Architecture Decision Records
Each ADR captures one significant decision: its context, the choice, and the consequences. They are append-only — a decision is changed by a new ADR that supersedes or refines an earlier one, not by rewriting it. This index is the canonical list; keep it in sync when adding an ADR.
Status legend: Accepted (in force) · Proposed (direction agreed, not yet built / rebuild-gated) ·
Superseded (replaced by a later ADR).
Foundation & AWS Org
Section titled “Foundation & AWS Org”| ADR | Status |
|---|---|
| ADR-001: Multi-Cloud Terragrunt Monorepo Structure | Accepted |
| ADR-002: AWS State Storage in S3 with Cloud-Aware Routing | Accepted |
| ADR-003: Service Control Policy Design Philosophy | Accepted |
| ADR-004: AWS Account Management Strategy | Accepted |
| ADR-005: Organizational Unit Hierarchy Design | Accepted |
| ADR-006: State Bootstrap Pattern | Accepted |
| ADR-007: Platform IAM Role Model | Accepted |
| ADR-083: Provider Version-Constraint Standardization | Accepted |
Networking & Connectivity
Section titled “Networking & Connectivity”| ADR | Status |
|---|---|
| ADR-015: CIDR Allocation Strategy | Accepted |
| ADR-022: DNS Architecture — Route53 with Cloudflare Delegation | Accepted |
| ADR-030: Route53 Subdomain Delegation for Environment DNS | Accepted |
| ADR-034: Transit Gateway for Cross-Account VPC Connectivity | Accepted |
| ADR-035: Cross-VPC DNS Resolution for Private EKS Endpoints | Accepted |
| ADR-096: Web Application Firewall — Edge-First via Cloudflare | Proposed (architecture agreed; implementation deferred — ADR-092 no-spend) |
Cluster & Platform Runtime
Section titled “Cluster & Platform Runtime”Secrets & Config
Section titled “Secrets & Config”Tenancy, Isolation & Policy
Section titled “Tenancy, Isolation & Policy”Workload & Human Identity
Section titled “Workload & Human Identity”Supply Chain & Delivery
Section titled “Supply Chain & Delivery”| ADR | Status |
|---|---|
| ADR-036: GitHub Actions OIDC Federation for CI/CD | Accepted |
| ADR-042: Isolated Build Provenance for SLSA Build L3 | Accepted |
ADR-050: Shared build-sign Reusable Workflow + Shared-Signer Policy Model |
Accepted |
| ADR-056: Progressive Delivery & Safe Rollback | Accepted (Phase 1 built + applied, both clusters) |
| ADR-071: Image-Digest Promotion via the Control Plane (Protected-Main Delivery) | Accepted |
| ADR-072: App-Repo Naming & Team Ownership | Accepted |
| ADR-099: Feature Flags as a First-Class Platform Service | Proposed |
| ADR-095: Dynamic Application Security Testing (DAST) | Proposed |
| ADR-098: Package Registry — AWS CodeArtifact (+ ECR Pull-Through Cache) | Accepted (built + live 2026-07-09) |
Developer Portal & Experience
Section titled “Developer Portal & Experience”| ADR | Status |
|---|---|
| ADR-051: Backstage as the Developer Portal | Accepted |
| ADR-064: Backstage Provisioning Visibility & Developer Experience | Proposed |
| ADR-097: TechDocs for the Learning Portal | Accepted (implementing) |
Self-Service Resources & Agentic Workloads
Section titled “Self-Service Resources & Agentic Workloads”| ADR | Status |
|---|---|
| ADR-073: Self-Service Cloud Resources (the resource paved road) | Accepted |
| ADR-074: Agentic Workloads — a Governed Platform for Running AI Agents | Proposed |
| ADR-075: The Resource Agent — Conversational Self-Service (ADR-073 Phase B) | Proposed |
| ADR-080: The Triage Copilot — Propose-Only On-Call Incident Triage | Accepted |
| ADR-081: Platform-Team Products on the One Delivery Road | Proposed (runtime forks: agents → ADR-082; services → 2026-07-11 amendment) |
ADR-082: The XAgent Platform-Agent Runtime — a GitOps-Native Agent Control Plane |
Accepted (built + live 2026-06-26) |
| ADR-086: Autonomous Agent Access — Graduated Autonomy under Machine-Enforced Guardrails | Proposed (draft / sketch) |