[
  {
    "id": "01-system-context",
    "title": "Health & Discovery Plane — System Context",
    "layout": "context",
    "canvas": {
      "width": 1700
    },
    "system": {
      "label": "Health & Discovery Plane",
      "sub": "Who exists · who gets traffic"
    },
    "groups": [
      {
        "side": "left",
        "title": "People",
        "nodes": [
          {
            "id": "owner",
            "label": "Service owner",
            "kind": "actor",
            "rel": "declares health contract",
            "dir": "in"
          },
          {
            "id": "sre",
            "label": "SRE on call",
            "kind": "actor",
            "rel": "drains, evacuates",
            "dir": "in"
          },
          {
            "id": "sec",
            "label": "Security engineer",
            "kind": "actor",
            "rel": "audits denials",
            "dir": "in"
          }
        ]
      },
      {
        "side": "right",
        "title": "Registration sources",
        "nodes": [
          {
            "id": "eks",
            "label": "EKS control planes",
            "sub": "12 clusters",
            "kind": "external",
            "rel": "pod + endpoint state",
            "dir": "in"
          },
          {
            "id": "ecs",
            "label": "ECS + EC2 Auto Scaling",
            "sub": "VM and task fleets",
            "kind": "external",
            "rel": "instance state",
            "dir": "in"
          },
          {
            "id": "cat",
            "label": "Service catalogue",
            "sub": "ownership, tiers",
            "kind": "external",
            "rel": "service of record",
            "dir": "in"
          },
          {
            "id": "third",
            "label": "Third-party endpoints",
            "sub": "no readiness signal",
            "kind": "external",
            "rel": "declared, unprobed",
            "dir": "in"
          }
        ]
      },
      {
        "side": "top",
        "title": "The traffic path it serves",
        "nodes": [
          {
            "id": "callers",
            "label": "Internal callers",
            "sub": "450 services",
            "kind": "app",
            "rel": "resolve by name",
            "dir": "in"
          },
          {
            "id": "sidecar",
            "label": "Envoy sidecar fleet",
            "sub": "60,000 subscriptions",
            "kind": "app",
            "rel": "versioned views",
            "dir": "out"
          }
        ]
      },
      {
        "side": "bottom",
        "title": "Dependencies and consumers",
        "nodes": [
          {
            "id": "iam",
            "label": "Workload identity",
            "sub": "IAM roles for SA",
            "kind": "security",
            "rel": "authn",
            "dir": "in"
          },
          {
            "id": "dns",
            "label": "Route 53 + Cloud Map",
            "kind": "external",
            "rel": "DNS surface",
            "dir": "out"
          },
          {
            "id": "obs",
            "label": "Observability platform",
            "kind": "external",
            "rel": "signals",
            "dir": "out"
          }
        ]
      }
    ],
    "note": "Out of scope: load-balancing algorithms beyond the endpoint set and weights, mesh policy and mTLS, the public API edge.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture",
      "date": "2026-10"
    }
  },
  {
    "id": "02-high-level-architecture",
    "title": "High-Level Architecture — Observe, Decide, Publish, Route",
    "layout": "flow",
    "chain": true,
    "canvas": {
      "width": 1760
    },
    "stages": [
      {
        "title": "Observe",
        "nodes": [
          {
            "id": "probe",
            "label": "Active probers",
            "sub": "sharded, bounded fan-out",
            "kind": "platform"
          },
          {
            "id": "self",
            "label": "Self-report ingest",
            "sub": "readiness + deps",
            "kind": "integration"
          },
          {
            "id": "passive",
            "label": "Passive outcome ingest",
            "sub": "reported by callers",
            "kind": "integration"
          }
        ]
      },
      {
        "title": "Decide",
        "nodes": [
          {
            "id": "fuse",
            "label": "Signal fusion",
            "sub": "3 evidence classes",
            "kind": "app"
          },
          {
            "id": "damp",
            "label": "Hysteresis + flap damper",
            "sub": "decaying score",
            "kind": "app"
          },
          {
            "id": "guard",
            "label": "Min-healthy-fraction guard",
            "sub": "50% floor",
            "kind": "app"
          }
        ]
      },
      {
        "title": "Assemble",
        "nodes": [
          {
            "id": "view",
            "label": "Versioned view builder",
            "sub": "monotonic versions",
            "kind": "app"
          },
          {
            "id": "tiers",
            "label": "Topology priority tiers",
            "sub": "zone, region, cross",
            "kind": "app"
          }
        ]
      },
      {
        "title": "Publish",
        "nodes": [
          {
            "id": "xds",
            "label": "xDS stream tier",
            "sub": "incremental deltas",
            "kind": "integration"
          },
          {
            "id": "dnsa",
            "label": "DNS authority",
            "sub": "compatibility surface",
            "kind": "integration"
          },
          {
            "id": "api",
            "label": "Resolution API",
            "sub": "tooling only",
            "kind": "integration"
          }
        ]
      },
      {
        "title": "Route",
        "nodes": [
          {
            "id": "cache",
            "label": "Last-known-good cache",
            "sub": "durable, per client",
            "kind": "store"
          },
          {
            "id": "proxy",
            "label": "Envoy data plane",
            "sub": "ejection, shrink cap",
            "kind": "app"
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "proxy",
        "to": "passive",
        "label": "request outcomes",
        "kind": "async",
        "route": "gutter"
      },
      {
        "from": "cache",
        "to": "proxy",
        "label": "serves on outage",
        "kind": "error"
      }
    ],
    "note": "The seam is between Publish and Route: everything left of the cache may fail for an hour without changing where traffic goes.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "03-actors-and-journeys",
    "title": "Who This Is For, and What They Get To Do",
    "layout": "actors",
    "canvas": {
      "width": 1760
    },
    "groups": [
      {
        "title": "The people who change traffic",
        "kind": "boundary",
        "actors": [
          {
            "id": "owner",
            "label": "Service owner",
            "sub": "450 services, ~120 teams",
            "goal": "Ship twice a day without anyone noticing, and get told if my readiness check is lying about me.",
            "journeys": [
              {
                "id": "j-deploy",
                "label": "Deploy without dropping traffic"
              },
              {
                "label": "Declare a health contract"
              },
              {
                "label": "Read my own flap report"
              }
            ]
          },
          {
            "id": "sre",
            "label": "SRE on call",
            "sub": "follow-the-sun, 3 regions",
            "goal": "Decide in two minutes whether this is one bad replica, one bad zone, or my own health check.",
            "journeys": [
              {
                "id": "j-grey",
                "label": "Chase errors from one replica"
              },
              {
                "id": "j-evac",
                "label": "Evacuate a zone or region"
              },
              {
                "label": "Override an eligibility decision"
              }
            ]
          }
        ]
      },
      {
        "title": "The people who are owed an answer",
        "kind": "boundary",
        "actors": [
          {
            "id": "sec",
            "label": "Security engineer",
            "sub": "quarterly review",
            "goal": "Know that nothing but a service itself can mark that service unhealthy, and prove it from a log.",
            "journeys": [
              {
                "label": "Audit a denial of service"
              },
              {
                "label": "Review resolution authorisation"
              }
            ]
          },
          {
            "id": "plat",
            "label": "Platform engineer",
            "sub": "owns this plane",
            "goal": "Prove the request path survives my own control plane being switched off, before it is switched off for me.",
            "journeys": [
              {
                "label": "Run a control-plane removal drill"
              },
              {
                "label": "Onboard a non-orchestrated fleet"
              }
            ]
          }
        ]
      },
      {
        "title": "Machines in the cast",
        "kind": "cloud",
        "actors": [
          {
            "id": "caller",
            "label": "Calling service",
            "kind": "app",
            "sub": "12 M req/s peak",
            "goal": "Get an endpoint list I can route on right now, even if nothing answers me.",
            "journeys": [
              {
                "label": "Resolve a callee by name"
              },
              {
                "label": "Eject a bad endpoint locally"
              }
            ]
          },
          {
            "id": "deployer",
            "label": "Deploy pipeline",
            "kind": "platform",
            "sub": "~900 deploys/day",
            "goal": "Be told no when draining this instance would take the service below its floor.",
            "journeys": [
