CI/CD Platform  ·  View 12 of 22  ·  Data

Core Data Model

Ten entities. The one that carries the architecture is a single column on the run.

Editable source SVG draw.io All views
tenant tenant_id PK name concurrency_entitlement priority_weight repository repo_id PK tenant_id FK -> tenant default_branch policy_bundle_version effective_definition definition_digest PK repo_id FK -> repository source_commit compiled_at run run_id PK repo_id FK -> repository definition_digest FK trust_class trigger_event state environment env_id PK tenant_id FK -> tenant name stage_order current_digest deployment deployment_id PK env_id FK -> environment digest FK -> artefact actor_id deployed_at artefact digest PK job_id FK -> job media_type retention_class job job_id PK run_id FK -> run resource_class outcome lease_expiry attempt gate_evaluation evaluation_id PK deployment_id FK -> deployment gate_type verdict reason override_by attestation attestation_id PK digest FK -> artefact log_index signature builder_id 1 : N 1 : N 1 : N 1 : N 1 : N 1 : 1 1 : N 1 : N 1 : N 1 : N CI/CD Platform — Core Data Model trust_class is set once, at admission, and nothing downstream may change it. The run-to-repository link is carried as an attribute rather than an edge, to keep the view readable. v 1.0 · owner Platform Engineering · date 2026-09

Decisions

  • trust_class is a column on run, written at admission and immutable thereafter. Making it a computed view would let a later change of state change the run's privileges, which is precisely the bug the classification exists to prevent.
  • artefact is keyed by digest, not by an identifier the platform allocates, so the same bits produced twice are the same row.
  • deployment references a digest rather than a run, because what was deployed is bits, and a rollback points at bits that an older run produced.

Deliberate omissions

  • The run-to-repository link is carried as an attribute rather than an edge; drawing it as well made the view unreadable without adding information.
  • Secrets, entitlement-change history, cache entries and log objects are omitted — they belong to stores this model does not govern.

Risks

  • gate_evaluation is the audit surface a regulator will ask for, and it is a child of deployment. A gate evaluated but not followed by a deployment therefore needs its own retention path.