S3 Platform Services — PostgreSQL HA, Valkey, object storage
Operator design review considered binding bounded rapp context to Forgejo orgs or State Hub domains and rejected both. OAS P1 governs - independent perspectives must stay in separate dimensions - and cardinality forces it: a repo has exactly one Forgejo org (a path segment in the clone URL) so org:repo is 1:many, while rapp:repo is many:many, and a many:many grouping cannot be derived from a 1:many one. Records the dimension table, the composition block (first-party member repos plus pinned upstream components and a stated purpose), and the precision that makes enforcement well-defined: repos are many:many with rapps but deployables are 1:1, so the validator can ask whether every live deployable belongs to exactly one rapp. That is the coverage check that would have caught all three of this survey's drift findings at once. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| .claude/rules | ||
| .forgejo/workflows | ||
| argocd | ||
| credential-change-requests | ||
| credential-grants | ||
| docs | ||
| helm | ||
| lib | ||
| openbao | ||
| registry | ||
| schemas | ||
| scripts | ||
| tests | ||
| tools | ||
| workplans | ||
| .custodian-brief.md | ||
| .gitignore | ||
| .repo-classification.yaml | ||
| .sops.yaml | ||
| AGENTS.md | ||
| CLAUDE.md | ||
| INTENT.md | ||
| LICENSE | ||
| Makefile | ||
| SCOPE.md | ||
| WORK-RECORDS.md | ||