Internal Developer Platform · View 09 of 21 · Structure
Decisions
- The API is primary; the portal and the CLI are clients of it. A capability reachable only through the portal cannot be scripted, audited or replaced, so it is defined as a defect (ADR-12).
- The platform API is versioned with a published deprecation window, because its consumers include 140 teams' pipelines.
- Git is the only integration the platform both drives and is driven by, which is a direct consequence of intent living in the repository (ADR-01).
Assumptions
- Team pipelines authenticate by OIDC federation with no static credential (ADR-15).
- Audit evidence is exported rather than queried live by the risk function.
Omitted
- Key Vault, Azure Monitor and Cost Management: the platform grants to or exports from them rather than driving them.
- Two edge labels on this view sit close enough to touch. That is the hub layout's fan geometry, not a routing error; the alternative was a shorter label that said less.