> ## Documentation Index
> Fetch the complete documentation index at: https://docs.connex.hybridsphere.io/llms.txt
> Use this file to discover all available pages before exploring further.

# System Architecture

> NEXUS LAB 126 Master Standards & HybridSphere Enterprise Architecture

CONNEX Cloud OS is built upon the **NEXUS LAB 126 Constitution** and **88 Master Engineering Standards (V31.0)**, delivering zero-defect reliability across multi-region cloud infrastructures.

## End-to-End Request Lifecycle

<Steps>
  <Step title="1. Client Layer (Browser / PWA)" icon="globe">
    Single-page React application delivering 60 FPS streaming, SWR zero-flicker state caching, and optimistic UI updates over HTTPS 443 & WSS.
  </Step>

  <Step title="2. Edge Security & Ingress (GKE L7 Gateway API)" icon="shield-check">
    Managed GKE Gateway API with Google Cloud Armor WAF, SSL certificate mapping, and region-targeted fast-path dispatching.
  </Step>

  <Step title="3. Orchestration Engine (FastAPI Thin Orchestrator)" icon="server">
    Ultra-low latency asynchronous API gateway routing requests under 300ms across distributed multi-region backend services.
  </Step>
</Steps>

## Core Distributed Infrastructure

<CardGroup cols={2}>
  <Card title="Hybrid SSO & Zero-Trust Auth" icon="key" href="/security/zero-trust-auth">
    Firebase Auth credential decoupling with cryptographically signed 7-role JWT token claims.
  </Card>

  <Card title="3-Tier Caching & VFS Hierarchy" icon="database" href="/features/vfs">
    L1 In-Memory LRU + L2 Redis cluster + L3 Cloud Storage with real-time SSE cache invalidation.
  </Card>

  <Card title="Multi-Region Data Sovereignty" icon="globe" href="/security/data-sovereignty">
    Physical database isolation between Seoul (`accounts-kr`) and Iowa (`accounts-us`) complying with PIPA/CCPA/GDPR.
  </Card>

  <Card title="Semantic Kernel & AI Models" icon="cpu" href="/features/agent">
    Agentic RCAG document retrieval, citation fidelity verification, and standalone MCP tool protocol execution.
  </Card>
</CardGroup>

***

## Three Anti-Fraud Engineering Standards

<AccordionGroup>
  <Accordion title="1. Permanent Ban on Arbitrary sleep() Synchronization">
    Inserting `sleep()`—even for 0.1s—to mask race conditions or async pipeline lag is categorized as engineering fraud. All temporal delays must be solved deterministically using protocols (events, locks, SWR caching, sync waves).
  </Accordion>

  <Accordion title="2. Prohibition on Abandoning Critical State Mutations in Background Threads">
    State changes affecting downstream authentication (token issuance, custom claims, permissions) must never be neglected in detached threads; transactions must be explicitly awaited before progressing.
  </Accordion>

  <Accordion title="3. Empirical End-to-End Latency Verification">
    Passing unit tests alone is insufficient. Real runtime HTTP packet latencies to local ports (8080, 8081, 3081) must be directly benchmarked and proven with numerical telemetry.
  </Accordion>
</AccordionGroup>


## Related topics

- [Quickstart Guide](/get-started/quickstart.md)
- [CONNEX | Docs Center](/index.md)
- [CONNEX Cloud OS Releases](/resources/releases.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.