[
  {
    "id": "01-system-context",
    "title": "CI/CD Platform — System Context",
    "layout": "context",
    "system": {
      "label": "CI/CD Platform",
      "sub": "commit to production"
    },
    "colWidth": 260,
    "groups": [
      {
        "side": "left",
        "title": "People who push and review",
        "nodes": [
          {
            "id": "dev",
            "label": "Application engineer",
            "kind": "actor",
            "rel": "pushes commits",
            "dir": "in"
          },
          {
            "id": "rev",
            "label": "Code reviewer",
            "kind": "actor",
            "rel": "approves merge",
            "dir": "in"
          },
          {
            "id": "ext",
            "label": "Outside contributor",
            "kind": "actor",
            "rel": "opens fork PR",
            "dir": "in"
          },
          {
            "id": "plat",
            "label": "Platform engineer",
            "kind": "actor",
            "rel": "owns capacity",
            "dir": "in"
          }
        ]
      },
      {
        "side": "right",
        "title": "Systems of record",
        "nodes": [
          {
            "id": "vcs",
            "label": "Source control",
            "kind": "external",
            "rel": "events, definitions",
            "dir": "in"
          },
          {
            "id": "pkg",
            "label": "Package registries",
            "kind": "external",
            "rel": "dependencies",
            "dir": "in"
          },
          {
            "id": "reg",
            "label": "Container registry",
            "kind": "external",
            "rel": "publishes images"
          },
          {
            "id": "idp",
            "label": "Identity provider",
            "kind": "external",
            "rel": "authenticates",
            "dir": "in"
          }
        ]
      },
      {
        "side": "top",
        "title": "Accountable for release",
        "nodes": [
          {
            "id": "rel",
            "label": "Release owner",
            "kind": "actor",
            "rel": "approves promotion",
            "dir": "in"
          },
          {
            "id": "sec",
            "label": "Security engineering",
            "kind": "actor",
            "rel": "sets gate policy",
            "dir": "in"
          }
        ]
      },
      {
        "side": "bottom",
        "title": "Targets and consumers",
        "nodes": [
          {
            "id": "rt",
            "label": "Runtime platforms",
            "kind": "external",
            "rel": "deploys to"
          },
          {
            "id": "audit",
            "label": "Audit and compliance",
            "kind": "external",
            "rel": "evidence feed",
            "kind2": "batch"
          },
          {
            "id": "cloud",
            "label": "Cloud control planes",
            "kind": "external",
            "rel": "provisions capacity"
          }
        ]
      }
    ],
    "note": "Test authoring, the runtime platform and the registries are outside the boundary. The platform reads source control and never writes to it.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "02-high-level-architecture",
    "title": "CI/CD Platform — High-Level Architecture",
    "layout": "flow",
    "chain": true,
    "align": "middle",
    "stages": [
      {
        "title": "Trigger",
        "nodes": [
          {
            "id": "recv",
            "label": "Event receiver",
            "sub": "signed webhooks",
            "kind": "integration"
          },
          {
            "id": "dedupe",
            "label": "Dedupe & supersede",
            "kind": "app"
          }
        ]
      },
      {
        "title": "Admit",
        "nodes": [
          {
            "id": "compile",
            "label": "Definition compiler",
            "sub": "DAG + policy",
            "kind": "app"
          },
          {
            "id": "classify",
            "label": "Trust classifier",
            "sub": "branch or fork",
            "kind": "security"
          }
        ]
      },
      {
        "title": "Schedule",
        "nodes": [
          {
            "id": "queue",
            "label": "Fair queue",
            "sub": "per-tenant slots",
            "kind": "queue"
          },
          {
            "id": "dispatch",
            "label": "Dispatcher",
            "sub": "lease per job",
            "kind": "app"
          }
        ]
      },
      {
        "title": "Execute",
        "nodes": [
          {
            "id": "sbmgr",
            "label": "Sandbox manager",
            "sub": "warm pool",
            "kind": "app"
          },
          {
            "id": "vm",
            "label": "Single-use microVM",
            "sub": "one job, then gone",
            "kind": "platform"
          }
        ]
      },
      {
        "title": "Attest",
        "nodes": [
          {
            "id": "attestor",
            "label": "Attestor",
            "sub": "control-plane key",
            "kind": "security"
          },
          {
            "id": "cas",
            "label": "Artefact store",
            "sub": "content-addressed",
            "kind": "store"
          }
        ]
      },
      {
        "title": "Promote",
        "nodes": [
          {
            "id": "gate",
            "label": "Gate decision service",
            "kind": "decision"
          },
          {
            "id": "deploy",
            "label": "Deployer",
            "sub": "digest pointer",
            "kind": "app"
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "vm",
        "to": "queue",
        "label": "run events",
        "kind": "async",
        "route": "rl"
      }
    ],
    "note": "The attestor sits in the control plane, so provenance records what the platform observed rather than what the build claimed.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "03-actors-and-journeys",
    "title": "CI/CD Platform — Actors and Their Core Journeys",
    "layout": "actors",
    "cardWidth": 280,
    "groups": [
      {
        "title": "Inside the company",
        "kind": "boundary",
        "actors": [
          {
            "id": "dev",
            "label": "Application engineer",
            "sub": "4,200 in 610 teams",
            "goal": "Tell me in minutes whether my change is safe to merge, and if it is not, tell me what I broke rather than making me guess.",
            "journeys": [
              {
                "id": "j-check",
                "label": "Get a green check"
              },
              {
                "label": "Reproduce a red job"
              }
            ]
          },
          {
            "id": "rev",
            "label": "Code reviewer",
            "sub": "every merge",
            "goal": "Let me trust the check beside the diff so I review the change instead of re-running the build.",
            "journeys": [
              {
                "label": "Read the evidence on a PR"
              }
            ]
          },
          {
            "id": "plat",
            "label": "Platform engineer",
            "sub": "14 people",
            "goal": "Keep 40,000 slots busy without letting one monorepo starve everyone else, and know when a failure is ours.",
            "journeys": [
              {
                "label": "Rebalance entitlements"
              },
              {
                "label": "Triage infra-failure ratio"
              }
            ]
          }
        ]
      },
      {
        "title": "Accountable for what ships",
        "kind": "boundary",
        "actors": [
          {
            "id": "rel",
            "label": "Release owner",
            "sub": "9 business units",
            "goal": "Ship exactly the bits we tested, and be able to take them back in five minutes without a rebuild.",
            "journeys": [
              {
                "id": "j-ship",
                "label": "Promote and roll back"
              }
            ]
          },
          {
            "id": "sec",
            "label": "Security engineer",
            "sub": "policy owner",
            "goal": "Make the safe path the default path, so no team has to remember to be careful about a fork build.",
            "journeys": [
              {
                "label": "Change a gate policy"
              },
              {
                "label": "Answer an audit request"
              }
            ]
          }
        ]
      },
      {
        "title": "Outside the company",
        "kind": "cloud",
        "actors": [
          {
            "id": "ext",
            "label": "Outside contributor",
            "sub": "~300 per quarter",
            "goal": "Get my fix tested and reviewed without being treated as an attacker, or left waiting with no reason given.",
            "journeys": [
              {
                "id": "j-fork",
                "label": "Land a fork contribution"
              }
            ]
          },
          {
            "id": "auditor",
            "label": "Auditor",
            "kind": "external",
            "sub": "2 reviews per year",
            "goal": "Show me, for one image in production, which commit produced it and who approved it.",
            "journeys": [
              {
                "label": "Trace an image to a commit"
              }
            ]
          }
        ]
      },
      {
        "title": "Machines in the cast",
        "kind": "cloud",
        "actors": [
          {
            "id": "sched",
            "label": "Scheduled trigger",
            "kind": "platform",
            "sub": "18k runs/night",
