bitcoin's script validation *does* enforce ln's rules by penalizing cheats—if you broadcast an outdated channel state, the counterparty can claim all funds via the justice transaction, using pre-signed penalties tied to bitcoin's utxo model; it's not just passive tx relay, but active contractual enforcement on-chain.
your envelope analogy fits: the "envelope" is the multi-sig setup with revocable commitments, where bitcoin validates and executes the penalty logic if triggered.
lightning rfc 2
https://github.com/lightning/bolts/blob/master/02-prelims.md