[{"data":1,"prerenderedAt":621},["ShallowReactive",2],{"navigation":3,"\u002Freference\u002Fcontributing":250,"\u002Freference\u002Fcontributing-surround":618},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":247,"body":252,"description":611,"extension":612,"links":613,"meta":614,"navigation":615,"path":248,"seo":616,"stem":249,"__hash__":617},"docs\u002F8.reference\u002F5.contributing.md",{"type":253,"value":254,"toc":601},"minimark",[255,260,269,273,285,323,338,342,365,368,383,387,420,426,430,475,485,490,493,518,532,535,541,553,560,577,590,594,597],[256,257,259],"h2",{"id":258},"this-repository","This repository",[261,262,263,264,268],"p",{},"This checkout contains the Nuxt documentation website. The ",[265,266,267],"a",{"href":53},"platform codebase"," is a proposed separate monorepo. Running this site does not run the intrnl control plane or customer workloads.",[256,270,272],{"id":271},"local-setup","Local setup",[261,274,275,276,280,281,284],{},"Use Node.js 24 LTS and ",[277,278,279],"code",{},"pnpm@12.5.1",", as pinned in ",[277,282,283],{},"package.json",". With Corepack available:",[286,287,292],"pre",{"className":288,"code":289,"language":290,"meta":291,"style":291},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","corepack pnpm install --frozen-lockfile\ncorepack pnpm dev\n","bash","",[277,293,294,313],{"__ignoreMap":291},[295,296,299,303,307,310],"span",{"class":297,"line":298},"line",1,[295,300,302],{"class":301},"sBMFI","corepack",[295,304,306],{"class":305},"sfazB"," pnpm",[295,308,309],{"class":305}," install",[295,311,312],{"class":305}," --frozen-lockfile\n",[295,314,316,318,320],{"class":297,"line":315},2,[295,317,302],{"class":301},[295,319,306],{"class":305},[295,321,322],{"class":305}," dev\n",[261,324,325,326,329,330,333,334,337],{},"The normal development address is ",[277,327,328],{},"http:\u002F\u002Flocalhost:3000",". The site uses Nuxt UI and Nuxt Content with the native SQLite connector. Set ",[277,331,332],{},"NUXT_PUBLIC_SITE_URL"," at build time when deploying somewhere other than the configured ",[277,335,336],{},"https:\u002F\u002Fdocs.intrnl.cloud"," default. The default URL is a configuration choice, not evidence of a live deployment.",[256,339,341],{"id":340},"authoring","Authoring",[261,343,344,345,348,349,352,353,356,357,360,361,364],{},"Pages live under ",[277,346,347],{},"content\u002F"," and require frontmatter ",[277,350,351],{},"title"," and ",[277,354,355],{},"description",". Numeric filename prefixes order navigation (use zero padding for sections with ten or more pages); they are not part of public URLs. Section titles and icons live in ",[277,358,359],{},".navigation.yml",". The landing page is ",[277,362,363],{},"content\u002Findex.md",".",[261,366,367],{},"Use root-relative public routes for internal links. Add useful cross-links between architecture, delivery requirements, and operations. Tables and code fences should describe the plan accurately; examples with ellipses are illustrative, not runnable samples. Keep placeholders and proposed contracts clearly labeled.",[261,369,370,371,374,375,378,379,382],{},"Maintain the ",[265,372,373],{"href":232},"31-section coverage index"," and the ",[265,376,377],{"href":236},"decision register",". Record implementation evidence before changing a phase from planned to accepted. Preserve all ",[265,380,381],{"href":221},"definition-of-done"," requirements.",[256,384,386],{"id":385},"validation","Validation",[286,388,390],{"className":288,"code":389,"language":290,"meta":291,"style":291},"corepack pnpm lint\ncorepack pnpm typecheck\ncorepack pnpm build\n",[277,391,392,401,410],{"__ignoreMap":291},[295,393,394,396,398],{"class":297,"line":298},[295,395,302],{"class":301},[295,397,306],{"class":305},[295,399,400],{"class":305}," lint\n",[295,402,403,405,407],{"class":297,"line":315},[295,404,302],{"class":301},[295,406,306],{"class":305},[295,408,409],{"class":305}," typecheck\n",[295,411,413,415,417],{"class":297,"line":412},3,[295,414,302],{"class":301},[295,416,306],{"class":305},[295,418,419],{"class":305}," build\n",[261,421,422,423,364],{},"The production build prerenders linked pages. Check the changed routes, search, table of contents, raw Markdown, and mobile navigation. Every new category must be included in the LLM sections in ",[277,424,425],{},"nuxt.config.ts",[256,427,429],{"id":428},"machine-readable-documentation","Machine-readable documentation",[431,432,433,440,446,456],"ul",{},[434,435,436,439],"li",{},[277,437,438],{},"\u002Fllms.txt"," is