What the platform accepts
Zero is a shared platform. There are two ways to decide what a customer may run on it: accept everything and block what is dangerous, or accept only what is described.
The first is a race you lose: the list of dangerous things grows with every new vulnerability, and every forgotten item is a hole. Zero chose the second.
A catalog, not a list of prohibitions
The platform accepts only what is in the catalog. And the strongest form of that rule is not a validator that refuses: it is that there is no way to ask. The input model has no field for privileged server access, for mounting host directories, or for describing execution freely. There is nothing to refuse, because there is no way to express it.
For the same reason, an artifact reference uses the image's fingerprint and not a movable tag: "promote the same immutable artifact" is not a rule someone checks, it is the only thing the model can express.
When something is refused
A refusal always comes with an explanation and an alternative, in product language:
This application requests administrative access to the server, which Zero does not allow in shared environments. Remove that requirement or deploy to a dedicated environment.
And never with a raw infrastructure error. An automated check fails the platform build if any user-facing text mentions internal infrastructure vocabulary.
What the platform never hands to the customer
Internal monitoring dashboards, administrative infrastructure credentials, direct access to the control database. Those tools exist and are operated — as NNumbers infrastructure, not as a product interface.
What you get instead: traffic and consumption measured, logs from all three sources, deployment history, and structured evidence when something fails.
What it costs and what it buys
The cost is real: you do not write the execution description freely. What you gain:
- The same decision for everyone — update strategy, health checking, network isolation, and quota are settled once, with the same standard.
- A smaller risk surface — what does not exist does not need defending.
- Readable refusals — at configuration time, not at three in the morning.
Next steps
- Services — what you can declare
- Resources and limits
- What exists today
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.