Skip to content

Architecture Decision Records

Each ADR captures one significant decision: its context, the choice, and the consequences. They are append-only — a decision is changed by a new ADR that supersedes or refines an earlier one, not by rewriting it. This index is the canonical list; keep it in sync when adding an ADR.

Status legend: Accepted (in force) · Proposed (direction agreed, not yet built / rebuild-gated) · Superseded (replaced by a later ADR).

ADR Status
ADR-001: Multi-Cloud Terragrunt Monorepo Structure Accepted
ADR-002: AWS State Storage in S3 with Cloud-Aware Routing Accepted
ADR-003: Service Control Policy Design Philosophy Accepted
ADR-004: AWS Account Management Strategy Accepted
ADR-005: Organizational Unit Hierarchy Design Accepted
ADR-006: State Bootstrap Pattern Accepted
ADR-007: Platform IAM Role Model Accepted
ADR-083: Provider Version-Constraint Standardization Accepted
ADR Status
ADR-015: CIDR Allocation Strategy Accepted
ADR-022: DNS Architecture — Route53 with Cloudflare Delegation Accepted
ADR-030: Route53 Subdomain Delegation for Environment DNS Accepted
ADR-034: Transit Gateway for Cross-Account VPC Connectivity Accepted
ADR-035: Cross-VPC DNS Resolution for Private EKS Endpoints Accepted
ADR-096: Web Application Firewall — Edge-First via Cloudflare Proposed (architecture agreed; implementation deferred — ADR-092 no-spend)
ADR Status
ADR-008: Cilium as Cross-Cloud CNI Accepted
ADR-009: EKS Component Separation Accepted
ADR-010: Private-Only EKS API Endpoint Accepted
ADR-011: Tailscale Operator for Private Cluster Access Accepted
ADR-016: OpenTofu over HashiCorp Terraform Accepted
ADR-017: Gateway API over Traditional Ingress Accepted
ADR-020: SSM Session Manager Bastion over SSH Bastion Accepted
ADR-021: ArgoCD for GitOps Delivery Accepted
ADR-023: EKS Managed Node Groups over Self-Managed or Karpenter Accepted
ADR-038: platctl CLI for Platform Operations Accepted
ADR-065: Self-Hosted GitHub Actions Runners (ARC) on the Platform Cluster Accepted
ADR Status
ADR-019: External Secrets Operator for Secrets Management Accepted
ADR-024: Secrets Management Architecture Accepted
ADR-025: Secret Naming Convention and Path Hierarchy Accepted
ADR-026: Cross-Account Secret Isolation Accepted
ADR-037: CloudTrail for Secrets Audit Logging Accepted
ADR-066: SOPS-Encrypted Config Secrets in Git (KMS) Accepted
ADR-070: Tenant Application Config & Secrets Proposed
ADR-094: Secret Rotation Strategy Proposed
ADR Status
ADR-013: Compliance Tier Model Accepted
ADR-014: Kyverno as Policy Engine Accepted
ADR-027: Hybrid Tenant Isolation Model Accepted
ADR-028: ECR Cross-Account Container Registry Accepted
ADR-029: Preprod Public Ingress via Gateway API Accepted
ADR-031: Multi-App Tenant Model Accepted
ADR-032: PR Preview Environments Accepted (built + live, proven end-to-end 2026-07-01)
ADR-033: Defer vCluster Tenant Support Accepted
ADR-046: Adopt the BACK Stack for Developer Self-Service Accepted
ADR-048: Federated, Per-Cluster Crossplane for Tenant Provisioning Accepted
ADR-049: Multi-Tenancy Model — Team, Tenant, and Zone Accepted (Zone/Customer partly superseded by ADR-067)
ADR-058: Per-Cloud Tenant Composition Strategy Proposed
ADR-060: Tenant App Hostname Convention — Derive and Inject Accepted
ADR-061: Tenant Ingress & Custom Domain Strategy Accepted
ADR-062: Self-Service Tenant Provisioning (Backstage + GitOps) & Its Security Model Accepted
ADR-063: Team as a First-Class Git-Native Object Accepted
ADR-067: IDP Domain Model — Team / Product / Service / Environment / Customer Accepted
ADR-069: Delivery Source-of-Truth — Product Registry + Environment Claims Accepted
ADR-101: ServiceGrant — A Governed Cross-Team Network Capability Accepted
ADR Status
ADR-012: ArgoCD SSO via Dex and SAML Superseded by ADR-053/059
ADR-018: IRSA for Pod-Level AWS Identity Superseded by ADR-047
ADR-039: Per-Team Developer RBAC Accepted
ADR-040: Platform Engineer Access Model Accepted
ADR-041: EKS Pod Identity for Tenant Workloads Accepted
ADR-047: EKS Pod Identity as the Standard for Pod AWS Identity Accepted
ADR-052: Centralized Dex SSO Broker Accepted (Dex retired; see ADR-053/059)
ADR-053: Identity & Cross-System Authorization Strategy Accepted
ADR-059: Identity Topology — Keycloak as the Pluggable Identity Seam Accepted
ADR-068: Product-Scoped & Cross-Team Access Model Proposed
ADR-084: Platform Identity Directory and Owner Resolution Proposed (Phase 0 + PagerDuty foundation built + live; Phases 1/3 outstanding)
ADR-087: Keycloak Admin-Plane Hardening — master-realm passkey + sealed break-glass Accepted (built + bound live 2026-06-27)
ADR-088: Temporary-Power Activation — just-in-time elevation & emergency revocation Accepted (built + live)
ADR-089: Governance Registry Topology — one git source, projected per-cluster Proposed (design)
ADR-090: Governance Identity Model — one source for role-holding, and the layer glossary Accepted (built + live)
ADR Status
ADR-036: GitHub Actions OIDC Federation for CI/CD Accepted
ADR-042: Isolated Build Provenance for SLSA Build L3 Accepted
ADR-050: Shared build-sign Reusable Workflow + Shared-Signer Policy Model Accepted
ADR-056: Progressive Delivery & Safe Rollback Accepted (Phase 1 built + applied, both clusters)
ADR-071: Image-Digest Promotion via the Control Plane (Protected-Main Delivery) Accepted
ADR-072: App-Repo Naming & Team Ownership Accepted
ADR-099: Feature Flags as a First-Class Platform Service Proposed
ADR-095: Dynamic Application Security Testing (DAST) Proposed
ADR-098: Package Registry — AWS CodeArtifact (+ ECR Pull-Through Cache) Accepted (built + live 2026-07-09)
ADR Status
ADR-051: Backstage as the Developer Portal Accepted
ADR-064: Backstage Provisioning Visibility & Developer Experience Proposed
ADR-097: TechDocs for the Learning Portal Accepted (implementing)