              {
                "label": "Request a drain"
              },
              {
                "label": "Ramp a new version"
              }
            ]
          },
          {
            "id": "ext",
            "label": "Third-party endpoint",
            "kind": "external",
            "sub": "health unknown",
            "goal": "Be routed to without pretending I publish a readiness signal.",
            "journeys": [
              {
                "label": "Be declared with no probe"
              }
            ]
          }
        ]
      }
    ],
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "04-journey-deploy-without-dropping-traffic",
    "title": "Journey — Deploy Without Dropping Traffic",
    "layout": "journey",
    "canvas": {
      "width": 1700
    },
    "actor": {
      "label": "Service owner",
      "sub": "ships twice a day",
      "goal": "Replace every replica of my service in ten minutes with nobody noticing",
      "trigger": "A merged pull request; the pipeline asks to drain the first instance",
      "success": "Old version gone, new version at full weight, zero caller-visible errors"
    },
    "phases": [
      {
        "title": "Ask to drain",
        "sub": "pipeline"
      },
      {
        "title": "Drain",
        "moment": true
      },
      {
        "title": "Terminate"
      },
      {
        "title": "Admit new version",
        "moment": true
      },
      {
        "title": "Ramp to full"
      }
    ],
    "lanes": [
      {
        "title": "What happens",
        "kind": "step",
        "cells": [
          [
            {
              "label": "Budget checked"
            }
          ],
          [
            {
              "label": "Marked draining"
            },
            {
              "label": "Withdrawal pushed"
            }
          ],
          [
            {
              "label": "Grace period ends"
            }
          ],
          [
            {
              "label": "Readiness passes"
            },
            {
              "label": "Weight 1 of 10"
            }
          ],
          [
            {
              "label": "Weight rises 60 s"
            }
          ]
        ]
      },
      {
        "title": "Who acts",
        "kind": "touch",
        "cells": [
          [
            {
              "label": "Deploy pipeline"
            }
          ],
          [
            {
              "label": "Evaluation tier"
            }
          ],
          [
            {
              "label": "Orchestrator"
            }
          ],
          [
            {
              "label": "Evaluation tier"
            }
          ],
          [
            {
              "label": "Every client"
            }
          ]
        ]
      },
      {
        "title": "How it feels",
        "kind": "emotion",
        "levels": [
          "Confident",
          "Watching",
          "Burned"
        ],
        "points": [
          1,
          2,
          1,
          1,
          0
        ]
      },
      {
        "title": "Where it hurts",
        "kind": "pain",
        "cells": [
          [
            {
              "label": "Budget refuses, no reason"
            }
          ],
          [
            {
              "label": "Terminated before callers knew"
            }
          ],
          [],
          [
            {
              "label": "Cold replica at full share"
            }
          ],
          []
        ]
      },
      {
        "title": "What answers it",
        "kind": "gain",
        "cells": [
          [
            {
              "label": "Typed refusal + floor"
            }
          ],
          [
            {
              "label": "Drain gated on measured delay"
            }
          ],
          [
            {
              "label": "Lease expiry backstop"
            }
          ],
          [
            {
              "label": "Control-plane slow start"
            }
          ],
          [
            {
              "label": "Ramp is uniform"
            }
          ]
        ]
      }
    ],
    "chain": true,
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "05-journey-chase-errors-from-one-replica",
    "title": "Journey — Chase Errors Coming From One Replica",
    "layout": "journey",
    "canvas": {
      "width": 1700
    },
    "actor": {
      "label": "SRE on call",
      "sub": "paged at 02:40",
      "goal": "Find out whether this is one replica, one zone, or my own health check — in under two minutes",
      "trigger": "A caller's error rate rises 4%; every probe is green",
      "success": "The bad replica is out of rotation and the reason is on the record"
    },
    "phases": [
      {
        "title": "Page",
        "sub": "error rate"
      },
      {
        "title": "Localise",
        "moment": true
      },
      {
        "title": "Explain"
      },
      {
        "title": "Act",
        "moment": true
      },
      {
        "title": "Close"
      }
    ],
    "lanes": [
      {
        "title": "What they do",
        "kind": "step",
        "cells": [
          [
            {
              "label": "Open the service page"
            }
          ],
          [
            {
              "label": "Compare per-endpoint rates"
            }
          ],
          [
            {
              "label": "Read the evidence trail"
            }
          ],
          [
            {
              "label": "Confirm or override"
            }
          ],
          [
            {
              "label": "File the flap report"
            }
          ]
        ]
      },
      {
        "title": "What the plane shows",
        "kind": "system",
        "cells": [
          [
            {
              "label": "Eligible fraction 100%"
            }
          ],
          [
            {
              "label": "One endpoint, 40% fail"
            }
          ],
          [
            {
              "label": "Probe green, passive red"
            }
          ],
          [
            {
              "label": "Weight already cut"
            }
          ],
          [
            {
              "label": "Transition + cause"
            }
          ]
        ]
      },
      {
        "title": "How it feels",
        "kind": "emotion",
        "levels": [
          "In control",
          "Hunting",
          "Blind"
        ],
        "points": [
          1,
          2,
          1,
          0,
          1
        ]
      },
      {
        "title": "Where it hurts",
        "kind": "pain",
        "cells": [
          [],
          [
            {
              "label": "Grey failure probes clean"
            }
          ],
          [],
          [
            {
              "label": "Override is a denial of service"
            }
          ],
          []
        ]
      },
      {
        "title": "What answers it",
        "kind": "gain",
        "cells": [
          [
            {
              "label": "Per-endpoint outcomes"
            }
          ],
          [
            {
              "label": "Passive signal is primary"
            }
          ],
          [
            {
              "label": "Inputs exposed per decision"
            }
          ],
          [
            {
              "label": "Override audited, rate-limited"
            }
          ],
          [
            {
              "label": "Quarantine, not a guess"
            }
          ]
        ]
      }
    ],
    "chain": true,
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "06-journey-evacuate-a-zone",
    "title": "Journey — Evacuate a Zone, and Bring It Back",
    "layout": "journey",
    "canvas": {
      "width": 1700
    },
    "actor": {
      "label": "SRE on call",
      "sub": "declared incident",
      "goal": "Move traffic out of one availability zone in a minute, and back only when I say so",
      "trigger": "Elevated latency across every service in one zone; the cause is below us",
      "success": "Zone carries no traffic, nothing else changed, and the way back is one reversible step"
    },
    "phases": [
      {
        "title": "Suspect",
        "sub": "cross-service"
      },
      {
        "title": "Declare",
        "moment": true
      },
      {
        "title": "Shift"
      },
      {
        "title": "Hold"
      },
      {
        "title": "Return",
        "moment": true
      }
    ],
    "lanes": [
      {
        "title": "What they do",
        "kind": "step",
        "cells": [
          [
            {
              "label": "See zone-wide latency"
            }
          ],
          [
            {
              "label": "Declare evacuation"
            }
          ],
          [
            {
              "label": "Watch tiers re-order"
            }
          ],
          [
            {
              "label": "Leave it drained"
            }
          ],
          [
            {
              "label": "Complete shift-back"
            }
          ]
        ]
      },
      {
        "title": "What the plane does",
        "kind": "system",
        "cells": [
          [
            {
              "label": "Failure domain tagged"
            }
          ],
          [
            {
              "label": "Topology preference shifts"
            }
          ],
          [
            {
              "label": "40k changes / minute"
            }
          ],
          [
            {
              "label": "Instances still registered"
            }
          ],
          [
            {
              "label": "Rate-capped return"
            }
          ]
        ]
      },
      {
        "title": "How it feels",
        "kind": "emotion",
        "levels": [
          "Calm",
          "Tense",
          "Exposed"
        ],
        "points": [
          2,
          1,
          1,
          0,
          1
        ]
      },
      {
        "title": "Where it hurts",
        "kind": "pain",
        "cells": [
          [
            {
              "label": "Is it the zone or us?"
