Multi-link failover
Three virtual links with an interactive impairment menu — inject latency, loss and jitter, kill and restore links, watch delivery-time failover and EWMA recovery in the real engine.
Twenty-four interactive simulations live where their subjects live — this page is the index. Every one carries the same label discipline: a Simulation reproduces the engine’s behaviour faithfully but is not the engine; anything marked Measured links to how it was measured.
Every frame on this site carries its own truth label, but a label at a time makes the whole picture hard to assemble. Here is the spectrum in one view: what each kind of demo costs us to produce, and — much more to the point — what it entitles you to conclude.
A model of the mechanism, written to behave the way the engine does.
That we understand the mechanism and will describe it the same way twice. The shape of a decision — why a share moves, when a path is abandoned, what dedup is for.
Anything at all about the shipping code. A simulation cannot be wrong about the software, because it never touches it.
The shipping binary on one Linux box, with links impaired on purpose.
That the code does this, reproducibly, on hardware you already own. Failover happens because a real socket stopped answering, not because a script said so.
How any of it behaves against physics — real radios, real interference, real weather, real distance.
Real hardware, real geography, real failures — the eight-node fleet and the HEMUS 2026 rig.
That it survives contact with the physical world: re-enumerating USB radios, a 64 kbps serial link beside a gigabit one, six dissimilar bearers bonded on one node.
A guarantee about your environment. These are properties of the configurations stated on the evidence page, not promises about a different sky.
The catalogue below is ordered by mechanism. This is the same set ordered by the thing that went wrong — which is usually how you arrive, because you already know what you are afraid of.
Each link jumps straight to the demo, controls armed.
Five dissimilar links, kill buttons, live reweighting — the signature demo, on the front page where it belongs.
Open on homeFive of the eight strategies over three dissimilar links — including latency-adaptive escalation with a delay injector.
Open on bondingA VSAT link rots and recovers; gradual reweighting against the binary-failover ghost line.
Open on bonding20,000 packets per second of video against a 2 kbps command channel. The command channel wins. Every time.
Open on transportThe same feed through TCP, plain UDP and Tempo during loss bursts — freeze vs tear vs bend.
Open on transportBlackout, queueing bundles, a reboot that loses nothing, and the drain burst when a link returns.
Open on transportThree classes planning their own link sets — jam a link and watch each class re-plan independently.
Open on transportK=8+2 Reed–Solomon shards, one per link; kill one mid-block and watch parity rebuild it in one trip. The simulation shows the shipping striped send path: shards stripe across links weighted by goodput, and the parity floor keeps one link’s death a recoverable erasure while its share stays at or below half the stripe.
Open on transportEight nodes, signed epochs over gossip, cut edges and push anyway.
Open on meshDestroy relays, degrade bands — SPF threads the route through whatever survives.
Open on meshPrediction on: zero drops. Prediction off: the textbook gap. Same flight.
Open on predictionA ridge drifts into the path while nobody moves relative to anyone. Only the elevation model sees it coming.
Open on predictionHidden nodes colliding under CSMA, silenced by a GPS-aligned slot grid — the research direction, animated.
Open on roadmapFive bearers with different range envelopes; fly outward and the bond loses members one envelope at a time, without ever failing over.
Open on integrationsNothing fails — the aircraft simply flies further out, and each bearer’s usable rate falls at its own pace while the split follows.
Open on bondingEvery hop of a multi-hop path is itself a bond. Kill a node and the route swings; kill one radio of a hop and nothing reroutes at all.
Open on meshTwo routes leaving on different first hops carry the same packet; the receiver keeps the first to land. Two copies, not five.
Open on architectureTwo relays moving, one opening range and one closing. Prediction hands over on the trend; without it the path holds until it breaks.
Open on predictionTwo selection policies over the same three links and the same traffic. Degrade one link gradually and watch one pane hold flat then jump, while the other bleeds off continuously.
Open on compareTwo nodes behind their own NATs: relayed, then discovery and rendezvous, then a direct path that is simply an ordinary link with an endpoint. Plus the NAT that will not open.
Open on traversalPush a change that cuts your own path to the fleet. No confirmation can arrive, and every node independently reverts itself when its deadman expires.
Open on operationsTwo sessions overlapping across a key rotation, throughput stacked by which key decrypted it — the total never dips.
Open on securityA 2048-entry sliding window: out-of-order accepted, duplicates and too-old rejected, and the check running after authentication.
Open on securityOne oversized packet split across three links, arriving out of order by construction — then a lost fragment and the janitor that reaps the half-filled buffer.
Open on architectureThree virtual links with an interactive impairment menu — inject latency, loss and jitter, kill and restore links, watch delivery-time failover and EWMA recovery in the real engine.
Broadcast over three links: kill one (zero loss), kill two (still alive), then force 30% loss on all three and measure ~2.7% end-to-end. Measured
Wi-Fi-class and serial-radio-class links under progressively injected impairment — watch the adaptive strategy step 1 → 2 → 3 paths and back down.
Command, relay and edge layers: bonding, single- and multi-hop relay, gateway redundancy, failure scenarios — per-node stats, dashboards and logs included.
Beyond the demos, a set of end-to-end namespace test suites gates every change — what they prove is on evidence.
Separate tools, same telemetry — all three exist because a topology you can see is a topology you can reason about. The dashboard ships on every node; the two visualisers are what you reach for when the picture matters more than the numbers.
The mission simulator: every LSDB node placed at its real position over real elevation data, links coloured by terrain line-of-sight, predictive reroutes drawn as they happen — in demo, live (polling one node’s /api/stats at 1 Hz), or replay mode. The visual companion of the terrain engine.
The underlay viewer: live 802.11s radio topology from any node’s browser — signal, airtime metric, dying links fading out, discovery of hidden multi-hop nodes, and a 3D view. It shows the layer below Atlas, which is exactly why it exists.
Every node ships the best demo: its own live dashboard — the same numbers the CLI and the REST API serve, once a second, with no collector in the middle. Real screenshots are on operations.
The browser versions are simulations. The real thing runs on a table in front of you — links cut by hand, video still flowing. That’s a briefing.