Streaming Video Encoding & Packaging Pipeline · View 20 of 22 · Assurance
The fleet is untrusted
- The assumed attack is a container escape through a codec parser handling a malformed or malicious master, not a request to the API.
- So workers decode inside a sandbox with no egress, read one master prefix and write one rendition prefix, and hold a short-lived workload identity that grants nothing else.
- That is also why an unreleased master is the highest-sensitivity asset in the system: per-object read auditing, alertable bulk reads, CMEK, and per-rights-holder key separation where a contract requires it.
One invariant with no exception
- No fallback may weaken protection. Degrade quality, degrade latency, degrade the rung set — never encryption. A key service outage stalls publication and that is the whole of the handling.
Known clutter and omissions
- Two intra-zone writes are omitted: sandbox to chunk scratch, and the gate to the pre-release origin.
- Two label-position warnings survive from the route check on this view; both labels name a zone crossing and are worth more than the overlap costs.