            "goal": "Use the capacity nobody else wants, and get out of the way when a human is waiting.",
            "journeys": [
              {
                "label": "Run nightly on spare capacity"
              }
            ]
          },
          {
            "id": "bot",
            "label": "Review bot",
            "kind": "external",
            "sub": "lint and SAST",
            "goal": "Post findings on the diff fast enough to be read before the human reviewer arrives.",
            "journeys": [
              {
                "label": "Post findings on a PR"
              }
            ]
          }
        ]
      }
    ],
    "note": "Three journeys get their own map: the engineer's green check, the fork contribution, and the release promotion. They fail in different places.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "04-journey-green-check",
    "title": "Journey — An Engineer Waits for a Green Check",
    "layout": "journey",
    "actor": {
      "label": "Application engineer",
      "sub": "pushes 6× a day",
      "goal": "Know within minutes whether this change is safe to merge",
      "trigger": "git push on a feature branch",
      "success": "A green check they trust, or a red one that names what they broke"
    },
    "phases": [
      {
        "title": "Push",
        "sub": "branch or PR"
      },
      {
        "title": "Wait",
        "sub": "queue + build"
      },
      {
        "title": "Read",
        "moment": true
      },
      {
        "title": "Fix"
      },
      {
        "title": "Merge",
        "moment": true
      }
    ],
    "lanes": [
      {
        "title": "What they do",
        "kind": "step",
        "cells": [
          [
            {
              "label": "Pushes the branch"
            }
          ],
          [
            {
              "label": "Switches to Slack"
            }
          ],
          [
            {
              "label": "Opens the failed job"
            }
          ],
          [
            {
              "label": "Pushes a fix"
            }
          ],
          [
            {
              "label": "Merges the PR"
            }
          ]
        ]
      },
      {
        "title": "What the platform does",
        "kind": "system",
        "cells": [
          [
            {
              "label": "Admits, compiles, queues"
            }
          ],
          [
            {
              "label": "Claims a warm microVM"
            },
            {
              "label": "Shows queue position"
            }
          ],
          [
            {
              "label": "First-failure summary"
            }
          ],
          [
            {
              "label": "Restores warm cache"
            }
          ],
          [
            {
              "label": "Signs provenance"
            }
          ]
        ]
      },
      {
        "title": "How it feels",
        "kind": "emotion",
        "levels": [
          "Trusting",
          "Fine",
          "Lost"
        ],
        "points": [
          2,
          1,
          0,
          1,
          2
        ]
      },
      {
        "title": "Where it hurts",
        "kind": "pain",
        "cells": [
          [],
          [
            {
              "label": "Wait with no reason"
            }
          ],
          [
            {
              "label": "Flake reads as my bug"
            }
          ],
          [],
          [
            {
              "label": "Green I did not earn"
            }
          ]
        ]
      }
    ],
    "chain": true,
    "note": "The trough is attribution, not speed. An engineer who cannot tell a flake from a regression learns to retry instead of read.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "05-journey-fork-contribution",
    "title": "Journey — A Pull Request From a Fork",
    "layout": "journey",
    "actor": {
      "label": "Outside contributor",
      "sub": "~300 per quarter",
      "goal": "Get a small fix tested and reviewed without being treated as an attacker",
      "trigger": "Opens a pull request from their own fork",
      "success": "Tests ran, and the maintainer can see the result beside the diff"
    },
    "phases": [
      {
        "title": "Open PR"
      },
      {
        "title": "Await run",
        "sub": "classification",
        "moment": true
      },
      {
        "title": "Build runs"
      },
      {
        "title": "Iterate"
      },
      {
        "title": "Merged",
        "moment": true
      }
    ],
    "lanes": [
      {
        "title": "What they do",
        "kind": "step",
        "cells": [
          [
            {
              "label": "Opens the PR"
            }
          ],
          [
            {
              "label": "Waits, then asks"
            }
          ],
          [
            {
              "label": "Watches the log"
            }
          ],
          [
            {
              "label": "Pushes a change"
            }
          ],
          [
            {
              "label": "Maintainer merges"
            }
          ]
        ]
      },
      {
        "title": "What the platform does",
        "kind": "system",
        "cells": [
          [
            {
              "label": "Classifies untrusted"
            }
          ],
          [
            {
              "label": "Runs without secrets"
            }
          ],
          [
            {
              "label": "Cache read-only"
            },
            {
              "label": "Egress allow-list only"
            }
          ],
          [
            {
              "label": "Re-runs on new head"
            }
          ],
          [
            {
              "label": "Re-runs as trusted"
            }
          ]
        ]
      },
      {
        "title": "How it feels",
        "kind": "emotion",
        "levels": [
          "Welcome",
          "Fine",
          "Suspect"
        ],
        "points": [
          2,
          0,
          1,
          1,
          2
        ]
      },
      {
        "title": "Where it hurts",
        "kind": "pain",
        "cells": [
          [],
          [
            {
              "label": "Blocked, no reason given"
            }
          ],
          [
            {
              "label": "Slower: no cache write"
            }
          ],
          [],
          []
        ]
      },
      {
        "title": "What the platform gains",
        "kind": "gain",
        "cells": [
          [],
          [
            {
              "label": "No secret reaches a fork"
            }
          ],
          [
            {
              "label": "No cache poisoning path"
            }
          ],
          [],
          [
            {
              "label": "Trusted re-run before merge"
            }
          ]
        ]
      }
    ],
    "chain": true,
    "note": "The trough is silence, not slowness. Telling a contributor why their build is restricted costs nothing and is the whole fix.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "06-journey-promote-and-roll-back",
    "title": "Journey — Promote a Release, Then Take It Back",
    "layout": "journey",
    "actor": {
      "label": "Release owner",
      "sub": "one of 9 business units",
      "goal": "Ship exactly the bits that passed staging, and undo it in minutes if it is wrong",
      "trigger": "A green run on a release tag of the main branch",
      "success": "Production on a known digest, with evidence for every gate that passed"
    },
    "phases": [
      {
        "title": "Verify"
      },
      {
        "title": "Approve"
      },
      {
        "title": "Deploy",
        "moment": true
      },
      {
        "title": "Watch",
        "moment": true
      },
      {
        "title": "Roll back"
      }
    ],
    "lanes": [
      {
        "title": "What they do",
        "kind": "step",
        "cells": [
          [
            {
              "label": "Checks the digest"
            }
          ],
          [
            {
              "label": "Approves in the UI"
            }
          ],
          [
            {
              "label": "Watches the deploy"
            }
          ],
          [
            {
              "label": "Reads target SLOs"
            }
          ],
          [
            {
              "label": "Picks the last digest"
            }
          ]
        ]
      },
      {
        "title": "What the platform does",
        "kind": "system",
        "cells": [
          [
            {
              "label": "Verifies attestation"
            }
          ],
          [
            {
              "label": "Evaluates every gate"
            }
          ],
          [
            {
              "label": "Takes the deploy lock"
            },
            {
              "label": "Moves the pointer"
            }
          ],
          [
            {
              "label": "Records gate evidence"
            }
          ],
          [
            {
              "label": "Repoints, no rebuild"
            }
          ]
        ]
      },
      {
        "title": "How it feels",
        "kind": "emotion",
        "levels": [
          "Confident",
          "Fine",
          "Exposed"
        ],
        "points": [
          2,
          1,
          1,
          0,
          1
        ]
      },
      {
        "title": "Where it hurts",
        "kind": "pain",
        "cells": [
          [],
          [
            {
              "label": "Gate denies, reason unclear"
            }
          ],
          [],
          [
            {
              "label": "Is this us or the target?"
