[{"data":1,"prerenderedAt":577},["ShallowReactive",2],{"navigation":3,"\u002Farchitecture\u002Fcontrol-plane":250,"\u002Farchitecture\u002Fcontrol-plane-surround":572},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":40,"body":252,"description":565,"extension":566,"links":567,"meta":568,"navigation":569,"path":41,"seo":570,"stem":42,"__hash__":571},"docs\u002F2.architecture\u002F3.control-plane.md",{"type":253,"value":254,"toc":549},"minimark",[255,271,276,283,286,289,314,317,321,332,335,346,350,355,358,387,394,398,401,421,424,428,431,457,460,464,467,470,474,476,499,502,506,509,529,532,535,539],[256,257,258],"note",{},[259,260,261,265,266,270],"p",{},[262,263,264],"strong",{},"v1 design baseline."," This page specifies intended behavior. Delivery and validation are tracked in the ",[267,268,269],"a",{"href":171},"implementation plan","; it is not a claim that the platform is already implemented.",[272,273,275],"h2",{"id":274},"architectural-style","Architectural style",[259,277,278,279,282],{},"Use a ",[262,280,281],{},"modular Laravel monolith",", not premature microservices.",[259,284,285],{},"Laravel owns orchestration, state transitions, authorization, the API, Filament, MCP operations, audit recording, and workflow decisions.",[259,287,288],{},"Separate processes are justified only where the trust boundary or runtime requirements differ:",[290,291,292,296,299,302,305,308,311],"ul",{},[293,294,295],"li",{},"Public app gateway",[293,297,298],{},"Runtime agent",[293,300,301],{},"Sandbox runner",[293,303,304],{},"SQLite binding service",[293,306,307],{},"KV binding service",[293,309,310],{},"Egress proxy",[293,312,313],{},"Telemetry collector",[259,315,316],{},"This keeps the business model and authorization logic cohesive while isolating security-sensitive execution code.",[272,318,320],{"id":319},"control-plane-modules","Control-plane modules",[322,323,329],"pre",{"className":324,"code":326,"language":327,"meta":328},[325],"language-text","Organizations\nIdentity\nAuthorization\nApplications\nSource\nChange Sets\nBuilds\nArtifacts\nDeployments\nRuntime Clusters\nData\nCapabilities\nPolicies\nApprovals\nSecrets and Integrations\nAudit\nUsage and Quotas\nBilling\nNotifications\nMCP\nDeveloper Integrations\n","text","",[330,331,326],"code",{"__ignoreMap":328},[259,333,334],{},"Each module exposes application-level commands and queries. Filament, REST, MCP, and a future CLI call those same application services.",[259,336,337,338,341,342,345],{},"There must not be separate implementations of ",[330,339,340],{},"CreateApp"," or ",[330,343,344],{},"RequestDeployment"," for each interface.",[272,347,349],{"id":348},"core-infrastructure","Core infrastructure",[351,352,354],"h3",{"id":353},"postgresql","PostgreSQL",[259,356,357],{},"Authoritative system of record for:",[290,359,360,363,366,369,372,375,378,381,384],{},[293,361,362],{},"Organizations and memberships",[293,364,365],{},"IdP configuration",[293,367,368],{},"Apps and environments",[293,370,371],{},"Source metadata",[293,373,374],{},"Builds and deployments",[293,376,377],{},"Policy and approval state",[293,379,380],{},"Runtime desired state",[293,382,383],{},"Audit metadata",[293,385,386],{},"Quotas and usage summaries",[259,388,389,390,393],{},"Application business data does ",[262,391,392],{},"not"," live in this database.",[351,395,397],{"id":396},"valkey","Valkey",[259,399,400],{},"Used for:",[290,402,403,406,409,412,415,418],{},[293,404,405],{},"Laravel queues",[293,407,408],{},"Short-lived caches",[293,410,411],{},"Distributed locks",[293,413,414],{},"Rate-limit