            }
          ],
          [
            {
              "label": "Wrong zone named"
            }
          ],
          [
            {
              "label": "Burst breaks the budget"
            }
          ],
          [
            {
              "label": "Remaining zones overload"
            }
          ],
          [
            {
              "label": "Herd hits the cold zone"
            }
          ]
        ]
      },
      {
        "title": "What answers it",
        "kind": "gain",
        "cells": [
          [
            {
              "label": "Failure domains first-class"
            }
          ],
          [
            {
              "label": "One-step reversible"
            }
          ],
          [
            {
              "label": "Withdrawal budget held"
            }
          ],
          [
            {
              "label": "Fraction guard per zone"
            }
          ],
          [
            {
              "label": "Explicit, capped return"
            }
          ]
        ]
      }
    ],
    "chain": true,
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "07-layered-architecture",
    "title": "Layered Architecture — Only Layer 7 Is In The Request Path",
    "layout": "bands",
    "canvas": {
      "width": 1740
    },
    "layerHeaderWidth": 170,
    "bands": [
      {
        "name": "1 · Sources of truth",
        "nodes": [
          {
            "id": "l-eks",
            "label": "EKS endpoint state",
            "kind": "external"
          },
          {
            "id": "l-ecs",
            "label": "ECS + ASG state",
            "kind": "external"
          },
          {
            "id": "l-cat",
            "label": "Service catalogue",
            "kind": "external"
          },
          {
            "id": "l-ext",
            "label": "External declarations",
            "kind": "external"
          }
        ]
      },
      {
        "name": "2 · Registry",
        "nodes": [
          {
            "id": "l-svc",
            "label": "Services + contracts",
            "kind": "store"
          },
          {
            "id": "l-inst",
            "label": "Instances + leases",
            "kind": "store"
          },
          {
            "id": "l-topo",
            "label": "Topology + policy",
            "kind": "store"
          }
        ]
      },
      {
        "name": "3 · Signal collection",
        "nodes": [
          {
            "id": "l-probe",
            "label": "Active probers",
            "kind": "platform"
          },
          {
            "id": "l-self",
            "label": "Self-report ingest",
            "kind": "integration"
          },
          {
            "id": "l-pass",
            "label": "Passive outcomes",
            "kind": "integration"
          }
        ]
      },
      {
        "name": "4 · Evaluation",
        "nodes": [
          {
            "id": "l-fuse",
            "label": "Signal fusion",
            "kind": "app"
          },
          {
            "id": "l-hyst",
            "label": "Hysteresis + quarantine",
            "kind": "app"
          },
          {
            "id": "l-frac",
            "label": "Fraction guard",
            "kind": "app"
          },
          {
            "id": "l-ramp",
            "label": "Weights + slow start",
            "kind": "app"
          }
        ]
      },
      {
        "name": "5 · View assembly",
        "nodes": [
          {
            "id": "l-view",
            "label": "Versioned views",
            "kind": "app"
          },
          {
            "id": "l-filt",
            "label": "Filters + tiers",
            "kind": "app"
          },
          {
            "id": "l-delta",
            "label": "Delta encoder",
            "kind": "app"
          }
        ]
      },
      {
        "name": "6 · Propagation",
        "nodes": [
          {
            "id": "l-xds",
            "label": "xDS stream tier",
            "kind": "integration"
          },
          {
            "id": "l-dns",
            "label": "DNS authority",
            "kind": "integration"
          },
          {
            "id": "l-api",
            "label": "Resolution API",
            "kind": "integration"
          }
        ]
      },
      {
        "name": "7 · Client data plane",
        "accent": "#dae8fc",
        "nodes": [
          {
            "id": "l-cache",
            "label": "Last-known-good cache",
            "kind": "store"
          },
          {
            "id": "l-eject",
            "label": "Outlier ejection",
            "kind": "app"
          },
          {
            "id": "l-shrink",
            "label": "Shrink cap",
            "kind": "app"
          },
          {
            "id": "l-route",
            "label": "Route selection",
            "kind": "app"
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "l-cat",
        "to": "l-svc",
        "label": "reconcile"
      },
      {
        "from": "l-inst",
        "to": "l-probe",
        "label": "probe assignment"
      },
      {
        "from": "l-pass",
        "to": "l-fuse",
        "label": "outcomes",
        "kind": "async"
      },
      {
        "from": "l-frac",
        "to": "l-view",
        "label": "eligibility"
      },
      {
        "from": "l-delta",
        "to": "l-xds",
        "label": "versioned delta"
      },
      {
        "from": "l-xds",
        "to": "l-cache",
        "label": "push",
        "kind": "async"
      },
      {
        "from": "l-route",
        "to": "l-pass",
        "label": "outcomes",
        "kind": "async",
        "route": "gutter"
      }
    ],
    "note": "Layers 1 to 6 are advisory. Layer 7 keeps routing from cache for 60 minutes with none of them available.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "08-platform-components",
    "title": "Platform Components — Four Planes, One Of Them Optional",
    "layout": "nested",
    "canvas": {
      "width": 1760
    },
    "boxes": [
      {
        "title": "Control plane — advisory, per region",
        "kind": "cloud",
        "dir": "col",
        "children": [
          {
            "title": "Registration and desired state",
            "kind": "boundary",
            "nodes": [
              {
                "id": "recon",
                "label": "Reconciler",
                "sub": "orchestrator watch",
                "kind": "app"
              },
              {
                "id": "regapi",
                "label": "Registration API",
                "sub": "non-orchestrated",
                "kind": "integration"
              },
              {
                "id": "reg",
                "label": "Registry store",
                "sub": "strongly consistent",
                "kind": "store"
              },
              {
                "id": "pol",
                "label": "Policy store",
                "sub": "contracts, topology",
                "kind": "store"
              }
            ]
          },
          {
            "title": "Observation",
            "kind": "boundary",
            "nodes": [
              {
                "id": "prober",
                "label": "Prober fleet",
                "sub": "bounded assignment",
                "kind": "platform"
              },
              {
                "id": "ingest",
                "label": "Signal ingest",
                "sub": "1.2 M results/s",
                "kind": "integration"
              },
              {
                "id": "obsst",
                "label": "Observed-state store",
                "sub": "7-day, write-sized",
                "kind": "store"
              }
            ]
          },
          {
            "title": "Evaluation and assembly",
            "kind": "boundary",
            "nodes": [
              {
                "id": "eval",
                "label": "Evaluator",
                "sub": "sharded by service",
                "kind": "app"
              },
              {
                "id": "asm",
                "label": "View assembler",
                "sub": "in memory only",
                "kind": "app"
              },
              {
                "id": "log",
                "label": "Transition log",
                "sub": "append-only",
                "kind": "store"
              }
            ]
          },
          {
            "title": "Propagation",
            "kind": "boundary",
            "nodes": [
              {
                "id": "xdsn",
                "label": "xDS stream tier",
                "sub": "60k subscriptions",
                "kind": "integration"
              },
              {
                "id": "dnsn",
                "label": "DNS authority",
                "sub": "Cloud Map / Route 53",
                "kind": "integration"
              },
              {
                "id": "apin",
                "label": "Resolution API",
                "sub": "tooling, admin",
                "kind": "integration"
              }
            ]
          }
        ]
      },
      {
        "title": "Data plane — authoritative for routing",
        "kind": "trust",
        "dir": "row",
        "children": [
          {
            "title": "Per workload",
            "kind": "boundary",
            "nodes": [
              {
                "id": "sc",
                "label": "Envoy sidecar",
                "sub": "xDS client",
                "kind": "app"
              },
              {
                "id": "lkg",
                "label": "Last-known-good cache",
                "sub": "durable, on disk",
                "kind": "store"
              },
              {
                "id": "guards",
                "label": "Client guards",
                "sub": "ejection, shrink cap",
                "kind": "app"
              }
