CI/CD Platform  ·  View 02 of 22  ·  Context and scope

High-Level Architecture

Six stages from a push to a promoted digest, with attestation as a stage rather than an afterthought.

Editable source SVG draw.io All views
Trigger Event receiver signed webhooks Dedupe & supersede Admit Definition compiler DAG + policy Trust classifier branch or fork Schedule Fair queue per-tenant slots Dispatcher lease per job Execute Sandbox manager warm pool Single-use microVM one job, then gone Attest Attestor control-plane key Artefact store content-addressed Promote Gate decision service Deployer digest pointer run events CI/CD Platform — High-Level Architecture Interface / broker Application we own Security / platform Queue / topic Data store Decision point event / async The attestor sits in the control plane, so provenance records what the platform observed rather than what the build claimed. v 1.0 · owner Platform Engineering · date 2026-09

Decisions

  • Trust classification happens in Admit, once, before any capacity is committed. Nothing downstream can raise it.
  • The attestor sits in the control plane and signs from what the platform observed. A build can produce a bad artefact but not a credible claim about one.
  • Promote consumes a digest and evidence, never a source commit, so the gate has something verifiable to check.

Why six stages

  • Each stage is a place a run can legitimately stop: rejected, queued, killed, failed, unsigned, or denied. A stage that cannot refuse is not a stage.
  • The single feedback edge is run events flowing back to the scheduler, which is what lets a lost runner be re-dispatched rather than assumed successful.

Risks

  • The control plane mediates every trusted act, so it is both a bottleneck and a blast radius. It must be more available than anything it serves.
  • Single-use sandboxes make cold-start the platform's hardest performance problem; the warm pool is a permanent cost line.