[{"data":1,"prerenderedAt":428},["ShallowReactive",2],{"navigation":3,"\u002Freference\u002Fdecisions":250,"\u002Freference\u002Fdecisions-surround":423},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":235,"body":252,"description":416,"extension":417,"links":418,"meta":419,"navigation":420,"path":236,"seo":421,"stem":237,"__hash__":422},"docs\u002F8.reference\u002F2.decisions.md",{"type":253,"value":254,"toc":406},"minimark",[255,260,280,284,296,300,385,389,392,396],[256,257,259],"h2",{"id":258},"status-conventions","Status conventions",[261,262,263,267,268,271,272,275,276,279],"p",{},[264,265,266],"strong",{},"Locked"," means the source plan establishes the design. ",[264,269,270],{},"Open gate"," means a selection or contract needs validation. ",[264,273,274],{},"Proposed default"," is an initial pilot value. ",[264,277,278],{},"Future"," is outside the current delivery scope. These states do not indicate implemented functionality.",[256,281,283],{"id":282},"locked-baseline","Locked baseline",[261,285,286,287,291,292,295],{},"The ",[288,289,290],"a",{"href":13},"architectural decisions"," establish a central SaaS control plane with separate runtimes; dedicated pilot infrastructure; disposable sandboxed builds; workerd inside an OS\u002FVM sandbox; scoped remote MCP; intrnl-brokered identity; one canonical source; Nuxt first; per-environment SQLite; and governance based on capabilities and risk. ",[288,293,294],{"href":68},"Separate registrable runtime and control-plane domains"," are also mandatory.",[256,297,299],{"id":298},"open-implementation-gates","Open implementation gates",[301,302,303,310,316,322,328,334,340,346,352,358,364,375],"ul",{},[304,305,306,309],"li",{},[264,307,308],{},"Sandbox RuntimeClass:"," compare Kata\u002FFirecracker with gVisor, including KVM availability, isolation, startup, build performance, memory, network enforcement, upgrades, and cost. Record the chosen class and fallback.",[304,311,312,315],{},[264,313,314],{},"Infrastructure and region:"," identify vendor, region, data residency requirements, KVM support, availability design, storage, and operational ownership. No vendor or region is selected here.",[304,317,318,321],{},[264,319,320],{},"Nuxt\u002Fworkerd compatibility:"," publish the supported template, pinned toolchain, API subset, package exclusions, and benchmark results.",[304,323,324,327],{},[264,325,326],{},"Database contract:"," fix result\u002Ferror shapes, parameter types, batch atomicity, transaction semantics, limits, WAL, concurrent writes, backups, and multiple runtime replica behavior.",[304,329,330,333],{},[264,331,332],{},"KV contract:"," document consistency, limits, TTLs, listing, namespace isolation, and recovery expectations independently from Cloudflare KV.",[304,335,336,339],{},[264,337,338],{},"Entra identity:"," validate issuer\u002Fsubject mapping, app roles, assigned groups, group overage, JIT, session revocation, and redirects. SCIM remains a required v1 follow-on.",[304,341,342,345],{},[264,343,344],{},"MCP compatibility:"," prove approved client\u002Faccount combinations, OAuth transport and discovery, scope denial, human\u002Fclient attribution, expiration, and revocation. Specify how approved workspace or account membership is established; client branding alone is insufficient evidence.",[304,347,348,351],{},[264,349,350],{},"Source adapter:"," validate managed repository creation, changes, protected merges, complete export, backup\u002Frestore, and optional developer access.",[304,353,354,357],{},[264,355,356],{},"Domain and TLS:"," choose the separate runtime apex and certificate automation, and validate preview naming, origin protection, and trusted client IPs.",[304,359,360,363],{},[264,361,362],{},"Artifacts and signing:"," define manifest encoding, digests, signing-service boundary, key custody, rotation, verification before execution, and activation.",[304,365,366,369,370,374],{},[264,367,368],{},"Quotas, retention, and capacity:"," benchmark actual Nuxt workloads and accept final request, build, storage, preview, and retention settings. Keep the ",[288,371,373],{"href":372},"\u002Foperations\u002Fobservability#pilot-retention-defaults","proposed defaults"," distinct from guarantees.",[304,376,377,380,381,384],{},[264,378,379],{},"Commercial prices:"," set amounts and packaging separately from the ",[288,382,383],{"href":25},"locked economic model",". No prices are promised here.",[256,386,388],{"id":387},"adr-record","ADR record",[261,390,391],{},"Each accepted gate needs a stable ADR ID, status, owner, date, context, alternatives, validation evidence, decision, consequences, fallback, and review trigger. Link it from the relevant phase and contract page. Do not mark an open selection accepted based solely on a preferred candidate in the plan.",[256,393,395],{"id":394},"acceptance-gates-after-phase-0","Acceptance gates after Phase 0",[261,397,286,398,401,402,405],{},[288,399,400],{"href":209},"pilot hardening phase"," requires security review, resolved critical\u002Fhigh penetration-test findings, restore evidence, pilot organization sign-off, and rehearsed operational procedures. The ",[288,403,404],{"href":213},"GA phase"," requires GitHub canonical mode and portable developer handoff.",{"title":407,"searchDepth":408,"depth":409,"links":410},"",1,2,[411,412,413,414,415],{"id":258,"depth":409,"text":259},{"id":282,"depth":409,"text":283},{"id":298,"depth":409,"text":299},{"id":387,"depth":409,"text":388},{"id":394,"depth":409,"text":395},"Locked architecture and the evidence required to close open implementation gates.","md",null,{},true,{"title":235,"description":416},"xUVYaFdMdInOO6ZiMY4u3LK31TOr-SkQKvMKKbx5ppM",[424,426],{"title":231,"path":232,"stem":233,"description":425,"children":-1},"A mapping from all 31 source-plan sections to this documentation.",{"title":239,"path":240,"stem":241,"description":427,"children":-1},"Shared terminology for the control plane, applications, capabilities, and delivery records.",1790019415367]