            ]
          },
          {
            "title": "Runtime edge",
            "kind": "boundary",
            "nodes": [
              {
                "id": "tg",
                "label": "NLB / ALB target groups",
                "sub": "fed by views",
                "kind": "integration"
              },
              {
                "id": "lib",
                "label": "Thin resolver library",
                "sub": "sidecar-less callers",
                "kind": "app"
              }
            ]
          }
        ]
      }
    ],
    "outside": [
      {
        "id": "idp",
        "label": "Workload identity",
        "sub": "IRSA / SPIFFE",
        "kind": "security"
      },
      {
        "id": "obsp",
        "label": "Observability platform",
        "kind": "external"
      },
      {
        "id": "arc",
        "label": "Readiness + failover signal",
        "sub": "out-of-band",
        "kind": "platform"
      }
    ],
    "edges": [
      {
        "from": "asm",
        "to": "xdsn",
        "label": "versioned deltas"
      },
      {
        "from": "xdsn",
        "to": "sc",
        "kind": "async"
      },
      {
        "from": "sc",
        "to": "lkg",
        "label": "persist view"
      },
      {
        "from": "lkg",
        "to": "sc",
        "label": "fail static",
        "kind": "error"
      },
      {
        "from": "idp",
        "to": "regapi",
        "label": "authn"
      },
      {
        "from": "log",
        "to": "obsp",
        "label": "transitions",
        "kind": "async"
      }
    ],
    "note": "The control plane is one box because it fails as one. Nothing in it is on the request path.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "09-resolution-surfaces",
    "title": "Interface Catalogue — Three Ways In, Three Ways Out",
    "layout": "hub",
    "canvas": {
      "width": 1740
    },
    "left": {
      "title": "Inbound — what feeds it",
      "nodes": [
        {
          "id": "h-eks",
          "label": "Orchestrator watch",
          "sub": "EKS, ECS, Auto Scaling",
          "kind": "external",
          "rel": " ",
          "dir": "in"
        },
        {
          "id": "h-reg",
          "label": "Instance API",
          "sub": "register, health, drain",
          "kind": "integration",
          "rel": "self only",
          "dir": "in"
        },
        {
          "id": "h-pass",
          "label": "Outcome channel",
          "sub": "reported by callers",
          "kind": "integration",
          "rel": " ",
          "dir": "in",
          "kind2": "async"
        },
        {
          "id": "h-pol",
          "label": "Policy API",
          "sub": "contracts, evacuation",
          "kind": "integration",
          "rel": " ",
          "dir": "in"
        }
      ]
    },
    "centre": {
      "title": "Health & Discovery Plane",
      "nodes": [
        {
          "id": "h-core",
          "label": "Regional control plane",
          "sub": "advisory",
          "kind": "app"
        }
      ]
    },
    "right": {
      "title": "Outbound — what it publishes",
      "nodes": [
        {
          "id": "h-xds",
          "label": "xDS subscription",
          "sub": "primary surface",
          "kind": "integration",
          "rel": "deltas",
          "dir": "out",
          "kind2": "async"
        },
        {
          "id": "h-dns",
          "label": "DNS zone",
          "sub": "compatibility surface",
          "kind": "integration",
          "rel": " ",
          "dir": "out"
        },
        {
          "id": "h-api",
          "label": "Resolution API",
          "sub": "tooling, target groups",
          "kind": "integration",
          "rel": " ",
          "dir": "out"
        },
        {
          "id": "h-sig",
          "label": "Signal + audit export",
          "sub": "90-day, 5-year",
          "kind": "integration",
          "rel": " ",
          "dir": "out",
          "kind2": "async"
        }
      ]
    },
    "note": "Four interfaces in, four out, and one contract in each direction: identity-attributed input, versioned output. Target-group membership rides the resolution API; no surface here may be read synchronously on a request.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "10-health-signal-flow",
    "title": "Data Flow — One Health Signal To One Routing Change",
    "layout": "flow",
    "chain": true,
    "canvas": {
      "width": 1780
    },
    "stages": [
      {
        "title": "Produced",
        "nodes": [
          {
            "id": "f-probe",
            "label": "Probe result",
            "sub": "pass / fail / timeout",
            "kind": "app"
          },
          {
            "id": "f-self",
            "label": "Readiness report",
            "sub": "ready / degraded / unready",
            "kind": "app"
          },
          {
            "id": "f-out",
            "label": "Request outcome",
            "sub": "per caller, per endpoint",
            "kind": "app"
          }
        ]
      },
      {
        "title": "Attributed",
        "nodes": [
          {
            "id": "f-ident",
            "label": "Identity check",
            "sub": "self-report only",
            "kind": "security"
          },
          {
            "id": "f-drop",
            "label": "Unattributable dropped",
            "sub": "never trusted",
            "kind": "risk"
          }
        ]
      },
      {
        "title": "Scored",
        "nodes": [
          {
            "id": "f-score",
            "label": "Decaying score",
            "sub": "per instance, per class",
            "kind": "app"
          },
          {
            "id": "f-unknown",
            "label": "Unknown detector",
            "sub": "silence ≠ unhealthy",
            "kind": "app"
          }
        ]
      },
      {
        "title": "Decided",
        "nodes": [
          {
            "id": "f-elig",
            "label": "Eligibility",
            "sub": "4 states + weight",
            "kind": "decision"
          },
          {
            "id": "f-guard",
            "label": "Fraction guard",
            "sub": "veto on mass withdrawal",
            "kind": "app"
          }
        ]
      },
      {
        "title": "Published",
        "nodes": [
          {
            "id": "f-ver",
            "label": "View version n+1",
            "sub": "delta only",
            "kind": "app"
          },
          {
            "id": "f-trans",
            "label": "Transition record",
            "sub": "cause + evidence",
            "kind": "store"
          }
        ]
      },
      {
        "title": "Applied",
        "nodes": [
          {
            "id": "f-client",
            "label": "Client view",
            "sub": "monotonic apply",
            "kind": "app"
          },
          {
            "id": "f-cache",
            "label": "Cache written",
            "sub": "durable",
            "kind": "store"
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "f-unknown",
        "to": "f-elig",
        "kind": "error"
      },
      {
        "from": "f-client",
        "to": "f-out",
        "label": "next outcomes",
        "kind": "async",
        "route": "gutter"
      }
    ],
    "note": "Withdrawal travels this path in 5 s at p99; an addition is deliberately allowed 30 s.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "11-state-classes",
    "title": "State Classes — Ordered By What Happens If It Is Lost",
    "layout": "nested",
    "canvas": {
      "width": 1740
    },
    "boxes": [
      {
        "title": "Desired state — RPO 0, system of record",
        "kind": "trust",
        "dir": "row",
        "children": [
          {
            "title": "Registry (regional, strongly consistent)",
            "kind": "boundary",
            "nodes": [
              {
                "id": "s-svc",
                "label": "Services",
                "sub": "450 rows",
                "kind": "store"
              },
              {
                "id": "s-inst",
                "label": "Instances + leases",
                "sub": "60,000 rows",
                "kind": "store"
              },
              {
                "id": "s-con",
                "label": "Health contracts",
                "sub": "versioned",
                "kind": "store"
              }
            ]
          },
          {
            "title": "Policy",
            "kind": "boundary",
            "nodes": [
              {
                "id": "s-topo",
                "label": "Topology + domains",
                "kind": "store"
              },
              {
                "id": "s-budget",
                "label": "Budgets + fractions",
                "kind": "store"
              },
              {
                "id": "s-authz",
                "label": "Resolution authz",
                "kind": "store"
              }
            ]
          }
        ]
      },
      {
        "title": "Observed state — RPO 60 s, recomputable",
        "kind": "boundary",
        "dir": "row",
        "children": [
          {
            "title": "Samples",
            "kind": "plain",
            "nodes": [
              {
                "id": "s-probe",
                "label": "Probe results",
                "sub": "7 days",
                "kind": "store"
              },
              {
                "id": "s-pass",
                "label": "Caller outcomes",
                "sub": "7 days",
                "kind": "store"
              },
              {
                "id": "s-lease",
                "label": "Lease renewals",
                "sub": "rolling",
                "kind": "store"
              }
            ]
          },
          {
            "title": "Evidence kept longer",
            "kind": "plain",
            "nodes": [
              {
