Authority: Normative summary · Status: Local-fixture process boundary implemented; public-origin egress not admitted · Applies to: E3 · Verified against: current checkout · Source:spec/atlas/OBSERVATORY_WORKER_0_1.md,schemas/json/observatory-job.schema.json,schemas/json/observatory-result.schema.json
Purpose
The Atlas control plane has no HTTP client. The Observatory worker is a separate command whose current executable profile accepts only one robots job at a literal127.0.0.1 fixture URL. It cannot contact the selected Atlas
origins.
Evidence order
Failure behavior
The job decoder rejects duplicate keys, unknown fields, trailing data, symlinks, public and private destinations, hostnames, credentials, queries, fragments, redirects, and bodies above 500 KiB. Offline verification recomputes the evidence digests and the robots decision without constructing a client.Security status
The repository includes an unactivated systemd candidate that denies every address except loopback. This is configuration for review, not deployment evidence. Public-origin observation still requires explicitallow policy,
controlled DNS and redirect behavior, network-level egress enforcement,
dedicated credentials, quotas, monitoring, revocation, and disposable workers.
The fixture result is not evidence for the live twirx.org robots
representation and does not change its review_required access state.