CI/CD Platform  ·  View 08 of 22  ·  Structure

Containers and Components

One control plane, one execution plane, three kinds of store — because there are three mutabilities to hold.

Editable source SVG draw.io All views
Control plane — never executes tenant code Admission services Event receiver EKS service Definition compiler DAG + schema Trust classifier Orchestration Run state machine lease per job Fair scheduler Job queue SQS, durable Run event log Kinesis Trust services Secret broker Identity federation OIDC, per job Attestor KMS signing key Gate decision service Execution plane — untrusted Capacity management Sandbox manager Warm pool Capacity autoscaler Isolation host microVM hypervisor one job per VM Per-job agent Egress proxy Stores Mutable state Run metadata Aurora PostgreSQL Environment registry Write-once evidence Artefact store S3, digest-addressed Transparency log Object Lock Log store Disposable Build cache rebuildable Dependency mirror Source control Container registry Runtime platforms job assignment build inputs signed record read wide allowed deploy CI/CD Platform — Containers and Components Interface / broker Application we own Security / platform Queue / topic Decision point Data store External / third party synchronous Three store groups because there are three mutabilities: transactional state, write-once evidence, and state that can be thrown away. v 1.0 · owner Platform Engineering · date 2026-09

Decisions

  • The signing key is reachable only from the attestor, which runs in the control plane. No path exists from an isolation host to it.
  • The job queue is durable and separate from the run event log: the queue is work to be done, the log is what happened. Conflating them makes recovery ambiguous.
  • Stores are grouped by mutability, not by technology: transactional state, write-once evidence, and state that can be thrown away have different availability, retention and cost answers.

Realisation

  • Control plane and gate service on EKS across three AZs; scheduler sharded with a leader per shard.
  • Aurora PostgreSQL for run metadata and the environment registry; S3 for artefacts, logs and the transparency log with Object Lock.
  • Isolation hosts are nested-virtualisation-capable EC2 instances running a microVM hypervisor, one job per VM.

Deliberate omissions

  • Five edges of many. The ones drawn are the job assignment, the attestation path, the cache read, and the only outbound deploy.