Distributed Job Scheduler · View 18 of 20 · Assurance
Decisions
- Target ownership is verified at definition time and again at dispatch time. Without that, a schedule is a server-side request-forgery primitive with a built-in timer and a retry budget (ADR-14).
- No tenant request reaches the fire zone. The timing and dispatch planes are reachable only from inside the perimeter (ADR-14).
- Backfill, horizon extension and quota change are separate grants from authorship, because each converts a scheduling mistake into multiplied real work (ADR-15).
Assumptions
- Dispatch credentials are minted per attempt with a lifetime no longer than the attempt timeout, so a captured dispatch buys one trigger for one timeout.
- Outcome callbacks are signed and replay-resistant within a short window; a stale signature is rejected rather than logged.
Risks
- Domain verification is a point-in-time check. A target that is legitimately owned at definition time and later reassigned is the residual, mitigated by re-verification at dispatch and nothing stronger.