Self-Service Resources & Agentic Workloads

Section titled “Self-Service Resources & Agentic Workloads”
ADR Status
ADR-073: Self-Service Cloud Resources (the resource paved road) Accepted
ADR-074: Agentic Workloads — a Governed Platform for Running AI Agents Proposed
ADR-075: The Resource Agent — Conversational Self-Service (ADR-073 Phase B) Proposed
ADR-080: The Triage Copilot — Propose-Only On-Call Incident Triage Accepted
ADR-081: Platform-Team Products on the One Delivery Road Proposed (runtime forks: agents → ADR-082; services → 2026-07-11 amendment)
ADR-082: The XAgent Platform-Agent Runtime — a GitOps-Native Agent Control Plane Accepted (built + live 2026-06-26)
ADR-086: Autonomous Agent Access — Graduated Autonomy under Machine-Enforced Guardrails Proposed (draft / sketch)

Observability, Resilience & Compliance Assurance

Section titled “Observability, Resilience & Compliance Assurance”
ADR Status
ADR-043: Self-Hosted Prometheus/Grafana Observability Stack Accepted
ADR-044: Grafana Mimir for Durable, Multi-Tenant Metrics Storage Accepted
ADR-045: Falco for Runtime Threat Detection Accepted
ADR-076: Agent / GenAI Observability Accepted (corrected 2026-06-27)
ADR-077: Application Instrumentation Strategy Accepted
ADR-100: Observability Instrumentation Golden Path + OTLP↔Prometheus Convention Accepted
ADR-078: Cluster Elasticity — Karpenter + Workload Autoscaling Accepted
ADR-091: Cost Guardrails — per-team budgets, attribution, and phased enforcement Accepted (A+B+C live)
ADR-093: Descheduler for Node Rebalancing Proposed
ADR-092: Platform FinOps Practice — adopting the FinOps Framework for the platform’s own spend Proposed
ADR-085: Workload Availability — Graceful Draining & Disruption-Tolerance Defaults Accepted (built + live both clusters; replica-floor Enforce 2026-06-27)
ADR-079: Cloud-Resource Monitoring Scope — Query-Time-First in Grafana Accepted
ADR-054: Platform Resilience & Business Continuity Proposed
ADR-055: Compliance Assurance & Continuous Control Evidence Proposed
ADR-057: Service Identity & East-West Zero Trust (mTLS) Accepted (Phase 1 encryption live both clusters; Phase 2 mutual-auth/SPIFFE showcase live preprod, 2026-07-07)