务把目的地收窄到声明的协议、主机与端口。
同账号访问自己的节点与私有服务由系统管理;跨账号共享必须通过指向所选资源的显式方向性授权。
中继、服务出网、互联网出口与公网入口分别报告就绪状态;网关在线不代表全部能力已经就绪。
管理与系统事件展示操作者、动作、资源、时间与结果,并提供筛选和事件详情用于调查。
不可变的同账号系统规则,让账号能够使用自己的节点和私有服务。与另一个账号共享是独立的方向性决定,由显式授权表达。
系统管理的访问覆盖当前空间内该账号自己的节点和私有服务。
授权选择主体及资源方向;反向访问需要另一项独立决定。
节点获得授权后,目的端主机防火墙仍拥有最终决定权。
已声明服务把路径限制到指定协议、主机与端口。
NSGW 暴露四项独立能力。运营告警应针对所需能力及其当前配置,而不能把网关的一般在线状态当作服务已就绪的证明。
在所选连接需要时提供中继路径。
从网关向已配置的私有服务后端提供出网路径。
配置后承载获授权的 IPv4 默认路由或指定 IPv4 CIDR。
按各自不同的授权模型接收已配置的公网 L7 或 L4 入口路径。
中继独立就绪状态
就绪服务出网独立就绪状态
就绪互联网出口独立就绪状态
检查公网入口独立就绪状态
就绪示意组合:在线状态与各项能力就绪状态有意分开。
活动日志是管理与系统事件的主要记录。配置后,HMAC 签名 Webhook 与外部审计导出可以延伸该流程,但它们不会替代源事件,也不能形成任何认证资质声明。