docs(gateway): separate shared edge transport from Orgmetra product composition - #433
seonghobae wants to merge 51 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Executable-feedback currentization only; no architecture-source write. #434 is now exact This does not change ADR 0432 topology, bounded-context ownership, OpenAPI/path authority, or the process-local-vs-durable provenance distinction. Keep #433 Proposed/Draft; do not create an ADR/TRACEABILITY churn commit merely to mirror a test-oracle repair. Normal architecture admission still requires unchanged-head terminal governance plus qualifying independent review. |
|
Architecture handoff after fresh executable review: no topology/ADR decision change is required. #434 is now exact The previously documented process-local-versus-durable distinction now has an explicit implementation owner: #435, with Draft child #436 exact Keep ADR 0432 Proposed. Do not currentize canonical protected docs from #436 implementation churn; source change becomes warranted only if durable implementation evidence contradicts the selected architecture or normal architecture admission requires a substantive repair. |
|
2026-09-22 architecture handoff currentization; no ADR source rewrite. ADR 0432 already distinguishes process-local construction integrity from durable configuration/deployment authority, so the new executable delta does not change the selected topology. Dependent Draft #436 is now exact Keep the evidence layers separate in later protected reconciliation: process-local construction snapshots -> reconstructable normalized material -> durable non-reassignable generation/configuration persistence -> still-missing append-only deployment activation/rollback/recovery. #436 has zero PR-triggered workflow runs and no submitted review/thread evidence at this exact head, so this is implementation evidence only, not architecture acceptance or protected truth. ADR 0432 remains Proposed. |
|
Architecture handoff only; no source rewrite warranted. #436 is exact |
|
Architecture-currentization handoff from #437: implementation exact head advanced from |
|
Architecture-owner handoff after #437 advanced to |
|
Architecture currentization handoff: executable child #437 advanced to exact |
|
Architecture-owner handoff refresh: #436 remains exact The current #433 conversation/body still names predecessor #437 |
|
Architecture evidence handoff only; no source-status promotion: Draft #438 now advances the post-#437 request-routing layer at exact The new invariant is that declared Path Item selection precedes availability. In particular, an unavailable optional concrete route must fail closed and must not disappear early so that a broader available template captures the request. #438 returns only the stable current ADR 0432 / TRACEABILITY / doctoring source remains at this PR's existing exact head and Proposed/Draft status. When source is next currentized after admissible exact-tree execution, record this declared-selection-before-availability boundary separately from the still-missing raw HTTP transport normalization, authenticated principal/ACL projection, owner transport, lifecycle invalidation/fault handling and measured buyer path. |
|
Architecture evidence handoff: executable descendant stack now extends through Draft #439 exact When this Proposed source is ordinary-forward currentized after canonical execution, keep the layers explicit: declared generation/configuration -> recovery-bound/current durable availability -> request path/method preselection -> raw ASGI request-target normalization -> later host/auth/owner execution. The transport layer currently requires exact HTTP scope, mandatory raw path, empty query/root path, admitted ASCII bytes and raw/decoded path identity. It is not a receive/send application and does not establish Keyverse auth, owner HTTP execution, lifecycle/fault handling, deployment or p95 evidence. PR metadata is only a handoff; ADR/TRACEABILITY/doctoring source at this PR's current head remains Proposed until separately updated. |
|
Architecture evidence handoff currentization only; this is not source currentization and ADR 0432 remains Proposed/Draft. Current executable descendant path now extends through #439 exact When the ADR/TRACEABILITY/doctoring source ordinary-forward currentizes, keep these layers distinct: admitted generation/configuration; durable activation/recovery/currentness; declared path/method selection before availability; raw ASGI transport evidence before decoded routing; and RFC-conformant non-disclosing HTTP error projection. Do not describe #440 as a complete deployable composition host: Keyverse/Orgmetra auth context, owner HTTP execution, receive/body/disconnect/cancellation lifecycle, snapshot reload/invalidation, deployment/runtime role separation and full buyer-path acceptance remain absent. Primary standards added by the descendant evidence are RFC 9110 405/ |
Scope
Advances #432 with a Proposed ADR before protected runtime adoption. Documentation-only: no gateway runtime, route configuration, identity adapter, owner API, database registry, activation/recovery, serving snapshot, request router, HTTP host, or Orgmetra release becomes production-authoritative from this PR.
