NUVL Live Challenge
Live Dashboard
Runtime telemetry / measurement scope / metric definitions
The Live Dashboard exposes runtime telemetry from the public NUVL challenge. It is provided so the running system's behavior can be checked against the published implementation.
Dashboard measurements are recorded by the provider and describe this specific deployment.
Measurement Notes
Traffic Source
The sustained invalid traffic is predominantly self-generated fault-injection traffic from the published challenge harness.
The service is publicly reachable, but the aggregate counters do not distinguish challenge-harness traffic from unsolicited external requests.
Counter Source
Dashboard counters are recorded and served by the provider. They represent provider-observed outcomes and are not independently corroborated.
Separate NUVL endpoint tests use an independent witness on the physical command path where that form of corroboration is available. The live software-only challenge has no equivalent independent observer.
Run Scope
The current live run began May 14, 2026. Cumulative values apply to this provider run.
An earlier Challenge run had already operated for approximately 43 days and processed more than one billion requests before the Live Lab was introduced. Introducing the Lab required restarting the Challenge, so that earlier traffic is not included in the current cumulative counters.
Restarting the provider begins a new run and clears the reference implementation's in-memory replay state. The live reference provider does not provide durable replay persistence across restart.
Deployment Context
The Live Challenge and Path Comparison share a general-purpose DigitalOcean droplet.
CPU, RAM, throughput, latency, and availability measurements characterize this shared deployment. They are not dedicated-host NUVL performance benchmarks.
Service Health
- NUVL
- Current status of the neutral request intermediary.
- Provider
- Current status of the provider process evaluating artifacts and recording admission or denial.
- Uptime
- Elapsed runtime of the current run.
- Run Started
- Start date of the current run.
Service health reports whether the components are operating. It does not establish that provider admission or denial behavior is correct.
Throughput
- Current RPS
- Recent provider request rate.
- Peak RPS
- Highest provider request rate recorded during the current run.
- Avg Response
- Average provider processing time for admitted requests. This is provider processing time, not end-to-end latency observed by the original caller.
- Total Attempts
- Requests accounted for by provider processing during the current run.
Decision Layer
- Initiated
- Requests admitted after provider validation. Initiated records provider admission. It does not represent physical execution.
- Denied
- Requests rejected during provider validation.
- Timed Out
- Inbound provider-processing attempts recorded as timeouts. This counter is separate from control-stream timeouts reported below.
- Internal Errors*
- Internal processing or telemetry failures outside normal admission or denial paths.
* July 14, 2026: Two obsolete Path Comparison processes on the shared host generated approximately 143 GB of error logs and exhausted host storage. The resulting telemetry write failures caused the Challenge to record 293 internal errors. Provider validation and denial continued operating; the failures were in the statistics-write path, not the admission path. The obsolete processes were removed, and the internal-error count has remained at 293 with no recurrence since the incident.
Control Stream
- Sent
- Admitted requests entering the control step represented by the test.
- Completed
- Requests reaching the end of the control step represented by the test.
- Timed Out
- Control-stream operations that did not complete normally.
- Success Rate
- Completed control-stream operations divided by sent control-stream operations.
No physical actuator is attached to the live challenge. Completed means completion of this test step, not completion of a downstream physical action.
System Resources
- CPU Now / Peak
- Current and highest recorded CPU utilization for the monitored provider process.
- RAM Now / Peak
- Current and highest recorded resident memory use for the monitored provider process.
These measurements characterize the shared live deployment. They are operational telemetry, not authorization results or dedicated-host performance benchmarks.
Trends
The time controls select the observation window displayed by the trend panels.
- Requests Per Second
- Provider request rate over the selected interval.
- Decision Outcomes
- Provider admission and denial activity over the selected interval.
- Control Stream Success %
- Control-stream completion rate over the selected interval.
- System Resources
- CPU and memory behavior over the selected interval.
Denial Breakdown
The provider records the validation condition responsible for each denial.
- Malformed
- The submitted artifact or provider token could not be decoded into the required structure.
- Missing Fields
- A required request representation, context, or token was absent or invalid.
- Bad Expiry
- The supplied expiry could not be parsed as the required integer deadline.
- Expired
- The provider-established deadline had passed.
- Mismatch
- The request representation or context did not match the values bound into the provider token.
- Replay
- A nonce already present in the provider's active replay state was submitted again.
- Bad Signature
- Provider HMAC verification failed.
- Bad Context
- The verification context failed provider context requirements.
Validation is ordered. If a request contains multiple defects, the counter records the first rejection reached by the provider. The breakdown therefore attributes each denial to one condition; it is not an inventory of every defect present in the rejected traffic.
Scope
The dashboard is an observability surface for this live challenge.
It provides visibility into provider-recorded admission and denial behavior, denial attribution, control-stream behavior, timeouts and internal errors, request rate, provider response behavior, and resource use.
It does not independently establish:
- physical actuation;
- durable replay protection across provider restart or power loss;
- endpoint-local enforcement;
- persistent consumption of bounded authority at an endpoint;
- resistance to compromise of the provider or its signing material;
- independent corroboration of the provider's dashboard counters;
- attribution of aggregate denial volume to unsolicited external traffic — challenge-harness and unsolicited traffic are not separately counted; or
- generalized NUVL performance outside this deployment.
Those properties require separate evidence and, where applicable, separate enforcement and observation points.
Source and Reproduction
The dashboard is an observation surface. The implementation is published.
Do not trust the dashboard because it says the boundary held. Inspect the implementation. Reproduce the test.