[{"data":1,"prerenderedAt":706},["ShallowReactive",2],{"navigation":3,"\u002Fdelivery\u002Fdata-recovery":250,"\u002Fdelivery\u002Fdata-recovery-surround":701},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":132,"body":252,"description":694,"extension":695,"links":696,"meta":697,"navigation":698,"path":133,"seo":699,"stem":134,"__hash__":700},"docs\u002F5.delivery\u002F3.data-recovery.md",{"type":253,"value":254,"toc":668},"minimark",[255,271,276,279,290,293,299,302,308,311,315,318,346,349,352,356,359,365,368,374,377,381,386,392,396,402,406,409,412,415,426,430,436,439,443,446,452,455,459,462,466,472,475,479,485,488,491,495,498,504,513,516,536,540,543,549,553,556,570,573,579,582,586,589,606,609,613,616,636,639,642,645,649,652,656],[256,257,258],"note",{},[259,260,261,265,266,270],"p",{},[262,263,264],"strong",{},"v1 design baseline."," This page specifies intended behavior. Delivery and validation are tracked in the ",[267,268,269],"a",{"href":171},"implementation plan","; it is not a claim that the platform is already implemented.",[272,273,275],"h2",{"id":274},"database-per-app-environment","Database per app environment",[259,277,278],{},"Logical model:",[280,281,287],"pre",{"className":282,"code":284,"language":285,"meta":286},[283],"language-text","Application\n├── production SQLite DB\n├── preview chg_123 SQLite DB\n└── preview chg_456 SQLite DB\n","text","",[288,289,284],"code",{"__ignoreMap":286},[259,291,292],{},"Never:",[280,294,297],{"className":295,"code":296,"language":285,"meta":286},[283],"one giant shared SQLite database for all apps\n",[288,298,296],{"__ignoreMap":286},[259,300,301],{},"The DB binding service maps:",[280,303,306],{"className":304,"code":305,"language":285,"meta":286},[283],"organization + application + environment\n→ authorized SQLite instance\n",[288,307,305],{"__ignoreMap":286},[259,309,310],{},"The application never learns the filesystem location.",[272,312,314],{"id":313},"physical-database-service","Physical database service",[259,316,317],{},"Each active SQLite database has:",[319,320,321,325,328,331,334,337,340,343],"ul",{},[322,323,324],"li",{},"Encrypted persistent storage",[322,326,327],{},"WAL mode where appropriate",[322,329,330],{},"Controlled connection pool",[322,332,333],{},"Serialized\u002Fmanaged write behavior",[322,335,336],{},"Resource limits",[322,338,339],{},"Migration lock",[322,341,342],{},"Backup\u002Fsnapshot integration",[322,344,345],{},"Metrics and corruption checks",[259,347,348],{},"Avoid running SQLite over a generic shared network filesystem.",[259,350,351],{},"Runtime replicas call the DB binding service over authenticated internal RPC.",[272,353,355],{"id":354},"migration-files","Migration files",[259,357,358],{},"Repository convention:",[280,360,363],{"className":361,"code":362,"language":285,"meta":286},[283],"database\u002F\n├── migrations\u002F\n│   ├── 0001_create_requests.sql\n│   ├── 0002_add_department.sql\n│   └── 0003_add_approval.sql\n└── seed.ts\n",[288,364,362],{"__ignoreMap":286},[259,366,367],{},"The platform stores:",[280,369,372],{"className":370,"code":371,"language":285,"meta":286},[283],"migration name\nchecksum\nsource revision\nclassification\napplied environment\napplied time\ndeployment\nresult\n",[288,373,371],{"__ignoreMap":286},[259,375,376],{},"An immutable migration that has run in production cannot be edited in place. A changed checksum fails the build\u002Fdeployment.",[272,378,380],{"id":379},"migration-classifications","Migration classifications",[382,383,385],"h3",{"id":384},"additivelow-risk","Additive\u002Flow risk",[280,387,390],{"className":388,"code":389,"language":285,"meta":286},[283],"CREATE TABLE\nCREATE INDEX\nADD COLUMN with safe defaults\u002Fnullable semantics\n",[288,391,389],{"__ignoreMap":286},[382,393,395],{"id":394},"potentially-destructive","Potentially destructive",[280,397,400],{"className":398,"code":399,"language":285,"meta":286},[283],"DROP TABLE\nDROP COLUMN\nrename\u002Frebuild\nconstraint tightening\ntype narrowing\nlarge data