CI/CD Platform  ·  View 11 of 22  ·  Data

Storage Zones by Ownership and Rebuildability

Four zones, ordered by what happens if the data is lost.

Editable source SVG draw.io All views
Authoritative and mutable — RPO 0 Run metadata Runs and jobs Aurora, multi-AZ Tenants and entitlements Delivery state Environment pointers Deployment locks Write-once evidence — immutable, 7 years Artefacts Artefact store S3 by digest SBOM store Proof Transparency log Object Lock Audit trail Replayable — bounded loss tolerated Event and log Run event log RPO 0, 400 days Log store 14d hot, 90d warm Disposable — no RPO, rebuilt on demand Derived Build cache 90 TB working set Dependency mirror Warm pool images digest recorded CI/CD Platform — Storage Zones by Ownership and Rebuildability Data store Queue / topic Security / platform synchronous The largest and hottest stores are the disposable ones. The smallest are the ones that can never be lost or altered. v 1.0 · owner Platform Engineering · date 2026-09

The inversion worth noticing

  • The largest and hottest stores are the disposable ones: a 90 TB cache and the warm-pool images. They have no RPO because they are rebuilt on demand.
  • The smallest stores carry the strictest requirements: the transparency log and audit trail are write-once and retained seven years.
  • That inversion is what makes cost tuning safe. The platform's biggest storage lever touches none of its evidence.

Realisation

  • Aurora multi-AZ for authoritative mutable state, RPO 0 / RTO 15 min.
  • S3 with Object Lock for the transparency log and audit trail; cross-region replication for artefacts and attestations, RPO 0 / RTO 1 h.
  • Run event log RPO 0 / RTO 30 min; log store RPO 5 min / RTO 1 h.

Assumptions

  • Retention: run metadata 400 days; release artefacts 400 days; main-branch 90 days; pull-request 14 days; caches evicted after 7 days idle.