Protected base remains
develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Current source head remains6fc85e4d8bb273adb0d5866d87554067c749179d, open · Draft · mergeable=true, 51 commits / exactly three changed documentation files. ADR 0432 remains Proposed.Live implementation authority
#434 exact
68bdf2d984ca7686219c335a85a6574195675cbeowns process-local owner-route-generation admission. #436 exact30d89fa8f4ba95d7ddb84dde8e3b7e5faebf0343owns durable normalized generation/configuration authority. #437 exact8a67b5cef24332619b3a4466e3787a851c299215owns durable activation/rollback/recovery through 0025, external evidence, checked-as-used capability integrity, recovery-bound snapshots and database-bound serving currentness. #438 exactd642eb71c05ae3990349a26facf30593a5703914is ordinary-forward 7 ahead / 0 behind #437 with #437 exact as merge base and owns declared-request selection before durable currentness/availability; it adds no migration bytes.Required routes require complete operation coverage; optional routes permit zero observations but require whole-route completeness once any operation is observed. Application and final PostgreSQL validators also agree that activation/recovery authority cannot remain valid longer than an owner-operation observation that makes the route serviceable.
Fresh #437 PostgreSQL RED
0e4d0b2e481db169108222fba374f89f74ba1ce4demonstrates activation and recovery cases where a longer-lived bundle could previously be persisted over a shorter-lived required-route observation. Repair2311c0deaf8688f26d55da12b03fe11d293ba015requiresevidence_valid_until_unix_ms <= observation.valid_until_unix_msin both final 0025 validators and restores activation-sideobserved_at <= wall_clockparity. Source contract127388c...pins those validators and8a67b5c...preserves executable mode for the PostgreSQL root. Migration lineage remains 0018→0025.#438 keeps configuration selection and availability separate. Concrete Path Item precedence is resolved over the complete declared generation before availability is checked, so an unavailable optional concrete route cannot disappear and widen a broader template's authority. Fresh RED
ef991ff83a301aacf38a3157a1ad9bb995699ca8additionally proves unknown declared paths and undeclared methods must be rejected before the PostgreSQL currentness boundary is crossed; repaird642eb71c05ae3990349a26facf30593a5703914performs path/method preselection first, pins the selected route ID, then invokes #437's current activation/recovery check only for a routable request.Architecture source status
ADR 0432, TRACEABILITY and doctoring at source head
6fc85e4...remain stale relative to current implementation. PR-body currentization is not source currentization. Before Accepted/Ready, all three architecture source files must ordinary-forward adopt final admissible heads and distinguish declared generation membership, canonical evidence-only projection, recovery-bound snapshot projection, detached/pinned structural and serving coordinates, database-owned recovery time, exact clock ordering, owner-observation lifetime dominance, latest-recovery supersession, durable-attestation/current-activation read linearization, selection-before-currentness/availability request routing, supported restore/failover provenance, and the still-missing deployable HTTP lifecycle/invalidation/performance evidence.Migration-time owner equality still does not prove production runtime/migrator least privilege. Migration
0026remains occupied by active Employment-absence work and must not be stolen.Verification boundary
Exact #433 has its own historical hosted checks but still lacks independent architecture approval; those checks do not authorize stale architecture source. Current implementation RED→repair contracts are not canonical package/PostgreSQL GREEN.
Canonical package and PostgreSQL acceptance must use one unchanged exact #438
d642eb71...candidate. #260 handoff covers request-routing currentness, the new preselection-before-DB regressions, inherited #437 package tests and 100% owned statement/branch/docstring/edge coverage. #311 handoff covers complete 0018→0025 PostgreSQL inventory including the evidence-lifetime root, DB-owned recovery time, optional-route, hostile namespace, upgrade, recovery, serialization and provenance roots. Predecessor GREEN does not transfer.#340 remains the inherited Foundation prerequisite.
API-01remains Planned under #100 because there is still no protected deployable buyer path; package routing is not an HTTP host and does not justify changingdocs/product-technical-gap-baseline.mdfrom this lane.Remaining order: canonical exact-tree execution → architecture source currentization → fresh checks + independent architecture admission → Foundation/protected reconciliation → immutable external evidence → DB-role/security/fault/recovery acceptance → deployable HTTP host → full buyer-path k6/E2E p95≤20 ms → #51/#100 reconciliation → immutable release.
No force-push, destructive rebase, self-approval, gate weakening, mutable sibling source, cross-service SQL, synthetic status, blind/no-op rerun, routine administrator bypass, predecessor-GREEN transfer, migration-number theft, or premature Accepted/Ready/protected/release claim is authorized.