            }
          ],
          [
            {
              "label": "Rebuild would cost 20 min"
            }
          ]
        ]
      },
      {
        "title": "What the platform gains",
        "kind": "gain",
        "cells": [
          [
            {
              "label": "Same bits as staging"
            }
          ],
          [],
          [
            {
              "label": "No interleaved deploy"
            }
          ],
          [],
          [
            {
              "label": "Rollback in 5 minutes"
            }
          ]
        ]
      }
    ],
    "chain": true,
    "note": "The trough is the watch, not the deploy. Promoting a digest is cheap; deciding whether the new version is the cause is not.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "07-layered-architecture",
    "title": "CI/CD Platform — Layered Architecture",
    "layout": "bands",
    "layerHeaderWidth": 160,
    "bands": [
      {
        "name": "Experience",
        "nodes": [
          {
            "id": "ui",
            "label": "Run console",
            "sub": "live tail"
          },
          {
            "id": "api",
            "label": "Public API",
            "kind": "integration"
          },
          {
            "id": "cli",
            "label": "CLI",
            "sub": "local repro"
          },
          {
            "id": "checks",
            "label": "Checks on the diff",
            "kind": "integration"
          }
        ]
      },
      {
        "name": "Admission",
        "nodes": [
          {
            "id": "recv",
            "label": "Event receiver",
            "kind": "integration"
          },
          {
            "id": "comp",
            "label": "Definition compiler"
          },
          {
            "id": "pol",
            "label": "Policy admission",
            "kind": "security"
          },
          {
            "id": "cls",
            "label": "Trust classifier",
            "kind": "security"
          }
        ]
      },
      {
        "name": "Control plane",
        "nodes": [
          {
            "id": "sm",
            "label": "Run state machine"
          },
          {
            "id": "sched",
            "label": "Fair scheduler",
            "sub": "entitlements"
          },
          {
            "id": "gated",
            "label": "Gate decision service",
            "kind": "decision"
          },
          {
            "id": "broker",
            "label": "Secret broker",
            "kind": "security"
          },
          {
            "id": "att",
            "label": "Attestor",
            "kind": "security"
          }
        ]
      },
      {
        "name": "Execution plane",
        "nodes": [
          {
            "id": "sbm",
            "label": "Sandbox manager"
          },
          {
            "id": "pool",
            "label": "Warm pool",
            "kind": "platform"
          },
          {
            "id": "host",
            "label": "Isolation hosts",
            "kind": "platform",
            "sub": "microVM per job"
          },
          {
            "id": "agent",
            "label": "Per-job agent"
          },
          {
            "id": "egress",
            "label": "Egress proxy",
            "kind": "security"
          }
        ]
      },
      {
        "name": "Evidence & artefacts",
        "nodes": [
          {
            "id": "cas",
            "label": "Artefact store",
            "kind": "store",
            "sub": "immutable"
          },
          {
            "id": "cache",
            "label": "Build cache",
            "kind": "store"
          },
          {
            "id": "tlog",
            "label": "Transparency log",
            "kind": "store",
            "sub": "append-only"
          },
          {
            "id": "logs",
            "label": "Log store",
            "kind": "store",
            "sub": "hot to cold"
          }
        ]
      },
      {
        "name": "Delivery",
        "nodes": [
          {
            "id": "envreg",
            "label": "Environment registry"
          },
          {
            "id": "lock",
            "label": "Deployment lock",
            "kind": "platform"
          },
          {
            "id": "dep",
            "label": "Deployers"
          },
          {
            "id": "rb",
            "label": "Rollback controller"
          }
        ]
      },
      {
        "name": "Foundation",
        "nodes": [
          {
            "id": "meta",
            "label": "Run metadata store",
            "kind": "store"
          },
          {
            "id": "bus",
            "label": "Run event log",
            "kind": "queue"
          },
          {
            "id": "kms",
            "label": "Key store",
            "kind": "security",
            "sub": "hardware-backed"
          },
          {
            "id": "idf",
            "label": "Identity federation",
            "kind": "security"
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "cls",
        "to": "sched",
        "label": "trust class",
        "kind": "sync"
      },
      {
        "from": "sched",
        "to": "sbm",
        "label": "job + lease",
        "kind": "sync"
      },
      {
        "from": "agent",
        "to": "att",
        "label": "observed inputs",
        "kind": "sync"
      },
      {
        "from": "cas",
        "to": "gated",
        "label": "evidence",
        "kind": "sync"
      }
    ],
    "note": "Admission sits above the control plane because classification happens once, before any capacity is committed, and cannot be revised later.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "08-platform-components",
    "title": "CI/CD Platform — Containers and Components",
    "layout": "nested",
    "boxes": [
      {
        "title": "Control plane — never executes tenant code",
        "kind": "trust",
        "dir": "col",
        "children": [
          {
            "title": "Admission services",
            "kind": "boundary",
            "nodes": [
              {
                "id": "recv",
                "label": "Event receiver",
                "sub": "EKS service",
                "kind": "integration"
              },
              {
                "id": "comp",
                "label": "Definition compiler",
                "sub": "DAG + schema"
              },
              {
                "id": "cls",
                "label": "Trust classifier",
                "kind": "security"
              }
            ]
          },
          {
            "title": "Orchestration",
            "kind": "boundary",
            "nodes": [
              {
                "id": "sm",
                "label": "Run state machine",
                "sub": "lease per job"
              },
              {
                "id": "sched",
                "label": "Fair scheduler"
              },
              {
                "id": "q",
                "label": "Job queue",
                "sub": "SQS, durable",
                "kind": "queue"
              },
              {
                "id": "ev",
                "label": "Run event log",
                "sub": "Kinesis",
                "kind": "queue"
              }
            ]
          },
          {
            "title": "Trust services",
            "kind": "boundary",
            "nodes": [
              {
                "id": "broker",
                "label": "Secret broker",
                "kind": "security"
              },
              {
                "id": "idf",
                "label": "Identity federation",
                "sub": "OIDC, per job",
                "kind": "security"
              },
              {
                "id": "att",
                "label": "Attestor",
                "sub": "KMS signing key",
                "kind": "security"
              },
              {
                "id": "gate",
                "label": "Gate decision service",
                "kind": "decision"
              }
            ]
          }
        ]
      },
      {
        "title": "Execution plane — untrusted",
        "kind": "onprem",
        "dir": "row",
        "children": [
          {
            "title": "Capacity management",
            "kind": "boundary",
            "nodes": [
              {
                "id": "sbm",
                "label": "Sandbox manager"
              },
              {
                "id": "pool",
                "label": "Warm pool",
                "kind": "platform"
              },
              {
                "id": "asg",
                "label": "Capacity autoscaler",
                "kind": "platform"
              }
            ]
          },
          {
            "title": "Isolation host",
            "kind": "boundary",
            "nodes": [
              {
                "id": "hv",
                "label": "microVM hypervisor",
                "sub": "one job per VM",
                "kind": "platform"
              },
              {
                "id": "agent",
                "label": "Per-job agent"
              },
              {
                "id": "egr",
                "label": "Egress proxy",
                "kind": "security"
              }
            ]
          }
