Distributed Job Scheduler · View 08 of 20 · Structure
Decisions
- Authorship, history and privilege are three APIs rather than one, because they need three different authorisation stories (ADR-15).
- The outcome callback is an inbound integration with its own verifier, not a trusted internal path: anything a tenant's executor can send is untrusted (ADR-14).
- Declarative apply (CLI and IaC) is a first-class surface, because a schedule that exists only in a console is a schedule nobody can review.
Assumptions
- Four target classes cover the estate: tenant HTTP, tenant queue, platform executor, and the no-op case where the fire is only recorded.
Deliberate omissions
- The audit and billing exports are omitted here and appear in views 10 and 16.