CI/CD Platform · View 08 of 22 · Structure
Decisions
- The signing key is reachable only from the attestor, which runs in the control plane. No path exists from an isolation host to it.
- The job queue is durable and separate from the run event log: the queue is work to be done, the log is what happened. Conflating them makes recovery ambiguous.
- Stores are grouped by mutability, not by technology: transactional state, write-once evidence, and state that can be thrown away have different availability, retention and cost answers.
Realisation
- Control plane and gate service on EKS across three AZs; scheduler sharded with a leader per shard.
- Aurora PostgreSQL for run metadata and the environment registry; S3 for artefacts, logs and the transparency log with Object Lock.
- Isolation hosts are nested-virtualisation-capable EC2 instances running a microVM hypervisor, one job per VM.
Deliberate omissions
- Five edges of many. The ones drawn are the job assignment, the attestation path, the cache read, and the only outbound deploy.