how it works
From the document you write to the tables the kernel matches against, and what happens when a gateway refuses one.
The policy you write is a source document, not the thing that gets enforced. The platform compiles it into a desired-configuration document that the appliance consumes. Compilation is where a document is accepted or refused, so a policy that survives it is one the datapath can express.
That is why an endpoint written as a prefix is rejected at submission rather than at enforcement. The compiler will not emit something the identity table cannot hold, and it will not quietly emit something narrower than you wrote.
Numbers cross the wire in their natural form
An address is the address, a port is the port. The conversion to whatever byte order the appliance runs happens on the appliance, where the architecture is known. A document that encoded the receiver’s word order would break the first time the fleet was not uniform.
Creating a policy stores it and creating a version stores a revision. Neither takes effect. Activation is the separate step that makes a revision the desired state for the cluster.
Connected gateways are sent the new revision on the stream they already hold. There is no polling interval to wait out and no window where some gateways have asked and others have not.
An acknowledgement carries the revision. A gateway that cannot apply a configuration says so, and the control plane keeps the last revision that was actually accepted rather than recording the one it hoped for.
A refused revision is re-pushed on a bounded cadence rather than in a hot loop, so a gateway that is genuinely unable to apply something does not become a load problem as well as a policy problem.
Activated is not the same as enforced
A revision is enforced on a gateway when that gateway has acknowledged it. Read the policy back and check which revision is live before you rely on it, particularly if any gateway in the cluster was unreachable when you activated.
Each stream has a bounded outbound queue. A gateway that cannot keep up slows the producers rather than letting the control plane buffer without limit on its behalf. The failure mode is a slow rollout you can observe, not memory growth you cannot.