        ]
      },
      {
        "title": "Stores",
        "kind": "cloud",
        "dir": "row",
        "children": [
          {
            "title": "Mutable state",
            "kind": "boundary",
            "nodes": [
              {
                "id": "meta",
                "label": "Run metadata",
                "sub": "Aurora PostgreSQL",
                "kind": "store"
              },
              {
                "id": "envreg",
                "label": "Environment registry",
                "kind": "store"
              }
            ]
          },
          {
            "title": "Write-once evidence",
            "kind": "boundary",
            "nodes": [
              {
                "id": "cas",
                "label": "Artefact store",
                "sub": "S3, digest-addressed",
                "kind": "store"
              },
              {
                "id": "tlog",
                "label": "Transparency log",
                "sub": "Object Lock",
                "kind": "store"
              },
              {
                "id": "logs",
                "label": "Log store",
                "kind": "store"
              }
            ]
          },
          {
            "title": "Disposable",
            "kind": "boundary",
            "nodes": [
              {
                "id": "cache",
                "label": "Build cache",
                "sub": "rebuildable",
                "kind": "store"
              },
              {
                "id": "mirror",
                "label": "Dependency mirror",
                "kind": "store"
              }
            ]
          }
        ]
      }
    ],
    "outside": [
      {
        "id": "vcs",
        "label": "Source control",
        "kind": "external"
      },
      {
        "id": "reg",
        "label": "Container registry",
        "kind": "external"
      },
      {
        "id": "rt",
        "label": "Runtime platforms",
        "kind": "external"
      }
    ],
    "edges": [
      {
        "from": "q",
        "to": "sbm",
        "label": "job assignment",
        "kind": "sync"
      },
      {
        "from": "agent",
        "to": "att",
        "label": "build inputs",
        "kind": "sync"
      },
      {
        "from": "att",
        "to": "tlog",
        "label": "signed record",
        "kind": "sync"
      },
      {
        "from": "agent",
        "to": "cache",
        "label": "read wide",
        "kind": "sync"
      },
      {
        "from": "gate",
        "to": "rt",
        "label": "allowed deploy",
        "kind": "sync"
      }
    ],
    "note": "Three store groups because there are three mutabilities: transactional state, write-once evidence, and state that can be thrown away.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "09-integration-surface",
    "title": "CI/CD Platform — Integration Surface",
    "layout": "hub",
    "left": {
      "title": "Inbound",
      "nodes": [
        {
          "id": "hook",
          "label": "Repository webhooks",
          "kind": "integration",
          "rel": "signed events"
        },
        {
          "id": "api",
          "label": "Trigger API",
          "kind": "integration",
          "rel": "dispatch"
        },
        {
          "id": "cron",
          "label": "Schedule service",
          "kind": "platform",
          "rel": "nightly"
        }
      ]
    },
    "centre": {
      "title": "CI/CD Platform",
      "nodes": [
        {
          "id": "core",
          "label": "CI/CD Platform",
          "sub": "one write surface"
        }
      ]
    },
    "right": {
      "title": "Outbound",
      "nodes": [
        {
          "id": "checks",
          "label": "Checks on the diff",
          "kind": "integration",
          "rel": "status",
          "dir": "out"
        },
        {
          "id": "rt",
          "label": "Runtime platforms",
          "kind": "external",
          "rel": "deploys",
          "dir": "out"
        },
        {
          "id": "siem",
          "label": "Audit and SIEM",
          "kind": "external",
          "rel": "evidence",
          "dir": "out",
          "kind2": "batch"
        }
      ]
    },
    "note": "Three authenticated inbound surfaces, three outbound. Source control is read-only to the platform; the container registry, identity, package mirrors, chat and cost reporting appear in views 14, 21 and 18.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "10-run-and-evidence-data-flow",
    "title": "CI/CD Platform — Run and Evidence Data Flow",
    "layout": "flow",
    "chain": true,
    "align": "middle",
    "stages": [
      {
        "title": "Sources",
        "nodes": [
          {
            "id": "src",
            "label": "Commit + definition",
            "kind": "external"
          },
          {
            "id": "deps",
            "label": "Declared dependencies",
            "kind": "external"
          }
        ]
      },
      {
        "title": "Admitted",
        "nodes": [
          {
            "id": "eff",
            "label": "Effective definition",
            "sub": "immutable",
            "kind": "store"
          },
          {
            "id": "runrec",
            "label": "Run record",
            "kind": "store"
          }
        ]
      },
      {
        "title": "Executing",
        "nodes": [
          {
            "id": "outp",
            "label": "Build output"
          },
          {
            "id": "logline",
            "label": "Log stream",
            "kind": "queue"
          },
          {
            "id": "cachew",
            "label": "Cache write",
            "sub": "trusted only",
            "kind": "store"
          }
        ]
      },
      {
        "title": "Sealed",
        "nodes": [
          {
            "id": "dig",
            "label": "Artefact digest",
            "kind": "store"
          },
          {
            "id": "prov",
            "label": "Provenance + SBOM",
            "kind": "store"
          }
        ]
      },
      {
        "title": "Serving",
        "nodes": [
          {
            "id": "hist",
            "label": "Run history",
            "kind": "store"
          },
          {
            "id": "envp",
            "label": "Environment pointer",
            "kind": "store"
          },
          {
            "id": "aud",
            "label": "Audit trail",
            "sub": "write-once",
            "kind": "store"
          }
        ]
      },
      {
        "title": "Consumers",
        "nodes": [
          {
            "id": "eng",
            "label": "Engineers",
            "kind": "actor"
          },
          {
            "id": "gatec",
            "label": "Gate decisions",
            "kind": "decision"
          },
          {
            "id": "auditor",
            "label": "Auditors",
            "kind": "actor"
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "logline",
        "to": "hist",
        "label": "tail then tier",
        "kind": "async"
      },
      {
        "from": "prov",
        "to": "gatec",
        "label": "verified",
        "kind": "sync"
      },
      {
        "from": "envp",
        "to": "aud",
        "label": "before pointer moves",
        "kind": "sync"
      }
    ],
    "note": "Evidence is written before the pointer moves, never after. A run that cannot record its audit line does not complete.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "11-storage-zones",
    "title": "CI/CD Platform — Storage Zones by Ownership and Rebuildability",
    "layout": "nested",
    "boxes": [
      {
        "title": "Authoritative and mutable — RPO 0",
        "kind": "trust",
        "dir": "row",
        "children": [
          {
            "title": "Run metadata",
            "kind": "boundary",
            "nodes": [
              {
                "id": "runs",
                "label": "Runs and jobs",
                "sub": "Aurora, multi-AZ",
                "kind": "store"
              },
              {
                "id": "ent",
                "label": "Tenants and entitlements",
                "kind": "store"
              }
            ]
          },
          {
            "title": "Delivery state",
            "kind": "boundary",
            "nodes": [
              {
                "id": "env",
                "label": "Environment pointers",
                "kind": "store"
              },
              {
                "id": "locks",
                "label": "Deployment locks",
                "kind": "store"
              }
            ]
          }
        ]
      },
      {
        "title": "Write-once evidence — immutable, 7 years",
        "kind": "trust",
        "dir": "row",
        "children": [
          {
            "title": "Artefacts",
            "kind": "boundary",
            "nodes": [
              {
                "id": "cas",
                "label": "Artefact store",
                "sub": "S3 by digest",
                "kind": "store"
              },
              {
                "id": "sbom",
                "label": "SBOM store",
                "kind": "store"
              }
            ]
          },
          {
            "title": "Proof",
            "kind": "boundary",
            "nodes": [