counters",[293,416,417],{},"Session\u002Fcache material where appropriate",[293,419,420],{},"Command dispatch acceleration",[259,422,423],{},"PostgreSQL remains authoritative for state transitions.",[351,425,427],{"id":426},"object-storage","Object storage",[259,429,430],{},"S3-compatible object storage holds:",[290,432,433,436,439,442,445,448,451,454],{},[293,434,435],{},"Content-addressed build artifacts",[293,437,438],{},"Static assets",[293,440,441],{},"SBOMs",[293,443,444],{},"Scanner reports",[293,446,447],{},"Export packages",[293,449,450],{},"Encrypted database snapshots",[293,452,453],{},"Archived logs",[293,455,456],{},"Source bundles where necessary",[259,458,459],{},"Artifacts are immutable and addressed by digest.",[351,461,463],{"id":462},"forgejo","Forgejo",[259,465,466],{},"Hidden source-control backend for managed applications.",[259,468,469],{},"Forgejo is not the source of truth for intrnl authorization. The control plane owns membership, app ownership, and permission decisions.",[351,471,473],{"id":472},"kmssecrets-system","KMS\u002Fsecrets system",[259,475,400],{},[290,477,478,481,484,487,490,493,496],{},[293,479,480],{},"Encryption-envelope keys",[293,482,483],{},"Signing keys",[293,485,486],{},"OIDC client secrets",[293,488,489],{},"GitHub App private keys",[293,491,492],{},"Runtime cluster certificates",[293,494,495],{},"Integration credentials",[293,497,498],{},"Raw application secrets where unavoidable",[259,500,501],{},"Customer secrets are encrypted with per-organization or per-integration data keys wrapped by the platform key hierarchy.",[272,503,505],{"id":504},"reliable-orchestration","Reliable orchestration",[259,507,508],{},"Use:",[290,510,511,514,517,520,523,526],{},[293,512,513],{},"Transactional outbox",[293,515,516],{},"Idempotent command handlers",[293,518,519],{},"Runtime command acknowledgements",[293,521,522],{},"Reconciliation loops",[293,524,525],{},"Optimistic version columns",[293,527,528],{},"Idempotency keys on mutating public APIs",[259,530,531],{},"A deployment request should be persisted atomically with its outbox event. Failure to dispatch immediately must not lose the operation.",[259,533,534],{},"Runtime clusters periodically reconcile their actual workloads against the desired state held by the control plane. This prevents a temporary queue or network failure from leaving the cluster permanently inconsistent.",[272,536,538],{"id":537},"related-documentation","Related documentation",[290,540,541,545],{},[293,542,543],{},[267,544,48],{"href":49},[293,546,547],{},[267,548,114],{"href":115},{"title":328,"searchDepth":550,"depth":551,"links":552},1,2,[553,554,555,563,564],{"id":274,"depth":551,"text":275},{"id":319,"depth":551,"text":320},{"id":348,"depth":551,"text":349,"children":556},[557,559,560,561,562],{"id":353,"depth":558,"text":354},3,{"id":396,"depth":558,"text":397},{"id":426,"depth":558,"text":427},{"id":462,"depth":558,"text":463},{"id":472,"depth":558,"text":473},{"id":504,"depth":551,"text":505},{"id":537,"depth":551,"text":538},"Laravel modules, authoritative stores, secrets infrastructure, and reliable orchestration.","md",null,{},true,{"title":40,"description":565},"vaQcAlZSGk-o5zumU3_Mkk-egzNO6k6Ai2rHwAgr7Ww",[573,575],{"title":36,"path":37,"stem":38,"description":574,"children":-1},"Security responsibilities of management, builds, runtimes, bindings, and external AI clients.",{"title":44,"path":45,"stem":46,"description":576,"children":-1},"Tenant context, authorization, row-level security, immutable identifiers, and tenant isolation.",1790019415367]