[{"data":1,"prerenderedAt":425},["ShallowReactive",2],{"navigation":3,"\u002Fgetting-started\u002Fdecisions":250,"\u002Fgetting-started\u002Fdecisions-surround":420},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":12,"body":252,"description":413,"extension":414,"links":415,"meta":416,"navigation":417,"path":13,"seo":418,"stem":14,"__hash__":419},"docs\u002F1.getting-started\u002F2.decisions.md",{"type":253,"value":254,"toc":407},"minimark",[255,271,363,366,373,392,397,404],[256,257,258],"note",{},[259,260,261,265,266,270],"p",{},[262,263,264],"strong",{},"v1 design baseline."," This page specifies intended behavior. Delivery and validation are tracked in the ",[267,268,269],"a",{"href":171},"implementation plan","; it is not a claim that the platform is already implemented.",[272,273,274,287],"table",{},[275,276,277],"thead",{},[278,279,280,284],"tr",{},[281,282,283],"th",{},"Decision",[281,285,286],{},"Locked v1 position",[288,289,290,299,312,320,328,336,347,355],"tbody",{},[278,291,292,296],{},[293,294,295],"td",{},"Deployment topology",[293,297,298],{},"Central SaaS control plane; separate runtime clusters; the pilot organization gets a dedicated intrnl-operated cluster.",[278,300,301,304],{},[293,302,303],{},"Execution isolation",[293,305,306,307,311],{},"All customer code is untrusted; disposable sandboxed builds; ",[308,309,310],"code",{},"workerd"," runs inside an OS\u002FVM-level sandbox.",[278,313,314,317],{},[293,315,316],{},"AI integration",[293,318,319],{},"Organization-aware remote MCP endpoint; users bring approved AI clients\u002Faccounts; intrnl does not proxy consumer subscriptions.",[278,321,322,325],{},[293,323,324],{},"Identity",[293,326,327],{},"intrnl acts as identity broker; the pilot organization uses Entra OIDC first, JIT provisioning, group\u002Fapp-role mapping, and later SCIM.",[278,329,330,333],{},[293,331,332],{},"Source management",[293,334,335],{},"Managed source defaults to hidden Forgejo; external Git is optional; exactly one writable source of truth.",[278,337,338,341],{},[293,339,340],{},"Runtime contract",[293,342,343,344,346],{},"Nuxt first, Workers-compatible ",[308,345,310],{}," runtime, explicit bindings, no arbitrary Node\u002Fcontainer environment.",[278,348,349,352],{},[293,350,351],{},"Data operations",[293,353,354],{},"Isolated SQLite database per app environment; controlled migrations, backups, previews, restore, and export.",[278,356,357,360],{},[293,358,359],{},"Governance\u002Feconomics",[293,361,362],{},"Capability- and risk-based governance; creator\u002Fdeveloper pricing plus platform capacity; application consumers are not paid seats.",[259,364,365],{},"These decisions are sufficiently settled to build against.",[259,367,368,369,372],{},"A few ",[262,370,371],{},"implementation selections"," remain deliberate Phase 0 validation gates rather than architectural ambiguity:",[374,375,376,380,383,386,389],"ul",{},[377,378,379],"li",{},"Kata\u002FFirecracker versus gVisor as the actual sandbox RuntimeClass.",[377,381,382],{},"The infrastructure vendor and region.",[377,384,385],{},"Exact request, build, storage, and retention quotas.",[377,387,388],{},"The final separate domain used for customer application origins.",[377,390,391],{},"The exact commercial price points.",[393,394,396],"h2",{"id":395},"recording-decisions","Recording decisions",[259,398,399,400,403],{},"Phase 0 produces ADRs for the sandbox, runtime compatibility, DB semantics, Entra mappings, MCP client compatibility, source adapter, routing\u002FTLS, and artifact signing. Each ADR records context, alternatives, evidence, decision, consequences, owner, and review date. Track unresolved selections in the ",[267,401,402],{"href":236},"decision register",".",[259,405,406],{},"Pilot retention proposals and the 128 MiB compatibility test profile are inputs to validation. Final contractual limits, retention, and prices remain open.",{"title":408,"searchDepth":409,"depth":410,"links":411},"",1,2,[412],{"id":395,"depth":410,"text":396},"Locked v1 architecture decisions and implementation selections that still require validation.","md",null,{},true,{"title":12,"description":413},"pi6b9vs-XnI-JhL0gIq7atnbcz-MTFyeQAjPTLHD-gg",[421,423],{"title":10,"path":6,"stem":7,"description":422,"children":-1},"The product, intended users, and the path from an idea to organization-owned software.",{"title":16,"path":17,"stem":18,"description":424,"children":-1},"The explicit boundary of v1, the organization pilot, and later platform capabilities.",1790019415367]