              {
                "id": "tlog",
                "label": "Transparency log",
                "sub": "Object Lock",
                "kind": "store"
              },
              {
                "id": "aud",
                "label": "Audit trail",
                "kind": "store"
              }
            ]
          }
        ]
      },
      {
        "title": "Replayable — bounded loss tolerated",
        "kind": "boundary",
        "dir": "row",
        "children": [
          {
            "title": "Event and log",
            "kind": "boundary",
            "nodes": [
              {
                "id": "ev",
                "label": "Run event log",
                "sub": "RPO 0, 400 days",
                "kind": "queue"
              },
              {
                "id": "logs",
                "label": "Log store",
                "sub": "14d hot, 90d warm",
                "kind": "store"
              }
            ]
          }
        ]
      },
      {
        "title": "Disposable — no RPO, rebuilt on demand",
        "kind": "plain",
        "dir": "row",
        "children": [
          {
            "title": "Derived",
            "kind": "boundary",
            "nodes": [
              {
                "id": "cache",
                "label": "Build cache",
                "sub": "90 TB working set",
                "kind": "store"
              },
              {
                "id": "mirror",
                "label": "Dependency mirror",
                "kind": "store"
              },
              {
                "id": "warm",
                "label": "Warm pool images",
                "kind": "platform"
              }
            ]
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "cas",
        "to": "tlog",
        "label": "digest recorded",
        "kind": "sync"
      }
    ],
    "note": "The largest and hottest stores are the disposable ones. The smallest are the ones that can never be lost or altered.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "12-data-model",
    "title": "CI/CD Platform — Core Data Model",
    "layout": "er",
    "canvas": {
      "width": 1720,
      "cols": 4
    },
    "rowGap": 250,
    "entities": [
      {
        "id": "tenant",
        "name": "tenant",
        "row": 0,
        "col": 0,
        "attrs": [
          "tenant_id  PK",
          "name",
          "concurrency_entitlement",
          "priority_weight"
        ]
      },
      {
        "id": "repo",
        "name": "repository",
        "row": 0,
        "col": 1,
        "attrs": [
          "repo_id  PK",
          "tenant_id  FK -> tenant",
          "default_branch",
          "policy_bundle_version"
        ]
      },
      {
        "id": "defn",
        "name": "effective_definition",
        "row": 0,
        "col": 2,
        "attrs": [
          "definition_digest  PK",
          "repo_id  FK -> repository",
          "source_commit",
          "compiled_at"
        ]
      },
      {
        "id": "run",
        "name": "run",
        "row": 0,
        "col": 3,
        "attrs": [
          "run_id  PK",
          "repo_id  FK -> repository",
          "definition_digest  FK",
          "trust_class",
          "trigger_event",
          "state"
        ]
      },
      {
        "id": "env",
        "name": "environment",
        "row": 1,
        "col": 0,
        "attrs": [
          "env_id  PK",
          "tenant_id  FK -> tenant",
          "name",
          "stage_order",
          "current_digest"
        ]
      },
      {
        "id": "dep",
        "name": "deployment",
        "row": 1,
        "col": 1,
        "attrs": [
          "deployment_id  PK",
          "env_id  FK -> environment",
          "digest  FK -> artefact",
          "actor_id",
          "deployed_at"
        ]
      },
      {
        "id": "artefact",
        "name": "artefact",
        "row": 1,
        "col": 2,
        "attrs": [
          "digest  PK",
          "job_id  FK -> job",
          "media_type",
          "retention_class"
        ]
      },
      {
        "id": "job",
        "name": "job",
        "row": 1,
        "col": 3,
        "attrs": [
          "job_id  PK",
          "run_id  FK -> run",
          "resource_class",
          "outcome",
          "lease_expiry",
          "attempt"
        ]
      },
      {
        "id": "gate",
        "name": "gate_evaluation",
        "row": 2,
        "col": 1,
        "attrs": [
          "evaluation_id  PK",
          "deployment_id  FK -> deployment",
          "gate_type",
          "verdict",
          "reason",
          "override_by"
        ]
      },
      {
        "id": "att",
        "name": "attestation",
        "row": 2,
        "col": 2,
        "attrs": [
          "attestation_id  PK",
          "digest  FK -> artefact",
          "log_index",
          "signature",
          "builder_id"
        ]
      }
    ],
    "relations": [
      {
        "from": "tenant",
        "to": "repo",
        "label": "1 : N",
        "from_side": "e",
        "to_side": "w"
      },
      {
        "from": "repo",
        "to": "defn",
        "label": "1 : N",
        "from_side": "e",
        "to_side": "w"
      },
      {
        "from": "defn",
        "to": "run",
        "label": "1 : N",
        "from_side": "e",
        "to_side": "w"
      },
      {
        "from": "run",
        "to": "job",
        "label": "1 : N",
        "from_side": "s",
        "to_side": "n"
      },
      {
        "from": "job",
        "to": "artefact",
        "label": "1 : N",
        "from_side": "w",
        "to_side": "e"
      },
      {
        "from": "artefact",
        "to": "att",
        "label": "1 : 1",
        "from_side": "s",
        "to_side": "n"
      },
      {
        "from": "artefact",
        "to": "dep",
        "label": "1 : N",
        "from_side": "w",
        "to_side": "e",
        "kind": "optional"
      },
      {
        "from": "tenant",
        "to": "env",
        "label": "1 : N",
        "from_side": "s",
        "to_side": "n"
      },
      {
        "from": "env",
        "to": "dep",
        "label": "1 : N",
        "from_side": "e",
        "to_side": "w"
      },
      {
        "from": "dep",
        "to": "gate",
        "label": "1 : N",
        "from_side": "s",
        "to_side": "n"
      }
    ],
    "note": "trust_class is set once, at admission, and nothing downstream may change it. The run-to-repository link is carried as an attribute rather than an edge, to keep the view readable.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "13-job-dispatch-sequence",
    "title": "Critical Flow — Commit to Signed Artefact",
    "layout": "sequence",
    "lifelines": [
      {
        "id": "vcs",
        "label": "Source control",
        "kind": "external"
      },
      {
        "id": "adm",
        "label": "Admission",
        "kind": "app"
      },
      {
        "id": "sch",
        "label": "Scheduler",
        "kind": "app"
      },
      {
        "id": "sbm",
        "label": "Sandbox mgr",
        "kind": "app"
      },
      {
        "id": "vm",
        "label": "microVM job",
        "kind": "platform"
      },
      {
        "id": "brk",
        "label": "Secret broker",
        "kind": "security"
      },
      {
        "id": "att",
        "label": "Attestor",
        "kind": "security"
      },
      {
        "id": "cas",
        "label": "Artefact store",
        "kind": "store"
      }
    ],
    "messages": [
      {
        "from": "vcs",
        "to": "adm",
        "label": "push event (signed)",
        "kind": "call"
      },
      {
        "from": "adm",
        "to": "adm",
        "label": "compile, classify trust",
        "kind": "self"
      },
      {
        "from": "adm",
        "to": "sch",
        "label": "run admitted",
        "kind": "call"
      },
      {
        "from": "sch",
        "to": "sch",
        "label": "fair-queue, lease job",
        "kind": "self"
      },
      {
        "from": "sch",
        "to": "sbm",
        "label": "assign job + lease",
        "kind": "call"
      },
      {
        "from": "sbm",
        "to": "vm",
        "label": "claim warm microVM",
        "kind": "call"
      },
      {
        "from": "vm",
        "to": "brk",
        "label": "request scoped token",
        "kind": "call"
      },
      {
        "from": "brk",
        "to": "vm",
        "label": "job-scoped, expiring",
        "kind": "return"
      },
      {
        "from": "vm",
        "to": "vm",
        "label": "build and test",
        "kind": "self"
      },
      {
        "from": "vm",
        "to": "cas",
        "label": "upload by digest",
        "kind": "call"
      },
      {
        "from": "vm",
        "to": "sbm",
        "label": "report outcome",
        "kind": "return"
      },
      {
        "from": "sbm",
        "to": "att",
        "label": "observed inputs + digest",
        "kind": "call"
      },
      {
        "from": "att",
        "to": "cas",
        "label": "sign + log provenance",
        "kind": "call"
      },
      {
        "from": "att",
        "to": "sch",
        "label": "job sealed",
        "kind": "return"
      },
      {
        "from": "sbm",
        "to": "vm",
        "label": "destroy sandbox",
