[{"data":1,"prerenderedAt":583},["ShallowReactive",2],{"navigation":3,"\u002Froadmap\u002Fphase-0":250,"\u002Froadmap\u002Fphase-0-surround":578},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":176,"body":252,"description":571,"extension":572,"links":573,"meta":574,"navigation":575,"path":177,"seo":576,"stem":178,"__hash__":577},"docs\u002F7.roadmap\u002F02.phase-0.md",{"type":253,"value":254,"toc":558},"minimark",[255,262,265,270,273,304,310,314,317,349,354,358,361,372,375,378,383,387,390,416,421,425,428,454,459,463,466,492,497,501,504,527,532,536,539,544,548,551],[256,257,258],"p",{},[259,260,261],"strong",{},"Status: planned; completion evidence not yet recorded in this documentation.",[256,263,264],{},"These spikes must finish before substantial production implementation.",[266,267,269],"h2",{"id":268},"sandbox-bake-off","Sandbox bake-off",[256,271,272],{},"Compare Kata\u002FFirecracker and gVisor against:",[274,275,276,280,283,286,289,292,295,298,301],"ul",{},[277,278,279],"li",{},"Escape\u002Fthreat model",[277,281,282],{},"KVM requirements",[277,284,285],{},"Cold start",[277,287,288],{},"Nuxt memory\u002Fbuild performance",[277,290,291],{},"Workerd startup",[277,293,294],{},"Network policy",[277,296,297],{},"Debuggability",[277,299,300],{},"Upgrade path",[277,302,303],{},"Per-app cost",[256,305,306,309],{},[259,307,308],{},"Exit:"," selected RuntimeClass and documented fallback.",[266,311,313],{"id":312},"nuxtworkerd-compatibility-spike","Nuxt\u002Fworkerd compatibility spike",[256,315,316],{},"Build representative Nuxt applications exercising:",[274,318,319,322,325,328,331,334,337,340,343,346],{},[277,320,321],{},"SSR",[277,323,324],{},"API routes",[277,326,327],{},"Static assets",[277,329,330],{},"Streaming",[277,332,333],{},"Cookies",[277,335,336],{},"Authentication context",[277,338,339],{},"DB binding",[277,341,342],{},"KV binding",[277,344,345],{},"Common packages",[277,347,348],{},"Error handling",[256,350,351,353],{},[259,352,308],{}," versioned supported Nuxt template and unsupported-package list.",[266,355,357],{"id":356},"db-binding-spike","DB binding spike",[256,359,360],{},"Implement:",[362,363,369],"pre",{"className":364,"code":366,"language":367,"meta":368},[365],"language-text","prepare\nbind\nfirst\nall\nrun\nbatch\n","text","",[370,371,366],"code",{"__ignoreMap":368},[256,373,374],{},"over an internal RPC service backed by isolated SQLite.",[256,376,377],{},"Test concurrency, transaction semantics, WAL, backup, recovery, and multiple runtime replicas.",[256,379,380,382],{},[259,381,308],{}," documented DB contract and performance envelope.",[266,384,386],{"id":385},"entra-spike","Entra spike",[256,388,389],{},"Create a test tenant integration representative of a pilot organization:",[274,391,392,395,398,401,404,407,410,413],{},[277,393,394],{},"OIDC code flow",[277,396,397],{},"PKCE",[277,399,400],{},"app roles",[277,402,403],{},"assigned groups",[277,405,406],{},"group overage",[277,408,409],{},"JIT",[277,411,412],{},"session revocation",[277,414,415],{},"app login redirect",[256,417,418,420],{},[259,419,308],{}," finalized claims\u002Fmapping design.",[266,422,424],{"id":423},"mcp-spike","MCP spike",[256,426,427],{},"Connect both representative OpenAI and Anthropic clients:",[274,429,430,433,436,439,442,445,448,451],{},[277,431,432],{},"OAuth",[277,434,435],{},"user\u002Forg selection",[277,437,438],{},"read tool",[277,440,441],{},"write tool",[277,443,444],{},"scope denial",[277,446,447],{},"deployment request",[277,449,450],{},"revocation",[277,452,453],{},"audit",[256,455,456,458],{},[259,457,308],{}," stable remote MCP transport and OAuth design.",[266,460,462],{"id":461},"source-spike","Source spike",[256,464,465],{},"Provision and operate hidden Forgejo:",[274,467,468,471,474,477,480,483,486,489],{},[277,469,470],{},"repo create",[277,472,473],{},"branch",[277,475,476],{},"commit",[277,478,479],{},"diff",[277,481,482],{},"merge",[277,484,485],{},"export",[277,487,488],{},"optional SSH",[277,490,491],{},"backup\u002Frestore",[256,493,494,496],{},[259,495,308],{}," source service adapter contract.",[266,498,500],{"id":499},"routingtlsdomain-spike","Routing\u002FTLS\u002Fdomain spike",[256,502,503],{},"Validate:",[274,505,506,509,515,518,521,524],{},[277,507,508],{},"Separate runtime apex",[277,510,511,514],{},[370,512,513],{},"{app}.{org}"," hostnames",[277,516,517],{},"Per-org wildcard certificate",[277,519,520],{},"Preview hostname scheme",[277,522,523],{},"Cloudflare tunnel\u002Forigin protection",[277,525,526],{},"trusted client-IP derivation",[256,528,529,531],{},[259,530,308],{}," production routing\u002Fcertificate ADR.",[266,533,535],{"id":534},"artifactsigning-spike","Artifact\u002Fsigning spike",[256,537,538],{},"Build, sign, upload, fetch, verify, and activate an artifact.",[256,540,541,543],{},[259,542,308],{}," manifest and key-management format.",[266,545,547],{"id":546},"evidence-to-record","Evidence to record",[256,549,550],{},"Record implementation revisions, test reports, relevant ADRs, unresolved findings, the accepting owner, and acceptance date. Leave this phase planned until its exit criteria are demonstrated.",[256,552,553,557],{},[554,555,556],"a",{"href":171},"Return to the implementation plan",".",{"title":368,"searchDepth":559,"depth":560,"links":561},1,2,[562,563,564,565,566,567,568,569,570],{"id":268,"depth":560,"text":269},{"id":312,"depth":560,"text":313},{"id":356,"depth":560,"text":357},{"id":385,"depth":560,"text":386},{"id":423,"depth":560,"text":424},{"id":461,"depth":560,"text":462},{"id":499,"depth":560,"text":500},{"id":534,"depth":560,"text":535},{"id":546,"depth":560,"text":547},"Deliverables and exit criteria for architecture spikes and ADRs.","md",null,{},true,{"title":176,"description":571},"qRyLTg6N2KyGlGbD0OizCFTCfhwOdlwMLmHqcAcwH90",[579,581],{"title":170,"path":171,"stem":172,"description":580,"children":-1},"Ten phases from architecture validation to the organization pilot and v1 general availability.",{"title":180,"path":181,"stem":182,"description":582,"children":-1},"Deliverables and exit criteria for control-plane foundation.",1790019415368]