Every node runs the gateway. It verifies the session, then dials the service ok.yaml names for that path.
The browser and other nodes talk to the gateway. The longest path prefix wins. Auth and geo are public. Other API routes require a Bearer token. Pages continue to the web app on this node.
Placement decides the dial. Mesh stays on this node. Control and catalog dial the central service. A workspace route looks up workspace:route:{workspace_id} in Redis, where workspace_id is the JWT workspace claim, one id per token. The value is an address. A missing port uses that service’s dev port. In production a missing workspace node is a 404.
After the token checks, the gateway sets the user id, role, and that workspace on the request. The service still verifies the Bearer token. A WebSocket upgrade stays on HTTP/1.1.