        "kind": "async"
      },
      {
        "from": "vm",
        "to": "sch",
        "label": "lease expired, re-dispatch",
        "kind": "error"
      }
    ],
    "note": "The job reports its outcome; the attestor signs it. A job can produce a bad artefact but never a credible claim about one.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "14-build-pipeline",
    "title": "CI/CD Platform — The Build Pipeline Inside One Run",
    "layout": "flow",
    "chain": true,
    "align": "middle",
    "stages": [
      {
        "title": "Prepare",
        "nodes": [
          {
            "id": "chk",
            "label": "Checkout at commit"
          },
          {
            "id": "rest",
            "label": "Restore cache",
            "sub": "integrity checked",
            "kind": "store"
          }
        ]
      },
      {
        "title": "Resolve",
        "nodes": [
          {
            "id": "dep",
            "label": "Resolve dependencies",
            "sub": "via mirror"
          },
          {
            "id": "lock",
            "label": "Record resolved set",
            "kind": "store"
          }
        ]
      },
      {
        "title": "Build",
        "nodes": [
          {
            "id": "cmp",
            "label": "Compile"
          },
          {
            "id": "img",
            "label": "Assemble image"
          }
        ]
      },
      {
        "title": "Verify",
        "nodes": [
          {
            "id": "unit",
            "label": "Unit and integration tests"
          },
          {
            "id": "scan",
            "label": "Dependency scan",
            "kind": "security"
          }
        ]
      },
      {
        "title": "Seal",
        "nodes": [
          {
            "id": "push",
            "label": "Upload by digest",
            "kind": "store"
          },
          {
            "id": "sign",
            "label": "Sign provenance + SBOM",
            "kind": "security"
          }
        ]
      },
      {
        "title": "Publish",
        "nodes": [
          {
            "id": "tag",
            "label": "Move tag to digest",
            "kind": "integration"
          },
          {
            "id": "save",
            "label": "Save cache",
            "sub": "trusted runs only",
            "kind": "store"
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "rest",
        "to": "cmp",
        "label": "warm inputs",
        "kind": "sync"
      },
      {
        "from": "scan",
        "to": "sign",
        "label": "findings attached",
        "kind": "sync"
      },
      {
        "from": "scan",
        "to": "tag",
        "label": "blocked on critical",
        "kind": "error",
        "route": "rl"
      }
    ],
    "note": "Signing is a stage, not an afterthought, and cache save is the only stage an untrusted run skips.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "15-execution-by-trust-class",
    "title": "CI/CD Platform — Execution by Trust Class",
    "layout": "swimlane",
    "laneHeaderWidth": 190,
    "stages": [
      "Admit",
      "Credentials",
      "Cache",
      "Egress",
      "Publish"
    ],
    "lanes": [
      {
        "title": "Trusted branch run",
        "cells": [
          [
            {
              "label": "Classified trusted"
            }
          ],
          [
            {
              "label": "Job-scoped secrets"
            },
            {
              "label": "Federated cloud role"
            }
          ],
          [
            {
              "label": "Read and write",
              "kind": "store"
            }
          ],
          [
            {
              "label": "Tenant allow-list"
            }
          ],
          [
            {
              "label": "Push + sign",
              "kind": "security"
            }
          ]
        ]
      },
      {
        "title": "Untrusted fork run",
        "cells": [
          [
            {
              "label": "Classified untrusted",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "No secrets issued",
              "kind": "security"
            }
          ],
          [
            {
              "label": "Read only",
              "kind": "store"
            }
          ],
          [
            {
              "label": "Mirror and VCS only"
            }
          ],
          [
            {
              "label": "No publish identity",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Scheduled background run",
        "cells": [
          [
            {
              "label": "Trusted, low priority"
            }
          ],
          [
            {
              "label": "Job-scoped secrets"
            }
          ],
          [
            {
              "label": "Read and write",
              "kind": "store"
            }
          ],
          [
            {
              "label": "Tenant allow-list"
            }
          ],
          [
            {
              "label": "Push + sign",
              "kind": "security"
            }
          ]
        ]
      },
      {
        "title": "Interactive repro session",
        "cells": [
          [
            {
              "label": "Inherits run class"
            }
          ],
          [
            {
              "label": "Human identity only",
              "kind": "security"
            }
          ],
          [
            {
              "label": "Read only",
              "kind": "store"
            }
          ],
          [
            {
              "label": "Tenant allow-list"
            }
          ],
          [
            {
              "label": "Never publishes",
              "kind": "risk"
            }
          ]
        ]
      }
    ],
    "note": "One execution substrate, four credential and cache postures. The difference is what the sandbox is given, never how well it is isolated.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "16-deployment-architecture",
    "title": "CI/CD Platform — Deployment Architecture",
    "layout": "nested",
    "boxes": [
      {
        "title": "AWS eu-west-1 — primary",
        "kind": "cloud",
        "dir": "col",
        "children": [
          {
            "title": "Control plane — EKS across three AZs",
            "kind": "boundary",
            "nodes": [
              {
                "id": "svc",
                "label": "Admission + API pods",
                "sub": "stateless"
              },
              {
                "id": "schp",
                "label": "Scheduler pods",
                "sub": "leader per shard"
              },
              {
                "id": "gatep",
                "label": "Gate service pods",
                "kind": "decision"
              },
              {
                "id": "attp",
                "label": "Attestor pods",
                "kind": "security"
              }
            ]
          },
          {
            "title": "Execution plane — AZ-a",
            "kind": "boundary",
            "nodes": [
              {
                "id": "hostA",
                "label": "Isolation hosts",
                "sub": "on-demand",
                "kind": "platform"
              },
              {
                "id": "spotA",
                "label": "Interruptible hosts",
                "sub": "background tier",
                "kind": "platform"
              }
            ]
          },
          {
            "title": "Execution plane — AZ-b and AZ-c",
            "kind": "boundary",
            "nodes": [
              {
                "id": "hostB",
                "label": "Isolation hosts",
                "kind": "platform"
              },
              {
                "id": "spotB",
                "label": "Interruptible hosts",
                "kind": "platform"
              },
              {
                "id": "gpu",
                "label": "GPU and arm64 pools",
                "kind": "platform"
              }
            ]
          },
          {
            "title": "Regional data",
            "kind": "boundary",
            "nodes": [
              {
                "id": "aur",
                "label": "Aurora, multi-AZ",
                "kind": "store"
              },
              {
                "id": "s3",
                "label": "Artefact + log buckets",
                "kind": "store"
              },
              {
                "id": "kms",
                "label": "Key store",
                "kind": "security"
              }
            ]
          }
        ]
      },
      {
        "title": "AWS eu-central-1 — recovery",
        "kind": "cloud",
        "dir": "row",
        "children": [
          {
            "title": "Warm standby",
            "kind": "boundary",
            "nodes": [
              {
                "id": "cp2",
                "label": "Control plane, scaled to zero"
              },
              {
                "id": "rep",
                "label": "Replicated artefacts + log",
                "kind": "store"
              },
              {
                "id": "aur2",
                "label": "Aurora read replica",
                "kind": "store"
              }
            ]
          }
        ]
      }
    ],
    "outside": [
      {
