Skip to main content

Glossary

TermMeaning
Auth modeHow a route authenticates callers: public, browser, or api-jwt.
dns_subdomainYour team's authoritative DNS subdomain. Route hostnames are always derived from it, never supplied by a team.
Gateway clusterA Pneuma GKE cluster that runs the shared ingress gateway. Member clusters have no public endpoint.
Logos specYour team's record in the Logos repository: team data, namespaces, routes, and auth policies. Nomos writes it; you never edit it by hand.
Member clusterA team GKE cluster that joins the mesh and is reached through the gateway cluster.
Mesh-enabled namespaceA namespace enrolled in the mesh. Routes and auth policies are valid only on these.
Nomos AgentThe agent that validates team requests and opens pull requests in the owning repositories.
RouteA service, port, and optional path prefix you ask Nomos for to serve traffic at your team's hostname.
Route auth policyThe authentication requirement attached to a route, keyed by the route name under route_auth_policies.