                "id": "s-trans",
                "label": "Transitions + cause",
                "sub": "90 days",
                "kind": "store"
              },
              {
                "id": "s-audit",
                "label": "Audit records",
                "sub": "5 years, immutable",
                "kind": "store"
              }
            ]
          }
        ]
      },
      {
        "title": "Computed state — no RPO, rebuilt not restored",
        "kind": "lane",
        "dir": "row",
        "children": [
          {
            "title": "Control plane memory",
            "kind": "plain",
            "nodes": [
              {
                "id": "s-elig",
                "label": "Eligibility + weights",
                "kind": "app"
              },
              {
                "id": "s-views",
                "label": "Versioned views",
                "kind": "app"
              }
            ]
          },
          {
            "title": "Client memory and disk",
            "kind": "plain",
            "nodes": [
              {
                "id": "s-lkg",
                "label": "Last-known-good cache",
                "sub": "per client, durable",
                "kind": "store"
              }
            ]
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "s-inst",
        "to": "s-elig",
        "label": "rebuild input"
      },
      {
        "from": "s-probe",
        "to": "s-elig",
        "label": "rebuild input"
      },
      {
        "from": "s-views",
        "to": "s-lkg",
        "label": "pushed",
        "kind": "async"
      }
    ],
    "note": "The one durable copy on the request path is the client cache — and it is the one copy the platform cannot restore.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "12-registry-data-model",
    "title": "Registry Data Model — Identity, Contract, Evidence",
    "layout": "er",
    "canvas": {
      "width": 1700,
      "cols": 3
    },
    "rowGap": 250,
    "entities": [
      {
        "id": "contract",
        "name": "health_contract",
        "kind": "store",
        "row": 0,
        "col": 0,
        "attrs": [
          "contract_id  PK",
          "service_id  FK",
          "version",
          "signal",
          "interval_ms",
          "timeout_ms",
          "fail_threshold",
          "pass_threshold",
          "dependency_authority"
        ]
      },
      {
        "id": "service",
        "name": "service",
        "kind": "store",
        "row": 0,
        "col": 1,
        "attrs": [
          "service_id  PK",
          "name  UQ",
          "owner_team",
          "tier",
          "protocol",
          "port_contract",
          "min_healthy_fraction",
          "capability_profile"
        ]
      },
      {
        "id": "policy",
        "name": "policy_change",
        "kind": "store",
        "row": 0,
        "col": 2,
        "attrs": [
          "change_id  PK",
          "service_id  FK  nullable",
          "kind  contract|budget|evacuation",
          "actor",
          "justification",
          "staged_from",
          "at"
        ]
      },
      {
        "id": "topo",
        "name": "failure_domain",
        "kind": "store",
        "row": 1,
        "col": 0,
        "attrs": [
          "domain_id  PK",
          "kind  region|zone|cluster",
          "parent_id  FK",
          "evacuation_state"
        ]
      },
      {
        "id": "instance",
        "name": "instance",
        "kind": "store",
        "row": 1,
        "col": 1,
        "attrs": [
          "instance_id  PK  never reused",
          "service_id  FK",
          "domain_id  FK",
          "address",
          "port",
          "runtime_type",
          "deploy_version",
          "lease_renewed_at",
          "lease_ttl_ms"
        ]
      },
      {
        "id": "sample",
        "name": "health_sample",
        "kind": "store",
        "row": 1,
        "col": 2,
        "attrs": [
          "sample_id  PK",
          "instance_id  FK",
          "class  probe|self|passive",
          "reporter_identity",
          "result",
          "observed_at"
        ]
      },
      {
        "id": "elig",
        "name": "eligibility",
        "kind": "store",
        "row": 2,
        "col": 1,
        "attrs": [
          "instance_id  PK FK",
          "state  eligible|degraded|",
          "          ineligible|unknown",
          "weight",
          "score",
          "quarantine_until",
          "computed_at"
        ]
      },
      {
        "id": "trans",
        "name": "transition",
        "kind": "store",
        "row": 2,
        "col": 2,
        "attrs": [
          "transition_id  PK",
          "instance_id  FK",
          "from_state",
          "to_state",
          "cause",
          "evidence_sample_id  FK",
          "actor",
          "at"
        ]
      }
    ],
    "relations": [
      {
        "from": "service",
        "to": "contract",
        "label": "1 : N",
        "from_side": "w",
        "to_side": "e"
      },
      {
        "from": "service",
        "to": "policy",
        "label": "1 : N",
        "from_side": "e",
        "to_side": "w",
        "kind": "optional"
      },
      {
        "from": "service",
        "to": "instance",
        "label": "1 : N",
        "from_side": "s",
        "to_side": "n"
      },
      {
        "from": "topo",
        "to": "instance",
        "label": "1 : N",
        "from_side": "e",
        "to_side": "w"
      },
      {
        "from": "instance",
        "to": "sample",
        "label": "1 : N",
        "from_side": "e",
        "to_side": "w"
      },
      {
        "from": "instance",
        "to": "elig",
        "label": "1 : 1",
        "from_side": "s",
        "to_side": "n"
      },
      {
        "from": "elig",
        "to": "trans",
        "label": "1 : N",
        "from_side": "e",
        "to_side": "w"
      },
      {
        "from": "sample",
        "to": "trans",
        "label": "0 : N",
        "from_side": "s",
        "to_side": "n"
      }
    ],
    "note": "Eight durable entities. Published views and client subscriptions are deliberately absent: they are computed state held in memory, not registry rows — see view 11.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "13-withdrawal-propagation",
    "title": "Critical Flow — A Replica Fails, And Traffic Stops In Five Seconds",
    "layout": "sequence",
    "canvas": {
      "width": 1700
    },
    "lifelines": [
      {
        "id": "caller",
        "label": "Calling service",
        "kind": "app"
      },
      {
        "id": "sc",
        "label": "Envoy sidecar",
        "kind": "app"
      },
      {
        "id": "bad",
        "label": "Failing replica",
        "kind": "risk"
      },
      {
        "id": "ing",
        "label": "Signal ingest",
        "kind": "integration"
      },
      {
        "id": "ev",
        "label": "Evaluator",
        "kind": "app"
      },
      {
        "id": "asm",
        "label": "View assembler",
        "kind": "app"
      },
      {
        "id": "xds",
        "label": "xDS stream tier",
        "kind": "integration"
      }
    ],
    "messages": [
      {
        "from": "caller",
        "to": "sc",
        "label": "call service B",
        "kind": "call"
      },
      {
        "from": "sc",
        "to": "bad",
        "label": "request",
        "kind": "call"
      },
      {
        "from": "bad",
        "to": "sc",
        "label": "503 / timeout",
        "kind": "error"
      },
      {
        "from": "sc",
        "to": "sc",
        "label": "local ejection, weight 0",
        "kind": "self"
      },
      {
        "from": "sc",
        "to": "caller",
        "label": "retried elsewhere, 200",
        "kind": "return"
      },
      {
        "from": "sc",
        "to": "ing",
        "label": "outcome report",
        "kind": "async"
      },
      {
        "from": "ing",
        "to": "ev",
        "label": "passive sample",
        "kind": "async"
      },
      {
        "from": "ev",
        "to": "ev",
        "label": "score decays past threshold",
        "kind": "self"
      },
      {
        "from": "ev",
        "to": "ev",
        "label": "fraction guard: 59% still eligible",
        "kind": "self"
      },
      {
        "from": "ev",
        "to": "asm",
        "label": "ineligible + cause",
        "kind": "call"
      },
      {
        "from": "asm",
        "to": "xds",
        "label": "delta, version n+1",
        "kind": "call"
      },
      {
        "from": "xds",
        "to": "sc",
        "label": "push delta",
        "kind": "async"
      },
      {
        "from": "sc",
        "to": "sc",
        "label": "monotonic apply, cache write",
        "kind": "self"
      },
      {
        "from": "sc",
        "to": "caller",
        "label": "endpoint gone from the set",
        "kind": "return"
      }
    ],
    "note": "Steps 4 and 5 are why the user never sees this: the client ejects before the control plane has an opinion.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "14-registration-to-eligible",
    "title": "Registration To Eligible — Four Runtimes, One Surface",
    "layout": "swimlane",
    "canvas": {
      "width": 1780
    },
    "laneHeaderWidth": 180,
    "stages": [
      "Appears",
      "Identified",
      "Probed",
      "Eligible",
      "At full weight"
    ],
    "lanes": [
      {
        "title": "EKS pod",
        "cells": [
          [
            {
              "label": "EndpointSlice watch",
              "kind": "external"
            }
          ],
          [
            {
              "label": "IRSA identity",
              "kind": "security"
            }
          ],
          [
            {
              "label": "Readiness + liveness",
              "kind": "app"
            }
          ],