rewrite\n",[288,401,399],{"__ignoreMap":286},[382,403,405],{"id":404},"unclassifiable","Unclassifiable",[259,407,408],{},"Anything the migration parser cannot confidently categorize.",[259,410,411],{},"Unclassifiable production migrations are treated as potentially destructive.",[259,413,414],{},"For the pilot organization:",[319,416,417,420,423],{},[322,418,419],{},"All production migrations require deployment approval during the pilot.",[322,421,422],{},"Destructive migrations always require an authorized human.",[322,424,425],{},"Regulated migrations eventually require stronger separation of duties.",[272,427,429],{"id":428},"deployment-migration-flow","Deployment migration flow",[280,431,434],{"className":432,"code":433,"language":285,"meta":286},[283],"1. Build succeeds\n2. Run migrations against preview DB\n3. Run tests\u002Fhealth checks\n4. Analyze\u002Fclassify migrations\n5. Obtain required approval\n6. Acquire production migration lock\n7. Create pre-migration snapshot\n8. Apply unapplied migrations\n9. Verify checksums and schema\n10. Start new runtime revision\n11. Run health check\n12. Switch production route\n13. Retain old revision and snapshot\n",[288,435,433],{"__ignoreMap":286},[259,437,438],{},"If a migration fails, the existing production runtime remains active wherever schema compatibility permits.",[272,440,442],{"id":441},"backward-compatible-migrations","Backward-compatible migrations",[259,444,445],{},"Templates and AI guidance should favor expand-and-contract:",[280,447,450],{"className":448,"code":449,"language":285,"meta":286},[283],"Deployment 1:\nadd new column, support old and new\n\nDeployment 2:\nbackfill and switch behavior\n\nDeployment 3:\nremove old column after rollback window\n",[288,451,449],{"__ignoreMap":286},[259,453,454],{},"This preserves the ability to roll code back without immediately restoring data.",[272,456,458],{"id":457},"code-rollback-versus-data-restore","Code rollback versus data restore",[259,460,461],{},"These are separate operations.",[382,463,465],{"id":464},"code-rollback","Code rollback",[280,467,470],{"className":468,"code":469,"language":285,"meta":286},[283],"active artifact B\n→ active artifact A\n",[288,471,469],{"__ignoreMap":286},[259,473,474],{},"Fast, normally nondestructive.",[382,476,478],{"id":477},"database-restore","Database restore",[280,480,483],{"className":481,"code":482,"language":285,"meta":286},[283],"current DB\n→ selected snapshot\n",[288,484,482],{"__ignoreMap":286},[259,486,487],{},"Potentially destroys legitimate records created after the snapshot.",[259,489,490],{},"The UI must never present these as a single ambiguous “Rollback” action.",[272,492,494],{"id":493},"backup-design","Backup design",[259,496,497],{},"Pilot defaults, configurable by contract:",[280,499,502],{"className":500,"code":501,"language":285,"meta":286},[283],"Online recovery points: frequent, target 15-minute RPO\nDaily backups: 30 days\nMonthly backups: 12 months\nPre-migration snapshots: retained at least 30 days\nDeleted-app recovery: 30 days\n",[288,503,501],{"__ignoreMap":286},[259,505,506,507],{},"Use SQLite’s Online Backup API or a validated equivalent to obtain live snapshots. SQLite documents that the backup can run incrementally while other users continue and produces a destination representing a snapshot of the source. ",[267,508,512],{"href":509,"rel":510},"https:\u002F\u002Fwww.sqlite.org\u002Fbackup.html",[511],"nofollow","SQLite Online Backup API",[259,514,515],{},"Backups must be:",[319,517,518,521,524,527,530,533],{},[322,519,520],{},"Encrypted",[322,522,523],{},"Stored off the primary runtime volume",[322,525,526],{},"Integrity-checked",[322,528,529],{},"Associated with app\u002Fenvironment",[322,531,532],{},"Periodically restored in automated and manual drills",[322,534,535],{},"Subject to organization retention\u002Fpurge policy",[272,537,539],{"id":538},"safe-restore-workflow","Safe restore workflow",[259,541,542],{},"Do not overwrite the live DB immediately.",[280,544,547],{"className":545,"code":546,"language":285,"meta":286},[283],"1. Select recovery point\n2. Restore to a new database instance\n3. Run