Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions docs/decisions/adrs/adr-104-runtime-control-plane-architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -195,6 +195,20 @@ tenants. Multitenancy, cross-target stores, cross-run scheduling, and shared
authorization namespaces are P3 nonclaims requiring a future ADR and explicit
coordination, fencing, cache-coherence, and tenant-isolation contracts.

Participant clients use an organizational backend boundary, not P2 or the
in-process/store interfaces directly. P2 read roles are privileged: an identity
allowed to retrieve a governed participant projection can also read the full
snapshot, so a participant/audience binding does not make that credential safe
to delegate. The backend owns organizational authentication and entitlement,
binds each request to its selected target/run, participant, exact episode and
audience, and releases only a permitted participant projection after the
API-423/RUN-319 crossing. Participant-facing deployments require a configured
crossing resolver; the legacy projection path without one carries no such
assurance. Service credentials and raw control-plane outputs remain inside the
trusted backend. Authentication principals do not add SDL participants or
roles. The accepted route, authority, and deployment matrix is the
[issue #1356 trust-boundary decision](../issue-1356-control-plane-participant-access-preflight.md).

### 8. Disposition of the incumbent surfaces

`RuntimeControlPlane`, the store protocol, the in-memory store, and the
Expand Down Expand Up @@ -334,3 +348,4 @@ demonstrated its lost-update and partial-state failures.
| 2026-09-19 | #1186 | Permitted the operator CLI to call only the closed public P1 offline-maintenance interface while keeping runtime validation and publication ownership intact. |
| 2026-09-20 | #1189 | Made profile declarations runtime-owned composition metadata, separated provider facts from guarantees, and fixed P2 and recovery-observation boundaries. |
| 2026-09-22 | #1348 | Defined shared-runtime supervision, effect reservations, evidence-based settlement and authored recovery choices while preserving profile and implementation nonclaims. |
| 2026-09-24 | #1356 | Bound participant clients to an organizational backend and kept privileged P2 credentials and raw control-plane outputs inside that boundary. |
5 changes: 4 additions & 1 deletion docs/decisions/adrs/adr-index.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -585,7 +585,7 @@ adrs:
pin: a44acbc2db1b5349ba316ba0d09bd9b46310db016cb87937b08bc6bc107755aa
- id: ADR-104
path: docs/decisions/adrs/adr-104-runtime-control-plane-architecture.md
pin: 51c31488ec6c704a371833c8ce8c468df5976bb2fc0ca0ff5fa3e6fde77bad1f
pin: 131d0c0923dd72ad51a9b621019b09494142b0636e7e6a5dc2d50f2f9d7766fb
amendments:
- date: 2026-09-03
ref: "#1151"
Expand All @@ -599,6 +599,9 @@ adrs:
- date: 2026-09-22
ref: "#1348"
summary: "Defined shared-runtime supervision, effect reservations, evidence-based settlement and authored recovery choices while preserving profile and implementation nonclaims."
- date: 2026-09-24
ref: "#1356"
summary: "Bound participant clients to an organizational backend and kept privileged P2 credentials and raw control-plane outputs inside that boundary."
- id: ADR-105
path: docs/decisions/adrs/adr-105-recursive-partial-description-semantics.md
pin: e50538c4e03d12ea92ad584322dc8618835f1724ae0086c444fba0527949a01e
Expand Down
Loading
Loading