Skip to content
U1.ca NAMES
Control Plane 1 · Proposed public authoritative service class

dns0.ca

The designated public administrative and authoritative-service apex within the Sovereign Seven architecture.

dns0.ca defines the public-plane control identity in a conceptual Canadian DNS namespace model. It does not presently operate as a live authoritative service or public resolver.

r1.ca · dns0.ca · ns1.ca–ns7.ca · ix1.ca–ix7.ca · ns9.ca
CONTROL PLANE 1
Sovereign Seven — provisional Control Plane 1 architecture visual.
Architecture roles

Control Plane 1 namespace roles

The model separates recursive service identity, administrative authority, authoritative serving identities, operational telemetry, and hidden-primary provisioning.

01

r1.ca

Separate recursive resolver service identity. It is not part of the authoritative serving path.

02

dns0.ca

Designated administrative and authoritative-service apex for the proposed public service class.

03

ns1.ca–ns7.ca

Proposed public authoritative service identities with candidate regional alignments across Canada.

04

ix1.ca–ix7.ca

Unicast operations and telemetry identities associated with the seven authoritative service identities; not claims of operating Internet exchanges.

05

ns9.ca

Reserved hidden-primary identity for provisioning and synchronization. It would not be published in the public NS delegation.

06

Namespace0

Shared internal taxonomy for routing, DNS, delivery, security, telemetry, compute, data, and AI primitives.

Role separation

Authority, recursion, operations, and provisioning remain distinct.

The authoritative plane serves zone data; the recursive identity represents a separate client-resolution service class. The architecture does not place r1.ca upstream of the authoritative nodes.

The hidden primary is represented only by ns9.ca in this plane. Its intended role is private provisioning and synchronization rather than public query service.

Anycast is an intended deployment model, not a property of the names themselves. Actual service would require shared service addresses, routing policy, node health controls, synchronized data, DDoS engineering, and operational governance.

Conceptual architecture. This is a namespace and infrastructure reference model, not a deployed production DNS, resolver, registry, anycast, cloud, or telecommunications service. No affiliation with or endorsement from CIRA is implied or claimed.