4Runr Project / Infrastructure
Active
4Runr Gateway
Your security posture. Wherever you go.
Portable security and network control that travels with you.
The problem
The network keeps changing. The assumptions follow it.
Home
Trusted
One device
Office
Different
One device
Hotel
Untrusted
One device
Client
Unknown
One device
Your location shouldn't decide your security posture.
What changes
Gateway becomes the boundary.
Outside
External network
Home
Hotel
Client
Unknown
Boundary
4Runr Gateway
Policy stays here.
Protected
Your devices
Governed by Gateway
The outside network can change. The protected side remains governed by Gateway policy.
Policy
Environment-aware enforcement. Tested.
Home / Admin
Starting state
Network change
Lab / Trusted
After network change
Return home
Home / Admin
Return home
The security posture changes with the environment. This is a tested example, not a concept sketch.
Architecture
Three layers.
01
Connectivity
Gateway controls how devices reach external networks.
Your devices
4Runr Gateway
External networks
02
Trust and enforcement
Policy sits on the boundary. These are the controls Gateway is built around.
Uplink trust
Device admission
Quarantine
Internet access
DNS
Firewall policy
Admin access
WireGuard access
Service exposure
Recovery / failover
03
Intelligence and management
Gateway Console turns infrastructure state into operational information.
Engineering proof
Declared state is not enough. Enforcement has to change.
Declared state
What the system believes about the environment.
Enforced state
What the firewall actually does after policy rebuild.
01
Environment detected
02
Trust level selected
03
Policy rebuilt
04
Firewall enforcement
05
Verification
Firewall behavior has been tested to change when Gateway trust state changes.
The larger system
Gateway is the security edge.
Device
4Runr Gateway
Secure path
4Runr Nodes
Applications / private infrastructure
Gateway controls the secure path into the rest of the system.
Currently built
Portable security and network control, with environment-aware policy on the edge.
Architectural direction
Authorized device + authorized Gateway + allowed policy = access to the services that device is permitted to use. This full authentication experience is not presented as finished.
Current state
What has been implemented or tested.
Portable gateway architecture
Multiple uplink trust levels
ADMIN / TRUSTED policy behavior
Dynamic administrative-path enforcement
Firewall policy changes
WireGuard-based private access
Device and network enforcement
Operational Gateway Console
Secure access toward private 4Runr infrastructure
Listed as implemented or tested. Not marked as a finished product.
Direction
The edge of something larger.
Built
- Portable security
- Network control
- Environment-aware policy
In development
- Deeper Node / infrastructure integration
Direction
- Unified identity, policy, infrastructure and application access
No dates. Planned work is not presented as completed functionality.