integrity check\n4. Start isolated validation environment\n5. Review\u002Fapprove\n6. Quiesce writes if required\n7. Atomically switch DB binding\n8. Retain old DB for a defined window\n9. Audit operation\n",[288,548,546],{"__ignoreMap":286},[272,550,552],{"id":551},"preview-data","Preview data",[259,554,555],{},"Default preview data:",[319,557,558,561,564,567],{},[322,559,560],{},"Empty schema plus migrations",[322,562,563],{},"Synthetic seed records",[322,565,566],{},"Test identities",[322,568,569],{},"No production copy",[259,571,572],{},"Optional future modes:",[280,574,577],{"className":575,"code":576,"language":285,"meta":286},[283],"schema only\napproved synthetic fixture set\napproved de-identified snapshot\n",[288,578,576],{"__ignoreMap":286},[259,580,581],{},"Production data cloning is never the default.",[272,583,585],{"id":584},"export-and-portability","Export and portability",[259,587,588],{},"Organization admins can export:",[319,590,591,594,597,600,603],{},[322,592,593],{},"Native SQLite database",[322,595,596],{},"SQL dump where practical",[322,598,599],{},"CSV by table",[322,601,602],{},"Migration history",[322,604,605],{},"Schema manifest",[259,607,608],{},"Source and data remain portable if an organization leaves intrnl.",[272,610,612],{"id":611},"kv","KV",[259,614,615],{},"KV is intended for:",[319,617,618,621,624,627,630,633],{},[322,619,620],{},"Cache",[322,622,623],{},"Session-like app state",[322,625,626],{},"Feature flags",[322,628,629],{},"Ephemeral coordination",[322,631,632],{},"Temporary counters",[322,634,635],{},"Short-lived data",[259,637,638],{},"Authoritative workflow records belong in DB.",[259,640,641],{},"Each app environment gets a logical KV namespace through the binding proxy. The app never receives raw Valkey credentials.",[259,643,644],{},"KV backup\u002Frecovery guarantees are weaker than database guarantees unless a future durable KV tier explicitly defines otherwise.",[272,646,648],{"id":647},"migration-failure-boundary","Migration failure boundary",[259,650,651],{},"Keeping the old runtime active does not undo schema changes. The migration runner must prevent incompatible or partially applied schema changes from silently leaving that runtime broken. Phase 5 acceptance must exercise migration failures and schema compatibility explicitly. If compatibility cannot be maintained, stop activation and follow approved recovery procedures; route stability alone does not guarantee uninterrupted service.",[272,653,655],{"id":654},"related-documentation","Related documentation",[319,657,658,663],{},[322,659,660],{},[267,661,662],{"href":155},"Backup and restore runbook",[322,664,665],{},[267,666,667],{"href":151},"Deployment runbook",{"title":286,"searchDepth":669,"depth":670,"links":671},1,2,[672,673,674,675,681,682,683,687,688,689,690,691,692,693],{"id":274,"depth":670,"text":275},{"id":313,"depth":670,"text":314},{"id":354,"depth":670,"text":355},{"id":379,"depth":670,"text":380,"children":676},[677,679,680],{"id":384,"depth":678,"text":385},3,{"id":394,"depth":678,"text":395},{"id":404,"depth":678,"text":405},{"id":428,"depth":670,"text":429},{"id":441,"depth":670,"text":442},{"id":457,"depth":670,"text":458,"children":684},[685,686],{"id":464,"depth":678,"text":465},{"id":477,"depth":678,"text":478},{"id":493,"depth":670,"text":494},{"id":538,"depth":670,"text":539},{"id":551,"depth":670,"text":552},{"id":584,"depth":670,"text":585},{"id":611,"depth":670,"text":612},{"id":647,"depth":670,"text":648},{"id":654,"depth":670,"text":655},"Per-environment SQLite, migration safety, backup retention, isolated restores, export, and KV recovery.","md",null,{},true,{"title":132,"description":694},"aX5j-z_V48rcKPpFL_vSmPHryGhbfjhdHtMZQ4hM4rc",[702,704],{"title":128,"path":129,"stem":130,"description":703,"children":-1},"The immutable deployment chain, approval invalidation, readiness checks, and code rollback.",{"title":142,"path":143,"stem":144,"description":705,"children":-1},"Telemetry, correlation context, redaction, append-only audit, and proposed retention defaults.",1790019415367]