Notre fallback behavior
Fail-open guarantees when Notre is off, errors, or unavailable.
Fail-open is a core design principle. Customers should never lose a completion because Notre was enabled. When NOTRE_MODE is off, the gateway strips a client notre object and does not apply Runtime. When apply is on and the core is missing or throws, the original chat body still goes upstream.
- Notre internal error → original request proceeds
- Notre declines intervention → original request proceeds
- Deployment without Notre → behaves as if mode were off
- telemetry: false → response shape unchanged even when Notre runs