          [
            {
              "label": "20 s to eligible",
              "kind": "app"
            }
          ],
          [
            {
              "label": "60 s slow start",
              "kind": "app"
            }
          ]
        ]
      },
      {
        "title": "ECS task",
        "cells": [
          [
            {
              "label": "Task state change",
              "kind": "external"
            }
          ],
          [
            {
              "label": "Task role identity",
              "kind": "security"
            }
          ],
          [
            {
              "label": "Container health + self",
              "kind": "app"
            }
          ],
          [
            {
              "label": "20 s to eligible",
              "kind": "app"
            }
          ],
          [
            {
              "label": "60 s slow start",
              "kind": "app"
            }
          ]
        ]
      },
      {
        "title": "EC2 fleet instance",
        "cells": [
          [
            {
              "label": "ASG lifecycle hook",
              "kind": "external"
            }
          ],
          [
            {
              "label": "Instance profile",
              "kind": "security"
            }
          ],
          [
            {
              "label": "Agent self-report",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Lease renewal required",
              "kind": "app"
            }
          ],
          [
            {
              "label": "60 s slow start",
              "kind": "app"
            }
          ]
        ]
      },
      {
        "title": "Third-party endpoint",
        "cells": [
          [
            {
              "label": "Declared by owner",
              "kind": "integration"
            }
          ],
          [
            {
              "label": "Owner's identity",
              "kind": "security"
            }
          ],
          [
            {
              "label": "No signal available",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Eligible, health unknown",
              "kind": "decision"
            }
          ],
          [
            {
              "label": "Passive outcomes only",
              "kind": "app"
            }
          ]
        ]
      },
      {
        "title": "What the caller sees",
        "cells": [
          [
            {
              "label": "Nothing yet",
              "kind": "plain"
            }
          ],
          [
            {
              "label": "Nothing yet",
              "kind": "plain"
            }
          ],
          [
            {
              "label": "Nothing yet",
              "kind": "plain"
            }
          ],
          [
            {
              "label": "Endpoint, weight 0.1",
              "kind": "journey"
            }
          ],
          [
            {
              "label": "Endpoint, full weight",
              "kind": "journey"
            }
          ]
        ]
      }
    ],
    "note": "The caller's row is identical for all four. Capability is declared per service, so the third-party row is honest rather than hidden.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "15-eligibility-decision-path",
    "title": "Eligibility — Every Path From Signal To Verdict",
    "layout": "flow",
    "chain": false,
    "canvas": {
      "width": 1780
    },
    "align": "top",
    "stages": [
      {
        "title": "Evidence",
        "nodes": [
          {
            "id": "e-silent",
            "label": "No signal",
            "sub": "all classes quiet",
            "kind": "app"
          },
          {
            "id": "e-dep",
            "label": "Dependency degraded",
            "sub": "self-reported",
            "kind": "app"
          },
          {
            "id": "e-soft",
            "label": "Failure rate rising",
            "sub": "probe or passive",
            "kind": "app"
          },
          {
            "id": "e-hard",
            "label": "Hard failure",
            "sub": "refused, process gone",
            "kind": "app"
          }
        ]
      },
      {
        "title": "First test",
        "nodes": [
          {
            "id": "d-corrob",
            "label": "Corroborated by a second class?",
            "kind": "decision"
          },
          {
            "id": "d-shared",
            "label": "Dependency declared shared?",
            "kind": "decision"
          },
          {
            "id": "d-score",
            "label": "Decaying score vs threshold",
            "kind": "app"
          },
          {
            "id": "d-fast",
            "label": "Fast path, skip decay",
            "kind": "app"
          }
        ]
      },
      {
        "title": "Damping",
        "nodes": [
          {
            "id": "d-flap",
            "label": "Transitions > 4 in 10 min?",
            "kind": "decision"
          }
        ]
      },
      {
        "title": "Veto",
        "nodes": [
          {
            "id": "d-frac",
            "label": "Would this breach 50%?",
            "kind": "decision"
          }
        ]
      },
      {
        "title": "Verdict",
        "nodes": [
          {
            "id": "v-unk",
            "label": "Unknown",
            "sub": "kept in rotation",
            "kind": "decision"
          },
          {
            "id": "v-deg",
            "label": "Degraded",
            "sub": "weight reduced",
            "kind": "integration"
          },
          {
            "id": "v-quar",
            "label": "Quarantined",
            "sub": "backoff, owner notified",
            "kind": "risk"
          },
          {
            "id": "v-inel",
            "label": "Ineligible",
            "sub": "removed from views",
            "kind": "risk"
          },
          {
            "id": "v-ignore",
            "label": "Health disregarded",
            "sub": "full set, declared",
            "kind": "decision"
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "e-silent",
        "to": "d-corrob"
      },
      {
        "from": "e-dep",
        "to": "d-shared"
      },
      {
        "from": "e-soft",
        "to": "d-score"
      },
      {
        "from": "e-hard",
        "to": "d-fast"
      },
      {
        "from": "d-corrob",
        "to": "v-unk",
        "kind": "error",
        "route": "gutter"
      },
      {
        "from": "d-corrob",
        "to": "d-flap"
      },
      {
        "from": "d-shared",
        "to": "v-deg",
        "label": "weight only",
        "route": "gutter"
      },
      {
        "from": "d-shared",
        "to": "d-flap"
      },
      {
        "from": "d-score",
        "to": "d-flap",
        "label": "crossed"
      },
      {
        "from": "d-fast",
        "to": "d-frac"
      },
      {
        "from": "d-flap",
        "to": "v-quar",
        "label": "yes",
        "kind": "error"
      },
      {
        "from": "d-flap",
        "to": "d-frac"
      },
      {
        "from": "d-frac",
        "to": "v-inel",
        "label": "no"
      },
      {
        "from": "d-frac",
        "to": "v-ignore",
        "label": "yes",
        "kind": "error",
        "route": "gutter"
      }
    ],
    "note": "Two of five verdicts keep the instance in rotation: silence that nothing corroborates stays Unknown, and a shared dependency only reduces weight. A removal that would take the last eligible instance in a region raises an incident instead.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "16-deployment-architecture",
    "title": "Deployment — Regional Authority, No Global Request-Path Dependency",
    "layout": "nested",
    "canvas": {
      "width": 1780
    },
    "boxes": [
      {
        "title": "AWS us-east-1 (home region)",
        "kind": "cloud",
        "dir": "row",
        "children": [
          {
            "title": "AZ a",
            "kind": "boundary",
            "nodes": [
              {
                "id": "a-cp",
                "label": "Control plane pods",
                "sub": "EKS, 6 replicas",
                "kind": "app"
              },
              {
                "id": "a-pr",
                "label": "Prober set a",
                "sub": "DaemonSet",
                "kind": "platform"
              },
              {
                "id": "a-wl",
                "label": "Workloads + sidecars",
                "sub": "~20,000",
                "kind": "app"
              }
            ]
          },
          {
            "title": "AZ b",
            "kind": "boundary",
            "nodes": [
              {
                "id": "b-cp",
                "label": "Control plane pods",
                "sub": "EKS, 6 replicas",
                "kind": "app"
              },
              {
                "id": "b-pr",
                "label": "Prober set b",
                "kind": "platform"
              },
              {
                "id": "b-wl",
                "label": "Workloads + sidecars",
                "kind": "app"
              }
            ]
          },
          {
            "title": "AZ c",
            "kind": "boundary",
            "nodes": [
              {
                "id": "c-cp",
                "label": "Control plane pods",
                "sub": "EKS, 6 replicas",
                "kind": "app"
              },
              {
                "id": "c-pr",
                "label": "Prober set c",
                "kind": "platform"
              },
              {
                "id": "c-wl",
                "label": "Workloads + sidecars",
                "kind": "app"
              }
            ]
          },
          {
            "title": "Regional state",
            "kind": "trust",
            "nodes": [
              {
                "id": "r-reg",
