SLO and Error Budget Service · View 13 of 21 · Runtime
Decisions
- The platform never tells the gate to stop. It returns a signed, typed claim and the gate applies its own declared policy, which keeps the reliability authority off the critical path of everything it governs (ADR-12).
- Two self-checks run before anything is signed: is the projection stale beyond the ceiling, and is coverage below the floor. Either turns the answer into insufficient-data rather than a figure (ADR-04).
- The error message is drawn deliberately: the unreachable case is part of the contract, answered by the gate failing static on its cached verdict with a declared staleness ceiling (ADR-13).
Targets
- Verdict API p99 ≤ 150 ms in-region, ≤ 400 ms cross-region, at 2,000 rps burst for 120 s — assumed.
- Verdict API availability ≥ 99.95% monthly, measured as successful responses over valid requests per minute — assumed.
- Signature verification at the gate, so a cached verdict cannot be forged during an outage of this platform.
Risks
- Fail-static weakens the policy with age. A gate running on an eight-hour-old verdict is enforcing history, and no staleness ceiling is obviously correct (ADR-13).
- The HSM is on the synchronous path. Signing latency and HSM availability are inside the verdict API's own budget, which is why signatures are short-lived rather than per-request-unique.