        "id": "vcs",
        "label": "Source control (SaaS)",
        "kind": "external"
      },
      {
        "id": "mir",
        "label": "Dependency mirror",
        "kind": "store"
      }
    ],
    "edges": [
      {
        "from": "s3",
        "to": "rep",
        "label": "cross-region",
        "kind": "async"
      },
      {
        "from": "schp",
        "to": "hostA",
        "label": "dispatch",
        "kind": "sync"
      }
    ],
    "note": "The recovery region holds evidence and a scaled-to-zero control plane. In-flight jobs are not failed over; they are re-dispatched.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "17-promotion-and-environments",
    "title": "CI/CD Platform — Promotion and Environments",
    "layout": "flow",
    "chain": true,
    "align": "middle",
    "stages": [
      {
        "title": "Source",
        "nodes": [
          {
            "id": "main",
            "label": "Main branch commit",
            "kind": "external"
          },
          {
            "id": "tagr",
            "label": "Release tag",
            "kind": "external"
          }
        ]
      },
      {
        "title": "Build once",
        "nodes": [
          {
            "id": "dig",
            "label": "One artefact digest",
            "sub": "immutable",
            "kind": "store"
          },
          {
            "id": "prov",
            "label": "Provenance + SBOM",
            "kind": "security"
          }
        ]
      },
      {
        "title": "Test env",
        "nodes": [
          {
            "id": "g1",
            "label": "Gates: outcomes, scan",
            "kind": "decision"
          },
          {
            "id": "e1",
            "label": "test",
            "sub": "auto-promote"
          }
        ]
      },
      {
        "title": "Staging",
        "nodes": [
          {
            "id": "g2",
            "label": "Gates: soak, SLO health",
            "kind": "decision"
          },
          {
            "id": "e2",
            "label": "staging",
            "sub": "30 min soak"
          }
        ]
      },
      {
        "title": "Production",
        "nodes": [
          {
            "id": "g3",
            "label": "Gates: approval, freeze",
            "kind": "decision"
          },
          {
            "id": "e3",
            "label": "production",
            "sub": "lock held"
          }
        ]
      },
      {
        "title": "Recover",
        "nodes": [
          {
            "id": "rb",
            "label": "Rollback to prior digest",
            "sub": "≤ 5 min p95"
          },
          {
            "id": "aud",
            "label": "Audit record",
            "sub": "write-once",
            "kind": "store"
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "rb",
        "to": "e3",
        "label": "repoint",
        "kind": "sync",
        "route": "rl"
      }
    ],
    "note": "One digest crosses every environment, with configuration bound at deployment. Provenance is verified at every gate, and a skipped stage needs a recorded override.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "18-observability",
    "title": "CI/CD Platform — Observability Coverage",
    "layout": "grid",
    "laneHeaderWidth": 200,
    "columns": [
      "Admission",
      "Queue",
      "Execution",
      "Evidence",
      "Promotion"
    ],
    "rows": [
      {
        "title": "Latency SLI",
        "cells": [
          [
            {
              "label": "Event to queued p99"
            }
          ],
          [
            {
              "label": "Wait inside entitlement"
            }
          ],
          [
            {
              "label": "Queued to first step"
            }
          ],
          [
            {
              "label": "Sign + log write"
            }
          ],
          [
            {
              "label": "Decision to deploy"
            }
          ]
        ]
      },
      {
        "title": "Correctness SLI",
        "cells": [
          [
            {
              "label": "Definitions rejected"
            }
          ],
          [
            {
              "label": "Fairness violations",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Infra-failure ratio",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Verify failures",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Gate denials by reason"
            }
          ]
        ]
      },
      {
        "title": "Throughput",
        "cells": [
          [
            {
              "label": "Runs admitted/min"
            }
          ],
          [
            {
              "label": "Queue depth by tier"
            }
          ],
          [
            {
              "label": "Sandbox creations/min"
            }
          ],
          [
            {
              "label": "Digests sealed/min"
            }
          ],
          [
            {
              "label": "Deploys per env"
            }
          ]
        ]
      },
      {
        "title": "Cost",
        "cells": [
          [],
          [
            {
              "label": "Idle entitlement"
            }
          ],
          [
            {
              "label": "Cost per job-minute"
            },
            {
              "label": "Warm-pool waste"
            }
          ],
          [
            {
              "label": "Artefact TB by class"
            }
          ],
          []
        ]
      },
      {
        "title": "Security signal",
        "cells": [
          [
            {
              "label": "Trust misclassification",
              "kind": "risk"
            }
          ],
          [],
          [
            {
              "label": "Egress denials"
            },
            {
              "label": "Limit-breach kills"
            }
          ],
          [
            {
              "label": "Unsigned artefacts",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Overrides used"
            }
          ]
        ]
      },
      {
        "title": "Developer experience",
        "cells": [
          [
            {
              "label": "Validation error clarity"
            }
          ],
          [
            {
              "label": "Wait visibility"
            }
          ],
          [
            {
              "label": "Flake rate per pipeline"
            }
          ],
          [
            {
              "label": "Log tail lag"
            }
          ],
          [
            {
              "label": "Lead time to prod"
            }
          ]
        ]
      }
    ],
    "note": "Empty cells are deliberate: cost is not attributed at admission, and promotion has no security signal beyond the override count.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "19-run-lifecycle-loop",
    "title": "CI/CD Platform — The Run Lifecycle Loop",
    "layout": "cycle",
    "centre": {
      "label": "Run lifecycle"
    },
    "nodes": [
      {
        "id": "trig",
        "label": "Trigger",
        "sub": "event, schedule, API"
      },
      {
        "id": "adm",
        "label": "Admit",
        "sub": "compile + classify"
      },
      {
        "id": "sch",
        "label": "Schedule",
        "sub": "fair queue"
      },
      {
        "id": "exe",
        "label": "Execute",
        "sub": "single-use sandbox"
      },
      {
        "id": "seal",
        "label": "Seal",
        "sub": "sign + store"
      },
      {
        "id": "gate",
        "label": "Gate",
        "kind": "decision",
        "sub": "allow or deny"
      },
      {
        "id": "obs",
        "label": "Observe",
        "sub": "flake, cost, ratio"
      }
    ],
    "ringLabels": [
      "run record",
      "job graph",
      "job + lease",
      "digest",
      "evidence",
      "outcome",
      "next definition"
    ],
    "rx": 440,
    "ry": 220,
    "note": "The loop closes through observation: flake rate and infra-failure ratio change the next definition and the next entitlement, not a dashboard.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "20-security-trust-zones",
    "title": "CI/CD Platform — Trust Zones and Crossings",
    "layout": "zones",
    "zones": [
      {
        "title": "Untrusted — tenant code executes here",
        "kind": "trust",
        "nodes": [
          {
            "id": "forkvm",
            "label": "Fork build sandbox",
            "sub": "no secrets, no writes",
            "kind": "risk"
          },
          {
            "id": "vm",
            "label": "Single-use microVM",
            "sub": "no long-lived creds",
            "kind": "platform"
          },
          {
            "id": "agent",
            "label": "Per-job agent"
          }
        ]
      },
      {
        "title": "Mediated — everything the sandbox may reach",
        "kind": "trust",
        "nodes": [
          {
            "id": "egr",
            "label": "Egress policy proxy",
            "kind": "security"
          },
          {
            "id": "mir",
            "label": "Dependency mirror",
            "kind": "store"
          },
          {
            "id": "cachez",
            "label": "Cache: read wide, write if trusted",
            "kind": "store"
          },
          {
            "id": "casw",