                "label": "Registry",
                "sub": "Aurora, 3-AZ",
                "kind": "store"
              },
              {
                "id": "r-obs",
                "label": "Observed state",
                "sub": "DynamoDB, 7-day TTL",
                "kind": "store"
              },
              {
                "id": "r-log",
                "label": "Transition log",
                "sub": "Kinesis + S3",
                "kind": "store"
              }
            ]
          }
        ]
      },
      {
        "title": "AWS eu-west-1 and ap-south-1 (same shape, independent)",
        "kind": "cloud",
        "dir": "row",
        "children": [
          {
            "title": "Regional control plane",
            "kind": "boundary",
            "nodes": [
              {
                "id": "e-cp",
                "label": "Control plane",
                "sub": "own authority",
                "kind": "app"
              },
              {
                "id": "e-reg",
                "label": "Registry",
                "sub": "own writes",
                "kind": "store"
              }
            ]
          },
          {
            "title": "Cross-region view",
            "kind": "plain",
            "nodes": [
              {
                "id": "e-rep",
                "label": "Async replica of peers",
                "sub": "read-only aggregate",
                "kind": "store"
              }
            ]
          }
        ]
      }
    ],
    "outside": [
      {
        "id": "o-arc",
        "label": "Out-of-band failover signal",
        "sub": "ARC readiness, no registry dependency",
        "kind": "platform"
      },
      {
        "id": "o-dns",
        "label": "Route 53 + Cloud Map",
        "sub": "global DNS surface",
        "kind": "external"
      },
      {
        "id": "o-cat",
        "label": "Service catalogue",
        "kind": "external"
      }
    ],
    "edges": [
      {
        "from": "r-reg",
        "to": "e-rep",
        "label": "async replication",
        "kind": "async"
      },
      {
        "from": "e-reg",
        "to": "e-rep"
      },
      {
        "from": "o-arc",
        "to": "e-cp",
        "label": "region health",
        "kind": "async"
      },
      {
        "from": "r-reg",
        "to": "o-dns",
        "label": "zone sync",
        "kind": "batch"
      }
    ],
    "note": "A region keeps routing with both peers and every global component unreachable. Cross-region resolution is the only thing that degrades.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "17-observability",
    "title": "Observability — Six Signal Families Across Five Stages",
    "layout": "grid",
    "canvas": {
      "width": 1780
    },
    "laneHeaderWidth": 170,
    "columns": [
      "Collection",
      "Evaluation",
      "Propagation",
      "Client",
      "Outcome"
    ],
    "rows": [
      {
        "title": "Freshness",
        "cells": [
          [
            {
              "label": "Sample age p99",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Decision age",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Propagation delay p99",
              "kind": "app"
            }
          ],
          [
            {
              "label": "View staleness",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Convergence lag",
              "kind": "app"
            }
          ]
        ]
      },
      {
        "title": "Correctness",
        "cells": [
          [
            {
              "label": "Unattributed signals",
              "kind": "security"
            }
          ],
          [
            {
              "label": "Unknown-state count",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Version regressions",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Cache-serve ratio",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Black-holed requests",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Stability",
        "cells": [
          [
            {
              "label": "Probe flap rate",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Transitions per instance",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Delta churn volume",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Ejection rate",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Retry rate by endpoint",
              "kind": "app"
            }
          ]
        ]
      },
      {
        "title": "Capacity",
        "cells": [
          [
            {
              "label": "Results per second",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Shard evaluation lag",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Open subscriptions",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Client CPU share",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Eligible fraction",
              "kind": "app"
            }
          ]
        ]
      },
      {
        "title": "Safety",
        "cells": [
          [
            {
              "label": "Prober reachability",
              "kind": "platform"
            }
          ],
          [
            {
              "label": "Fraction-guard trips",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Shed episodes",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Shrink-cap hits",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Static-serving minutes",
              "kind": "platform"
            }
          ]
        ]
      },
      {
        "title": "Governance",
        "cells": [
          [
            {
              "label": "Contract changes staged",
              "kind": "security"
            }
          ],
          [
            {
              "label": "Manual overrides",
              "kind": "security"
            }
          ],
          [],
          [
            {
              "label": "Library version spread",
              "kind": "risk"
            }
          ],
          [
            {
              "label": "Removal-drill results",
              "kind": "platform"
            }
          ]
        ]
      }
    ],
    "note": "Four alarms, not thirty: withdrawal delay past budget, fraction-guard trip, version regression, and static-serving minutes above zero when nothing is declared broken.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "18-instance-lifecycle",
    "title": "Instance Lifecycle — A Loop That Closes",
    "layout": "cycle",
    "canvas": {
      "width": 1560
    },
    "centre": {
      "label": "Instance lifecycle"
    },
    "nodes": [
      {
        "label": "Registered",
        "sub": "identity assigned",
        "kind": "app",
        "id": "registered"
      },
      {
        "label": "Probed",
        "sub": "contract applied",
        "kind": "platform",
        "id": "probed"
      },
      {
        "label": "Ramping",
        "sub": "weight rising 60 s",
        "kind": "integration",
        "id": "ramping"
      },
      {
        "label": "Serving",
        "sub": "full weight",
        "kind": "app",
        "id": "serving"
      },
      {
        "label": "Suspect",
        "sub": "score decaying",
        "kind": "decision",
        "id": "suspect"
      },
      {
        "label": "Withdrawn",
        "sub": "or quarantined",
        "kind": "risk",
        "id": "withdrawn"
      },
      {
        "label": "Draining",
        "sub": "budget checked",
        "kind": "integration",
        "id": "draining"
      },
      {
        "label": "Deregistered",
        "sub": "or lease expired",
        "kind": "external",
        "id": "deregistered"
      }
    ],
    "ringLabels": [
      "first readiness pass",
      "admitted, weight 0.1",
      "ramp complete",
      "failure rate rises",
      "threshold crossed",
      "recovered, re-entry slower",
      "grace period ends",
      "replacement registers"
    ],
    "rx": 470,
    "ry": 215,
    "note": "Withdrawn returns to Draining or to Ramping — never straight to Serving. Re-entry is always the slow direction.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "19-security-trust-zones",
    "title": "Trust Zones — Who May Deny Service To Whom",
    "layout": "zones",
    "canvas": {
      "width": 1740
    },
    "zones": [
      {
        "title": "Untrusted — outside the estate",
        "kind": "trust",
        "nodes": [
          {
            "id": "z-third",
            "label": "Third-party endpoints",
            "sub": "declared, never probed",
            "kind": "external"
          },
          {
            "id": "z-net",
            "label": "Public internet",
            "kind": "external"
          }
        ]
      },
      {
        "title": "Workload zone — authenticated, least privilege",
        "kind": "trust",
        "nodes": [
          {
            "id": "z-wl",
            "label": "Application instance",
            "sub": "may report only itself",
            "kind": "app"
          },
          {
            "id": "z-sc",
            "label": "Envoy sidecar",
            "sub": "reports outcomes it saw",
            "kind": "app"
          },
          {
            "id": "z-pr",
            "label": "Prober",
            "sub": "assigned targets only",
            "kind": "platform"
          }
        ]
      },
      {
        "title": "Control zone — privileged, audited",
        "kind": "trust",
        "nodes": [
          {
            "id": "z-ing",
            "label": "Signal ingest",
            "sub": "attribution enforced",
            "kind": "integration"
          },
          {
            "id": "z-ev",
            "label": "Evaluator",
            "sub": "may deny service",
            "kind": "app"
          },
          {
            "id": "z-pol",
            "label": "Policy API",
            "sub": "staged + budgeted",
            "kind": "integration"
          },
          {
