Search Indexing Service  ·  View 19 of 21  ·  Assurance

Security Trust Zones

Six zones, and four privileges that are deliberately not the same privilege.

Editable source SVG draw.io All views
Internet Consumer app Merchant console Admin console Edge WAF + CloudFront API Gateway authn, quotas Query zone — read only Query Service Mandatory ACL Filter from identity, pre-retrieval Cost Ceiling Write zone — no caller reaches it Capture Tier Assembly Workers Index Writers Control zone — the swap privilege Definition API change a definition Alias Swap changes what everyone sees Audit Log Object Lock Data zone OpenSearch indices Definition Registry KMS tenant keys TLS signed token filtered read admin role separate grant actor + reason internal Security — Trust Zones and What Crosses Them External / third party Security / platform Interface / broker Application we own Risk / gap Data store synchronous failure / alternate event / async Four privileges, deliberately split: query, write a source, change a definition, move an alias. Only the last changes what 40 M people see in one call. v 1.0 · owner Data Platform Architecture

Decisions

  • Query, write a source, change a definition, and move an alias are four separate grants. Only the last changes what 40 million people see, in one call, with no deploy.
  • No caller reaches the write zone. Changes arrive through capture or the push API; nothing in the query path can write a document.
  • Document-level access constraints are indexed fields applied as a mandatory pre-retrieval filter derived from the caller's identity — never a request parameter a caller could omit.
  • Every definition change, promotion, swap, rollback and quarantine release is written to an append-only audit store with the actor and the reason.

Assumptions

  • Tenant-scoped keys where residency or deletion obligations require them; deletion propagates to retained index versions and snapshots within a declared deadline, provably.

Risks

  • The alias swap is the highest-value privilege in the package and the easiest to under-protect, because it looks like an operations action rather than a release.