[{"data":1,"prerenderedAt":489},["ShallowReactive",2],{"navigation":3,"\u002Freference\u002Fglossary":250,"\u002Freference\u002Fglossary-surround":484},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":239,"body":252,"description":477,"extension":478,"links":479,"meta":480,"navigation":481,"path":240,"seo":482,"stem":241,"__hash__":483},"docs\u002F8.reference\u002F3.glossary.md",{"type":253,"value":254,"toc":469},"minimark",[255,260,313,317,373,377],[256,257,259],"h2",{"id":258},"organizations-and-authority","Organizations and authority",[261,262,263,271,277,283,289,295,301,307],"ul",{},[264,265,266,270],"li",{},[267,268,269],"strong",{},"Organization:"," root tenant and durable owner of applications and their data.",[264,272,273,276],{},[267,274,275],{},"Creator:"," person authorized to create or change applications and request deployment.",[264,278,279,282],{},[267,280,281],{},"Consumer:"," person who uses a deployed app; does not require a paid creator seat.",[264,284,285,288],{},[267,286,287],{},"Business owner:"," accountable for the workflow and its ongoing need.",[264,290,291,294],{},[267,292,293],{},"Technical owner:"," accountable for maintenance and technical review.",[264,296,297,300],{},[267,298,299],{},"Human grant:"," revocable authority delegated to an AI client, bound to a person, organization, apps, scopes, and expiration.",[264,302,303,306],{},[267,304,305],{},"Capability:"," an explicitly authorized resource or operation, such as an app DB or approved integration.",[264,308,309,312],{},[267,310,311],{},"Risk floor:"," minimum risk classification computed from capabilities; a creator cannot lower it.",[256,314,316],{"id":315},"source-and-delivery","Source and delivery",[261,318,319,325,331,337,343,349,355,361,367],{},[264,320,321,324],{},[267,322,323],{},"Canonical source:"," the single writable source of truth: managed Forgejo or an external Git provider.",[264,326,327,330],{},[267,328,329],{},"Change set:"," source edits with a base\u002Fcurrent revision, human and client attribution, build, preview, and review state.",[264,332,333,336],{},[267,334,335],{},"Source revision:"," immutable source identity used for a build; never a moving branch reference.",[264,338,339,342],{},[267,340,341],{},"Artifact:"," immutable build output and metadata addressed by digest and signed for verification.",[264,344,345,348],{},[267,346,347],{},"Deployment:"," an artifact and its policy, capabilities, migrations, approvals, and activation history for an environment.",[264,350,351,354],{},[267,352,353],{},"Environment:"," independently scoped production or preview resources within an application.",[264,356,357,360],{},[267,358,359],{},"Preview:"," temporary, protected deployment with an isolated database and KV namespace, synthetic data, and expiration.",[264,362,363,366],{},[267,364,365],{},"Code rollback:"," switches to an earlier artifact after confirming current schema compatibility.",[264,368,369,372],{},[267,370,371],{},"Data restore:"," recovers a snapshot into a new DB, validates it, and switches the binding after approval. It can lose writes made after the recovery point.",[256,374,376],{"id":375},"infrastructure-and-reliability","Infrastructure and reliability",[261,378,379,385,391,397,403,409,415,421,427,433,439,445,451,457,463],{},[264,380,381,384],{},[267,382,383],{},"Control plane:"," trusted services owning identity, tenancy, policy, desired state, and workflows.",[264,386,387,390],{},[267,388,389],{},"Runtime\u002Fdata plane:"," gateway, sandboxed applications, binding services, and controlled egress in a runtime cluster.",[264,392,393,396],{},[267,394,395],{},"workerd:"," the Workers-compatible execution engine; it must run inside a separate strong sandbox.",[264,398,399,402],{},[267,400,401],{},"Binding:"," API and capability to a scoped resource without exposing infrastructure connection credentials.",[264,404,405,408],{},[267,406,407],{},"RuntimeClass:"," Kubernetes mechanism selecting the sandbox runtime; actual implementation is a Phase 0 gate.",[264,410,411,414],{},[267,412,413],{},"Reconciliation:"," comparing observed resources with authoritative desired state and converging safely.",[264,416,417,420],{},[267,418,419],{},"Transactional outbox:"," persists an operation and its dispatch event atomically, then delivers asynchronously.",[264,422,423,426],{},[267,424,425],{},"Idempotency:"," repeating an operation with the same identity does not repeat its side effects.",[264,428,429,432],{},[267,430,431],{},"RPO:"," recovery point objective, the target maximum data-loss interval.",[264,434,435,438],{},[267,436,437],{},"RTO:"," recovery time objective, the target time to restore service.",[264,440,441,444],{},[267,442,443],{},"eTLD+1:"," registrable domain boundary; application origins must be on a different one from the control plane.",[264,446,447,450],{},[267,448,449],{},"JIT:"," just-in-time provisioning on a valid, authorized first login.",[264,452,453,456],{},[267,454,455],{},"SCIM:"," lifecycle provisioning\u002Fdeprovisioning of users and groups.",[264,458,459,462],{},[267,460,461],{},"WAF-lite:"," intrnl's limited request policy controls; not full managed WAF parity.",[264,464,465,468],{},[267,466,467],{},"Regulated data:"," information subject to additional legal, contractual, or compliance controls; excluded from the v1 pilot.",{"title":470,"searchDepth":471,"depth":472,"links":473},"",1,2,[474,475,476],{"id":258,"depth":472,"text":259},{"id":315,"depth":472,"text":316},{"id":375,"depth":472,"text":376},"Shared terminology for the control plane, applications, capabilities, and delivery records.","md",null,{},true,{"title":239,"description":477},"MHUYP85d3x3ZibC020uw2TVaXsss1srSLRrQRBtrEc8",[485,487],{"title":235,"path":236,"stem":237,"description":486,"children":-1},"Locked architecture and the evidence required to close open implementation gates.",{"title":243,"path":244,"stem":245,"description":488,"children":-1},"Official references for isolation, identity, MCP, source, data recovery, and data protection.",1790019415367]