            "id": "z-ovr",
            "label": "Manual override",
            "sub": "rate-limited",
            "kind": "security"
          }
        ]
      },
      {
        "title": "Record zone — write once",
        "kind": "trust",
        "nodes": [
          {
            "id": "z-reg",
            "label": "Registry",
            "sub": "address ownership checked",
            "kind": "store"
          },
          {
            "id": "z-aud",
            "label": "Audit log",
            "sub": "5 years, immutable",
            "kind": "store"
          }
        ]
      }
    ],
    "edges": [
      {
        "from": "z-wl",
        "to": "z-ing",
        "label": "self only"
      },
      {
        "from": "z-sc",
        "to": "z-ing",
        "kind": "async"
      },
      {
        "from": "z-pr",
        "to": "z-ing",
        "label": "assigned only"
      },
      {
        "from": "z-ing",
        "to": "z-ev",
        "label": "attributed"
      },
      {
        "from": "z-ev",
        "to": "z-aud"
      },
      {
        "from": "z-ovr",
        "to": "z-aud",
        "label": "actor + why"
      },
      {
        "from": "z-pol",
        "to": "z-reg",
        "label": "versioned"
      },
      {
        "from": "z-third",
        "to": "z-reg",
        "label": "declared",
        "kind": "batch"
      }
    ],
    "note": "The control the design rests on sits at the ingest boundary: a signal that cannot be attributed to the instance it describes is discarded, and a registered address must be proved to belong to its registrant.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "20-operator-authorisation-flow",
    "title": "Identity Flow — An Override The Platform Is Allowed To Refuse",
    "layout": "sequence",
    "canvas": {
      "width": 1700
    },
    "lifelines": [
      {
        "id": "sre",
        "label": "SRE on call",
        "kind": "actor"
      },
      {
        "id": "cli",
        "label": "Admin client",
        "kind": "app"
      },
      {
        "id": "idp",
        "label": "Workload / human identity",
        "kind": "security"
      },
      {
        "id": "pol",
        "label": "Policy API",
        "kind": "integration"
      },
      {
        "id": "bud",
        "label": "Budget guard",
        "kind": "app"
      },
      {
        "id": "ev",
        "label": "Evaluator",
        "kind": "app"
      },
      {
        "id": "aud",
        "label": "Audit log",
        "kind": "store"
      }
    ],
    "messages": [
      {
        "from": "sre",
        "to": "cli",
        "label": "force instance ineligible",
        "kind": "call"
      },
      {
        "from": "cli",
        "to": "idp",
        "label": "assume break-glass role",
        "kind": "call"
      },
      {
        "from": "idp",
        "to": "cli",
        "label": "scoped, 15 min",
        "kind": "return"
      },
      {
        "from": "cli",
        "to": "pol",
        "label": "override + justification",
        "kind": "call"
      },
      {
        "from": "pol",
        "to": "pol",
        "label": "authz: may deny this service?",
        "kind": "self"
      },
      {
        "from": "pol",
        "to": "bud",
        "label": "check disruption budget",
        "kind": "call"
      },
      {
        "from": "bud",
        "to": "pol",
        "label": "refused: floor is 50%",
        "kind": "error"
      },
      {
        "from": "pol",
        "to": "aud",
        "label": "attempt, actor, refusal",
        "kind": "async"
      },
      {
        "from": "pol",
        "to": "cli",
        "label": "429 + the floor it hit",
        "kind": "error"
      },
      {
        "from": "sre",
        "to": "cli",
        "label": "evacuate the zone instead",
        "kind": "call"
      },
      {
        "from": "cli",
        "to": "pol",
        "label": "declared evacuation",
        "kind": "call"
      },
      {
        "from": "pol",
        "to": "ev",
        "label": "shift topology preference",
        "kind": "call"
      },
      {
        "from": "ev",
        "to": "aud",
        "label": "policy change recorded",
        "kind": "async"
      },
      {
        "from": "pol",
        "to": "cli",
        "label": "accepted, reversible in one step",
        "kind": "return"
      }
    ],
    "note": "The refusal is the control. An operator who can always remove capacity is a denial-of-service path with a badge.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  },
  {
    "id": "21-failure-classes",
    "title": "Twelve Failure Classes — What Catches Each, And What It Costs",
    "layout": "grid",
    "canvas": {
      "width": 1780
    },
    "laneHeaderWidth": 215,
    "columns": [
      "Caught by",
      "Bounded by",
      "Worst case if the bound fails"
    ],
    "rows": [
      {
        "title": "Instance dead",
        "cells": [
          [
            {
              "label": "Probe + lease expiry",
              "kind": "platform"
            }
          ],
          [
            {
              "label": "10 s p99 detection",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Black-holed requests",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Instance slow, not dead",
        "cells": [
          [
            {
              "label": "Passive outcomes",
              "kind": "integration"
            }
          ],
          [
            {
              "label": "Weight cut, local ejection",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Grey failure stays in rotation",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Observation path failed",
        "cells": [
          [
            {
              "label": "Second signal class",
              "kind": "integration"
            }
          ],
          [
            {
              "label": "Unknown state",
              "kind": "decision"
            }
          ],
          [
            {
              "label": "Healthy fleet drained",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Control plane unavailable",
        "cells": [
          [
            {
              "label": "Client cache age",
              "kind": "app"
            }
          ],
          [
            {
              "label": "60 min static serving",
              "kind": "store"
            }
          ],
          [
            {
              "label": "Routing on hour-old truth",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Stale client view",
        "cells": [
          [
            {
              "label": "Connection failure",
              "kind": "app"
            }
          ],
          [
            {
              "label": "5 s withdrawal budget",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Requests to a dead address",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Correlated mass withdrawal",
        "cells": [
          [
            {
              "label": "Eligible fraction",
              "kind": "app"
            }
          ],
          [
            {
              "label": "50% guard disregards health",
              "kind": "decision"
            }
          ],
          [
            {
              "label": "Service at zero capacity",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Flapping",
        "cells": [
          [
            {
              "label": "Transition count",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Hysteresis + quarantine",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Every client's view churns",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Thundering herd on recovery",
        "cells": [
          [
            {
              "label": "Reconnect rate",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Slow start, 5% per 10 s",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Recovered target re-killed",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Registration leak",
        "cells": [
          [
            {
              "label": "Reconciliation diff",
              "kind": "app"
            }
          ],
          [
            {
              "label": "30 s lease expiry",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Zombie endpoints served",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Cross-region split-brain",
        "cells": [
          [
            {
              "label": "Replication lag + ARC",
              "kind": "platform"
            }
          ],
          [
            {
              "label": "Each region serves its own view",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Both regions declare the other dead",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Poisoned health signal",
        "cells": [
          [
            {
              "label": "Attribution at ingest",
              "kind": "security"
            }
          ],
          [
            {
              "label": "Passive signal cannot be forged",
              "kind": "security"
            }
          ],
          [
            {
              "label": "One workload denies another",
              "kind": "risk"
            }
          ]
        ]
      },
      {
        "title": "Policy error",
        "cells": [
          [
            {
              "label": "Staged rollout diff",
              "kind": "security"
            }
          ],
          [
            {
              "label": "Budget + one-step reversal",
              "kind": "app"
            }
          ],
          [
            {
              "label": "Wrong region evacuated",
              "kind": "risk"
            }
          ]
        ]
      }
    ],
    "note": "Not one recovery in this table is a code change. Every bound is a number in the requirement, which is what makes the table checkable.",
    "meta": {
      "v": "1.0",
      "owner": "Reliability Architecture"
    }
  }
]
