[{"data":1,"prerenderedAt":526},["ShallowReactive",2],{"navigation":3,"\u002Farchitecture\u002Ftrust-zones":250,"\u002Farchitecture\u002Ftrust-zones-surround":521},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":36,"body":252,"description":514,"extension":515,"links":516,"meta":517,"navigation":518,"path":37,"seo":519,"stem":38,"__hash__":520},"docs\u002F2.architecture\u002F2.trust-zones.md",{"type":253,"value":254,"toc":505},"minimark",[255,271,276,279,310,313,317,320,323,340,347,367,371,374,391,395,398,401,456,459,467,471,474,477,481,484,487,491,501],[256,257,258],"note",{},[259,260,261,265,266,270],"p",{},[262,263,264],"strong",{},"v1 design baseline."," This page specifies intended behavior. Delivery and validation are tracked in the ",[267,268,269],"a",{"href":171},"implementation plan","; it is not a claim that the platform is already implemented.",[272,273,275],"h2",{"id":274},"management-plane","Management plane",[259,277,278],{},"Trusted intrnl services:",[280,281,282,286,289,292,295,298,301,304,307],"ul",{},[283,284,285],"li",{},"Laravel\u002FFilament control plane",[283,287,288],{},"Identity broker",[283,290,291],{},"MCP authorization layer",[283,293,294],{},"Orchestrator",[283,296,297],{},"PostgreSQL metadata database",[283,299,300],{},"Forgejo",[283,302,303],{},"Artifact registry\u002Fobject store",[283,305,306],{},"Key management and secrets",[283,308,309],{},"Audit service",[259,311,312],{},"Customer application code must never execute here.",[272,314,316],{"id":315},"build-plane","Build plane",[259,318,319],{},"Assume source code, package manifests, dependencies, build scripts, and post-install scripts are malicious.",[259,321,322],{},"The build plane receives only:",[280,324,325,328,331,334,337],{},[283,326,327],{},"An immutable source revision",[283,329,330],{},"A supported builder image",[283,332,333],{},"Read-only package access",[283,335,336],{},"A short-lived artifact upload credential",[283,338,339],{},"Build-specific metadata",[259,341,342,343,346],{},"It does ",[262,344,345],{},"not"," receive:",[280,348,349,352,355,358,361,364],{},[283,350,351],{},"Production database access",[283,353,354],{},"Production secrets",[283,356,357],{},"Runtime service credentials",[283,359,360],{},"Control-plane database access",[283,362,363],{},"Cluster administrator credentials",[283,365,366],{},"Credentials belonging to another organization",[272,368,370],{"id":369},"runtime-plane","Runtime plane",[259,372,373],{},"Assume deployed application code can be buggy, intentionally malicious, or compromised.",[259,375,376,377,381,382,384,385],{},"Each application environment executes inside its own OS-level sandbox in v1. ",[378,379,380],"code",{},"workerd"," remains the application runtime but not the security boundary. Cloudflare’s own ",[378,383,380],{}," documentation explicitly warns that it is not, by itself, a hardened sandbox for potentially malicious code and should be placed inside an appropriate secure sandbox such as a VM. ",[267,386,390],{"href":387,"rel":388},"https:\u002F\u002Fgithub.com\u002Fcloudflare\u002Fworkerd#security",[389],"nofollow","workerd security model",[272,392,394],{"id":393},"bindingdata-services","Binding\u002Fdata services",[259,396,397],{},"The database, KV, secret\u002Fintegration, and egress services are trusted brokers.",[259,399,400],{},"An application receives a logical capability such as:",[402,403,408],"pre",{"className":404,"code":405,"language":406,"meta":407,"style":407},"language-ts shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","env.DB\nenv.KV\nenv.AUTH\nenv.INTEGRATIONS\n","ts","",[378,409,410,426,436,446],{"__ignoreMap":407},[411,412,415,419,423],"span",{"class":413,"line":414},"line",1,[411,416,418],{"class":417},"sTEyZ","env",[411,420,422],{"class":421},"sMK4o",".",[411,424,425],{"class":417},"DB\n",[411,427,429,431,433],{"class":413,"line":428},2,[411,430,418],{"class":417},[411,432,422],{"class":421},[411,434,435],{"class":417},"KV\n",[411,437,439,441,443],{"class":413,"line":438},3,[411,440,418],{"class":417},[411,442,422],{"class":421},[411,444,445],{"class":417},"AUTH\n",[411,447,449,451,453],{"class":413,"line":448},4,[411,450,418],{"class":417},[411,452,422],{"class":421},[411,454,455],{"class":417},"INTEGRATIONS\n",[259,457,458],{},"It does not receive:",[402,460,465],{"className":461,"code":463,"language":464,"meta":407},[462],"language-text","a filesystem path to its SQLite file\na raw Valkey password\na shared database connection string\na control-plane token\na customer network credential\n","text",[378,466,463],{"__ignoreMap":407},[272,468,470],{"id":469},"external-ai-vendors","External AI vendors",[259,472,473],{},"Claude, ChatGPT, and Codex are external systems.",[259,475,476],{},"They are authenticated clients of intrnl, not trusted infrastructure components. Every tool invocation is reauthorized by intrnl regardless of what the model says the user intended.",[272,478,480],{"id":479},"future-customer-network-integrations","Future customer network integrations",[259,482,483],{},"Enterprise resource planning systems, internal APIs, reporting databases, or private networks sit behind explicit integration boundaries.",[259,485,486],{},"No application gets ambient access to the organization’s internal network.",[272,488,490],{"id":489},"related-documentation","Related documentation",[280,492,493,497],{},[283,494,495],{},[267,496,87],{"href":88},[283,498,499],{},[267,500,106],{"href":107},[502,503,504],"style",{},"html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":407,"searchDepth":414,"depth":428,"links":506},[507,508,509,510,511,512,513],{"id":274,"depth":428,"text":275},{"id":315,"depth":428,"text":316},{"id":369,"depth":428,"text":370},{"id":393,"depth":428,"text":394},{"id":469,"depth":428,"text":470},{"id":479,"depth":428,"text":480},{"id":489,"depth":428,"text":490},"Security responsibilities of management, builds, runtimes, bindings, and external AI clients.","md",null,{},true,{"title":36,"description":514},"IhtdnkN8vzkFAjWlN4h9M-Ffobw5UUnok0_Pd3UPpW4",[522,524],{"title":34,"path":30,"stem":31,"description":523,"children":-1},"The central control plane, dedicated runtime clusters, and the boundaries between them.",{"title":40,"path":41,"stem":42,"description":525,"children":-1},"Laravel modules, authoritative stores, secrets infrastructure, and reliable orchestration.",1790019415367]