Plan coverage
This index maps all 31 sections of the supplied “intrnl.cloud v1 — system architecture and implementation plan” into maintained documentation. Section numbers refer to the original plan; page headings use descriptive names.
Section coverage
- Introduction — Product definition.
- Decisions and open gates — Locked architectural decisions.
- Domains and TLS — One important security refinement: separate app and control-plane domains.
- System architecture — Top-level architecture.
- Trust zones — Trust zones.
- Control plane — Central control plane.
- Organization tenancy — Organization tenancy.
- Identity and sessions — Identity architecture.
- AI and MCP — AI and MCP architecture.
- Source control — Source-control architecture.
- Sandboxed builds — Build architecture.
- Runtime contract and SDK — Runtime contract.
- Runtime clusters and previews — Runtime-cluster architecture.
- Ingress and egress — Ingress, network, and egress.
- Access policies and WAF-lite — Access policy and WAF-lite.
- Databases and recovery — Data architecture.
- Secrets and integrations — Secrets and integrations.
- Deployments and approvals — Deployment pipeline.
- Governance and ownership — Governance.
- Economics and quotas — Economics and metering.
- Core data model — Core data model.
- APIs and protocols — API architecture.
- Observability and audit — Observability and audit.
- Threat model — Security threat model.
- Organization pilot — Organization v1 pilot.
- Codebase organization — Codebase organization.
- Implementation plan — all ten phases, each with full scope and exit criteria.
- Test strategy — Test strategy.
- Operating model — Operational model.
- Scope and non-goals — Explicit v1 non-goals.
- Definition of done — v1 definition of done.
Editorial treatment
Extraction was checked against the supplied plan on 2026-09-21: all 31 sections, all ten implementation phases and their exit criteria, and all 28 definition-of-done requirements are preserved. The maintained pages are self-contained; the temporary root-level project-plan.md is not required to build or use this site.
All original major sections and phase exit criteria are retained. Citation tokens are replaced by official references. Section numbers are removed from subheadings. The artifact contract date is aligned with the illustrative runtime configuration date; neither declares a shipped version. Signature verification precedes workload startup. Migration availability is conditional on schema compatibility. Customer and industry examples are generalized. Enterprise system integrations remain future scope.
The decision register, glossary, contributor guide, and operational runbooks add navigation and implementation guidance. Runbooks are procedure specifications pending implementation-specific commands and rehearsal. No additional feature is promoted into v1, and no phase is marked complete.