Rule one
No controller
There is no master node, no election whose failure stalls the site, and no external orchestrator required for any federated behavior. Coordination state converges through peer-to-peer replication.
OSI-ORB-F1 · Version 0.9 Draft
A single ORB covers a site. Some sites are bigger than one ORB: a 40 km highway corridor, a mine with three pits, a wind farm across two ridgelines, a disaster area spanning a county. Federation is how units become one coverage domain, one policy plane, one ledger, and one management view, while each unit stays fully autonomous.
Doctrine
Every capability here layers on top of a unit that is complete by itself. The loss of any unit, link, or coordination service degrades the federation gracefully back toward independent operation, never below it. Three design rules are normative.
Rule one
There is no master node, no election whose failure stalls the site, and no external orchestrator required for any federated behavior. Coordination state converges through peer-to-peer replication.
Rule two
Federation uses only the radios, transport links, and management channels already specified in ORB-1 and ORB-C1. Nothing is added to the crate to make units work together.
Rule three
Units federate because they share a site identity delivered through provisioning, not because anyone drew a topology. The topology is discovered, and it changes as units arrive and leave.
Discovery
Federation forms under any connectivity condition a real site presents. Mutual authentication in all three channels chains to the provisioned device identity: a unit that cannot prove membership in the site identity is a neighbor to be coexisted with, never a peer to be joined.
| Channel | Carried on | What it covers |
|---|---|---|
| Management plane | LTE-M provisioned identity and site assignment | Units learn their siblings' existence, keys, and last-known positions before they can hear each other. A unit still in its crate already knows the federation it will join. |
| Transport tier | 5.8 GHz PtP, wireless fiber, or wired interconnect | A peer discovery and authentication exchange runs on link-up, which is how chains and rings self-assemble as dishes are aimed. |
| Over the air | NR+ coordination beaconing and shared ledger state | Units within radio range detect sibling identity directly, covering two units deployed within earshot before any transport link exists. |
Synchronization
What actually synchronizes between units, and what the operator sees as a result.
| Domain | What replicates | Behavior |
|---|---|---|
| Spectrum | SAS grant state, channel and power plans, TVWS channel sets, Wi-Fi and AFC plans | Sectors of adjacent units interlock rather than collide. TDD phase alignment comes free from the common GNSS base, and the uplink-heavy frame structure is applied federation-wide. |
| Mobility | Handover context, slice membership, QoS policy, ledger identity | A haul truck driving 15 km transits five ORBs as one continuous attachment, make-before-break across both the CBRS and TVWS tiers. Nothing re-authenticates at a coverage boundary. |
| WAN | Pooled path set across every unit in the chain | One fibered handoff at the south end and one LEO terminal at the north end serve the whole corridor. A chain of N units needs one or two WAN subscriptions, not N. |
| The ledger | Append-only, identity-signed grant, attachment, and position records | Each unit writes locally and replicates peer-to-peer. Any single unit answers an audit query for the whole site, and records merge on rejoin with nothing to reconcile, only to interleave. |
| Policy and tenancy | Slice definitions, authentication, QoS class, WAN policy, accounting | A tenant defined on one unit exists on all units. A subcontractor's devices work identically at either end of a corridor and their accounting aggregates site-wide. |
| Compute and content | Class A edge workloads, site caches, plans, models, firmware images | Capture workloads process on the nearest unit with capacity and caches replicate, so the site feels identical everywhere on it. |
Topologies
Topology is descriptive, not configured: the federation is whatever the discovered link graph says it is, and it changes as dishes are aimed, units arrive, and units leave.
| Topology | Formed by | Fits | Failure behavior |
|---|---|---|---|
| Chain | Sequential 5.8 GHz or wireless fiber hops | Corridors: highways, pipelines, rail, transmission lines | A broken hop splits the chain into two federations, each fully functional; WAN re-pools per side |
| Ring | Chain closed back on itself, or dual-homed ends | Large area sites wanting hop redundancy | Any single hop loss leaves the ring connected; no split |
| Star | Spoke units on transport links to one anchor | A central pit or yard with satellite work areas | Spoke loss isolates one unit into autonomous operation; anchor loss reverts all spokes to autonomy |
| Cluster | Overlapping coverage, with or without transport links | Dense sites, staged deployments, disaster surges | Degrades continuously; any subset of units federates among itself |
Multi-site fleets federate one level up through the management plane, which provides fleet-wide views and policy without ever sitting in the data or coordination path. The management plane can see every federation and is required by none of them.
Architecture
That is what permits the no-controller rule. Convergence is eventual and bounded, and correctness never depends on it.
Partition behavior
Partition behavior follows from the same design. Nothing about a severed link is exceptional.
The operator's view
Commissioning discipline is unchanged from a single unit: place it, power it, aim the dish if there is one, and the unit finds its site, its siblings, and its role.
Coverage
Every added unit extends the site rather than fighting the last one. Adding a unit adds capacity, which is the opposite of what uncoordinated equipment does.
Devices
A machine, a phone, or a camera works identically across the whole deployment, at vehicle speed, across as many units as the ground takes.
Economics
One fiber handoff or one LEO terminal serves the corridor. WAN pooling is the largest single economic effect of federating a deployment.
Operations
One ledger, one tenant list, one management view, however many units it takes to cover the ground.
Conformance
The federation profile extends the ORB-1 conformance suite. A unit claiming ORB-F1 conformance passes the suite in both roles.
Tell us the corridor, the pits, or the county. We will lay out the chain, the transport hops, and the WAN handoffs, or send the federation specification for engineering review.