            "label": "Artefact write, scoped",
            "kind": "store"
          }
        ]
      },
      {
        "title": "Control plane — no tenant code, ever",
        "kind": "trust",
        "nodes": [
          {
            "id": "brk",
            "label": "Secret broker",
            "kind": "security"
          },
          {
            "id": "idf",
            "label": "Identity federation",
            "kind": "security"
          },
          {
            "id": "att",
            "label": "Attestor",
            "kind": "security"
          },
          {
            "id": "gate",
            "label": "Gate decision service",
            "kind": "decision"
          }
        ]
      },
      {
        "title": "Custody — offline or hardware-held",
        "kind": "trust",
        "nodes": [
          {
            "id": "kms",
            "label": "Signing key",
            "sub": "never exported",
            "kind": "security"
          },
          {
            "id": "tlog",
            "label": "Transparency log",
            "sub": "write-once",
            "kind": "store"
          },
          {
            "id": "aud",
            "label": "Audit trail",
            "kind": "store"
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "vm",
        "to": "egr",
        "label": "egress",
        "kind": "sync"
      },
      {
        "from": "egr",
        "to": "mir",
        "label": "allow-listed",
        "kind": "sync"
      },
      {
        "from": "agent",
        "to": "att",
        "label": "reports, not asserts",
        "kind": "sync"
      },
      {
        "from": "att",
        "to": "tlog",
        "label": "append",
        "kind": "sync"
      },
      {
        "from": "gate",
        "to": "aud",
        "label": "every verdict",
        "kind": "sync"
      }
    ],
    "note": "The only upward path from the untrusted zone is a report the control plane validates. Nothing the sandbox says is taken as fact.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "21-identity-and-credential-flow",
    "title": "Identity — How a Job Gets a Credential and Loses It",
    "layout": "sequence",
    "lifelines": [
      {
        "id": "job",
        "label": "microVM job",
        "kind": "platform"
      },
      {
        "id": "agent",
        "label": "Job agent",
        "kind": "app"
      },
      {
        "id": "sch",
        "label": "Scheduler",
        "kind": "app"
      },
      {
        "id": "idf",
        "label": "Identity federation",
        "kind": "security"
      },
      {
        "id": "brk",
        "label": "Secret broker",
        "kind": "security"
      },
      {
        "id": "cloud",
        "label": "Cloud STS",
        "kind": "external"
      },
      {
        "id": "aud",
        "label": "Audit trail",
        "kind": "store"
      }
    ],
    "messages": [
      {
        "from": "sch",
        "to": "idf",
        "label": "mint job identity",
        "kind": "call"
      },
      {
        "from": "idf",
        "to": "idf",
        "label": "bind tenant, repo, ref, class",
        "kind": "self"
      },
      {
        "from": "idf",
        "to": "agent",
        "label": "OIDC token, job TTL",
        "kind": "return"
      },
      {
        "from": "job",
        "to": "agent",
        "label": "needs a secret",
        "kind": "call"
      },
      {
        "from": "agent",
        "to": "brk",
        "label": "present token + scope",
        "kind": "call"
      },
      {
        "from": "brk",
        "to": "brk",
        "label": "check class and policy",
        "kind": "self"
      },
      {
        "from": "brk",
        "to": "aud",
        "label": "record the read",
        "kind": "call"
      },
      {
        "from": "brk",
        "to": "agent",
        "label": "value, redaction registered",
        "kind": "return"
      },
      {
        "from": "agent",
        "to": "cloud",
        "label": "exchange for role",
        "kind": "call"
      },
      {
        "from": "cloud",
        "to": "agent",
        "label": "short-lived credential",
        "kind": "return"
      },
      {
        "from": "brk",
        "to": "agent",
        "label": "untrusted class: refused",
        "kind": "error"
      },
      {
        "from": "sch",
        "to": "idf",
        "label": "revoke on job end",
        "kind": "async"
      }
    ],
    "note": "Revocation does not wait for expiry, and the audit record is written before the value is returned, never after.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  },
  {
    "id": "22-failure-classes",
    "title": "CI/CD Platform — Failure Classes and Responses",
    "layout": "grid",
    "laneHeaderWidth": 210,
    "columns": [
      "What fails",
      "How it is detected",
      "Response",
      "What the user sees"
    ],
    "rows": [
      {
        "title": "Transient infrastructure",
        "cells": [
          [
            {
              "label": "Sandbox launch, image pull",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Agent never reports ready"
            }
          ],
          [
            {
              "label": "Retry on fresh capacity"
            }
          ],
          [
            {
              "label": "Nothing, below threshold"
            }
          ]
        ]
      },
      {
        "title": "Capacity reclamation",
        "cells": [
          [
            {
              "label": "Interruptible host taken",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Drain notice, lease loss"
            }
          ],
          [
            {
              "label": "Re-dispatch on-demand"
            }
          ],
          [
            {
              "label": "Longer run, same outcome"
            }
          ]
        ]
      },
      {
        "title": "Runner loss",
        "cells": [
          [
            {
              "label": "Host death, partition",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Lease expiry, not silence"
            }
          ],
          [
            {
              "label": "Re-dispatch, keep part log"
            }
          ],
          [
            {
              "label": "Attempt 2, cause named"
            }
          ]
        ]
      },
      {
        "title": "Poison job",
        "cells": [
          [
            {
              "label": "Escape, fork bomb, mining",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Limit breach, egress denial"
            }
          ],
          [
            {
              "label": "Kill, destroy, flag tenant"
            }
          ],
          [
            {
              "label": "Blocked by policy"
            }
          ]
        ]
      },
      {
        "title": "Dependency outage",
        "cells": [
          [
            {
              "label": "Registry or VCS down",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Mirror miss rate spike"
            }
          ],
          [
            {
              "label": "Serve from mirror"
            }
          ],
          [
            {
              "label": "Dependency unavailable"
            }
          ]
        ]
      },
      {
        "title": "Cache poisoning",
        "cells": [
          [
            {
              "label": "Hostile or bad entry",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Integrity check on restore"
            }
          ],
          [
            {
              "label": "Treat as miss, evict"
            }
          ],
          [
            {
              "label": "Slower build only"
            }
          ]
        ]
      },
      {
        "title": "Gate or policy failure",
        "cells": [
          [
            {
              "label": "Decision service down",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Health probe, timeout"
            }
          ],
          [
            {
              "label": "Fail closed in prod"
            }
          ],
          [
            {
              "label": "Promotion blocked"
            }
          ]
        ]
      },
      {
        "title": "Region loss",
        "cells": [
          [
            {
              "label": "Control plane region",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Multi-AZ probes all red"
            }
          ],
          [
            {
              "label": "Second region, new runs"
            }
          ],
          [
            {
              "label": "30 min degraded"
            }
          ]
        ]
      },
      {
        "title": "Permanent user failure",
        "cells": [
          [
            {
              "label": "Compile error, failing test"
            }
          ],
          [
            {
              "label": "Non-zero exit, no retry"
            }
          ],
          [
            {
              "label": "Report, never retry"
            }
          ],
          [
            {
              "label": "First-failure summary"
            }
          ]
        ]
      }
    ],
    "note": "Every row distinguishes platform failure from user failure, because conflating them is what teaches engineers to retry instead of read.",
    "meta": {
      "v": "1.0",
      "owner": "Platform Engineering",
      "date": "2026-09"
    }
  }
]
