No-Code SaaS Automation Platform  ·  View 16 of 21  ·  Operations

Delivery and Connector Release

Two things ship on this pipeline — our code and other people's connectors — and only one of them we wrote.

Editable source SVG draw.io All views
Source Platform code Git Connector manifests declarative Build Container image signed Manifest lint schemas resolvable Gates Contract tests provider sandbox Replay class declared blocks publish Sandbox policy scan Environments Staging provider sandboxes Production canary 1% of runs Catalogue Version published immutable Deprecation notice per-workspace impact reject supersedes Delivery — Platform Code and Connector Versions Application we own Decision point Data store Security / platform failure / alternate event / async An action cannot be published without its replay-safety class, because every execution guarantee downstream is derived from it. v 1.0 · owner Integration Platform Architecture · date 2026-10

Decisions

  • 'Replay class declared' is a hard release gate that rejects the manifest. Every execution guarantee in views 12 and 14 is derived from that field, so an unclassified action would silently degrade the platform's correctness promise.
  • Contract tests run against provider sandboxes rather than mocks, because the failure being guarded against is the provider's response shape changing, which a mock cannot notice.
  • Deprecation is a notice with per-workspace impact, not a date in a changelog: the affected authors are knowable from the definition registry and must be told.

Assumptions

  • A deprecated connector version stays executable until its end-of-life date, plus 90 days of retention after.
  • Production canary at 1% of runs, which for a rarely-firing long tail means a canary is measured in hours, not minutes.

Risks

  • The connector developer's incentive is to ship, and the replay class is self-declared. A wrong declaration is indistinguishable from a correct one until an effect is duplicated in a customer's system.