CI/CD Platform  ·  View 10 of 22  ·  Data

Run and Evidence Data Flow

From a commit to an audit line, with the sealing step that makes everything after it verifiable.

Editable source SVG draw.io All views
Sources Commit + definition Declared dependencies Admitted Effective definition immutable Run record Executing Build output Log stream Cache write trusted only Sealed Artefact digest Provenance + SBOM Serving Run history Environment pointer Audit trail write-once Consumers Engineers Gate decisions Auditors tail then tier verified before pointer moves CI/CD Platform — Run and Evidence Data Flow External / third party Data store Application we own Queue / topic Person or role Decision point event / async synchronous Evidence is written before the pointer moves, never after. A run that cannot record its audit line does not complete. v 1.0 · owner Platform Engineering · date 2026-09

Decisions

  • The effective definition — templates expanded, digests pinned, parameters bound — is written as an immutable artefact of the run, because the repository that produced it is mutable and the run record must not be.
  • Cache write is shown as a separate flow because only trusted runs perform it. That asymmetry is a data-flow fact, not a permission detail.
  • The audit record is durable before the environment pointer moves. A run that cannot write its evidence does not complete.

Assumptions

  • 6 TB/day of raw log output; 480 TB of retained artefacts growing 40%/year; 90 TB cache working set.
  • Logs 14 days searchable, 90 days retrievable, 400 days cold for release pipelines only.

Risks

  • Log volume is the fastest-growing cost in the set and the easiest to over-retain. Retention is set per pipeline class rather than globally for exactly that reason.