the categorized documentation index.",[434,441,442,445],{},[277,443,444],{},"\u002Fllms-full.txt"," contains the full documentation.",[434,447,448,451,452,455],{},[277,449,450],{},"\u002Fraw\u002Farchitecture.md"," is the architecture page as Markdown; other docs use the same ",[277,453,454],{},"\u002Fraw\u002F\u003Cpage-path>.md"," pattern.",[434,457,458,459,462,463,352,466,469,470,472,473,364],{},"The documentation MCP endpoint is ",[277,460,461],{},"\u002Fmcp",", with read-only ",[277,464,465],{},"list-pages",[277,467,468],{},"get-page"," tools. Discover a page path with ",[277,471,465],{},", then supply it to ",[277,474,468],{},[261,476,477,478,481,482,364],{},"These endpoints read the content served by this site. They do not grant application access, mutate source, build applications, or request deployment. The organization-aware platform tools at ",[277,479,480],{},"mcp.intrnl.cloud"," are a separate ",[265,483,484],{"href":99},"planned service",[486,487,489],"h3",{"id":488},"connect-with-codex","Connect with Codex",[261,491,492],{},"Add the public documentation server using the Codex CLI:",[286,494,496],{"className":288,"code":495,"language":290,"meta":291,"style":291},"codex mcp add intrnl-docs --url https:\u002F\u002Fdocs.intrnl.cloud\u002Fmcp\n",[277,497,498],{"__ignoreMap":291},[295,499,500,503,506,509,512,515],{"class":297,"line":298},[295,501,502],{"class":301},"codex",[295,504,505],{"class":305}," mcp",[295,507,508],{"class":305}," add",[295,510,511],{"class":305}," intrnl-docs",[295,513,514],{"class":305}," --url",[295,516,517],{"class":305}," https:\u002F\u002Fdocs.intrnl.cloud\u002Fmcp\n",[261,519,520,521,523,524,527,528,531],{},"No login, API key, or bearer token is required. Start a new Codex session, then use ",[277,522,461],{}," to check that ",[277,525,526],{},"intrnl-docs"," is connected. You can also run ",[277,529,530],{},"codex mcp list"," in your terminal to check the saved configuration.",[261,533,534],{},"Try this prompt:",[536,537,538],"blockquote",{},[261,539,540],{},"Use intrnl-docs to explain our runtime contract and cite the relevant documentation.",[261,542,543,544,546,547,549,550,552],{},"Codex can use ",[277,545,465],{}," to find relevant pages, then ",[277,548,468],{}," with a discovered path such as ",[277,551,111],{}," to read their full Markdown.",[261,554,555,556,559],{},"For manual configuration, add this entry to ",[277,557,558],{},"~\u002F.codex\u002Fconfig.toml"," instead of running the add command:",[286,561,565],{"className":562,"code":563,"language":564,"meta":291,"style":291},"language-toml shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","[mcp_servers.intrnl-docs]\nurl = \"https:\u002F\u002Fdocs.intrnl.cloud\u002Fmcp\"\n","toml",[277,566,567,572],{"__ignoreMap":291},[295,568,569],{"class":297,"line":298},[295,570,571],{},"[mcp_servers.intrnl-docs]\n",[295,573,574],{"class":297,"line":315},[295,575,576],{},"url = \"https:\u002F\u002Fdocs.intrnl.cloud\u002Fmcp\"\n",[261,578,579,580,582,583,589],{},"If the server is missing from ",[277,581,461],{},", check the saved configuration and restart your Codex session or IDE extension. See ",[265,584,588],{"href":585,"rel":586},"https:\u002F\u002Flearn.chatgpt.com\u002Fdocs\u002Fextend\u002Fmcp?surface=cli",[587],"nofollow","OpenAI's MCP configuration guide"," for client setup details.",[256,591,593],{"id":592},"publication-boundary","Publication boundary",[261,595,596],{},"The pages use generic organization examples and describe detailed architecture. Keep deployment access aligned with the intended documentation audience. No remote deployment or publication is performed merely by editing this repository.",[598,599,600],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}",{"title":291,"searchDepth":298,"depth":315,"links":602},[603,604,605,606,607,610],{"id":258,"depth":315,"text":259},{"id":271,"depth":315,"text":272},{"id":340,"depth":315,"text":341},{"id":385,"depth":315,"text":386},{"id":428,"depth":315,"text":429,"children":608},[609],{"id":488,"depth":412,"text":489},{"id":592,"depth":315,"text":593},"Run this documentation site, maintain plan coverage, and read the documentation through Markdown or MCP.","md",null,{},true,{"title":247,"description":611},"aVfk7jocfwcYIUxncCSPVnwHlKX4DfzhlUEOV9LR1Pc",[619,613],{"title":243,"path":244,"stem":245,"description":620,"children":-1},"Official references for isolation, identity, MCP, source, data recovery, and data protection.",1790019415368]