Platform boundaries · Deployment business cases
Dedicated deployments and shared infrastructure
Two business cases share one management contract: customer control through a dedicated environment, and quicker creation and trimming through retained parent infrastructure. Their evidence levels differ.
Platform boundaries · Deployment business cases
Dedicated deployments and shared infrastructure
Two business cases share one management contract: customer control through a dedicated environment, and quicker creation and trimming through retained parent infrastructure. Their evidence levels differ.
What this view establishes
The architectural commitments
- Dedicated deployment serves customer control; shared infrastructure serves efficient environment creation and trimming.
- Shared-pool isolation is observed locally, including restart and sibling preservation; hosted shared-pool operation is not yet accepted.
- Multi-tenant here means isolated child resources on retained infrastructure, not unrestricted shared data or shared-table tenancy.
- Browser-driven create/duplicate/retire is implemented behind the same session-derived admin authority, a bound single role store and a hard capacity cap; hosted acceptance (Phase 4) is Astra's to run.
Layered platform stack
Dedicated customer control
Dedicated environment
Separate application authority, database, object storage and credentials.
Development to production
Stage and domain identity stay separate from placement choice.
Hosted pilot proof
Historical three-client journey; not a production availability claim.
Shared infrastructure efficiency
One management surface
Authorized admin view
Projects, environments, release identity, status and admitted actions.
Hosted shared-pool service
Provider-specific operations, quotas and isolation acceptance remain.
Safe recovery
Unresolved effects refuse recovery until server reconciliation is proven.
Browser-driven lifecycle
Create, duplicate and retire an environment from the admin panel: an admission-gated owner bootstrap, a session-derived actor re-checked on every action, one bound role store, and a hard global capacity cap (default 10 live environments) enforced in plan and again inside create's transaction. Duplicate copies a source's release and domain pins plus its stage/region/recipe/retention configuration into a fresh isolated child -- never its data. Retire reuses the existing bounded delete/trim, confirmed by exact target and generation match. Recovery stays refused. Hosted acceptance is pending -- Phase 4 is Astra's to run against a disposable hosted environment.
Connections and evidence
Open the 12-relationship source key
Numbers set an explanatory reading order. They do not measure runtime timing.
Connections and evidence
Open the 12-relationship source key
- 01observed
Dedicated environment→Hosted pilot proof
hosted demonstration
- 02implemented
Development to production→Authorized admin view
project and stage identity
- 03implemented
Retained parent pool→Isolated child environments
reserve and provision
- 04observed
Isolated child environments→Trim one child
child-only cleanup
- 05implemented
Authorized admin view→Retained parent pool
manage local placement
- 06implemented
Authorized admin view→Dedicated environment
inspect registered state
- 07planned
Retained parent pool→Hosted shared-pool service
next provider acceptance
- 08planned
Authorized admin view→Safe recovery
unavailable today
- 09implemented
Authorized admin view→Browser-driven lifecycle
authorizes via session-derived actor
- 10implemented
Browser-driven lifecycle→Isolated child environments
create/duplicate provisions a fresh isolated child
- 11implemented
Browser-driven lifecycle→Trim one child
retire reuses the bounded delete/trim path
- 12planned
Browser-driven lifecycle→Hosted shared-pool service
hosted acceptance pending (Phase 4)
Connections and evidence
12 directed, source-backed relationships
Numbers set an explanatory reading order. They do not measure runtime timing.
- 01observed
Dedicated environment→Hosted pilot proof
hosted demonstration
- 02implemented
Development to production→Authorized admin view
project and stage identity
- 03implemented
Retained parent pool→Isolated child environments
reserve and provision
- 04observed
Isolated child environments→Trim one child
child-only cleanup
- 05implemented
Authorized admin view→Retained parent pool
manage local placement
- 06implemented
Authorized admin view→Dedicated environment
inspect registered state
- 07planned
Retained parent pool→Hosted shared-pool service
next provider acceptance
- 08planned
Authorized admin view→Safe recovery
unavailable today
- 09implemented
Authorized admin view→Browser-driven lifecycle
authorizes via session-derived actor
- 10implemented
Browser-driven lifecycle→Isolated child environments
create/duplicate provisions a fresh isolated child
- 11implemented
Browser-driven lifecycle→Trim one child
retire reuses the bounded delete/trim path
- 12planned
Browser-driven lifecycle→Hosted shared-pool service
hosted acceptance pending (Phase 4)
What this view establishes
The architectural commitments
- Dedicated deployment serves customer control; shared infrastructure serves efficient environment creation and trimming.
- Shared-pool isolation is observed locally, including restart and sibling preservation; hosted shared-pool operation is not yet accepted.
- Multi-tenant here means isolated child resources on retained infrastructure, not unrestricted shared data or shared-table tenancy.
- Browser-driven create/duplicate/retire is implemented behind the same session-derived admin authority, a bound single role store and a hard capacity cap; hosted acceptance (Phase 4) is Astra's to run.
Follow the live system
Move from explanation to inspection
The Atlas is static and source-backed. The Observatory shows authenticated environment state.
16 repository sources behind this view
docs/delegation/browser-driven-lifecycle-2026-09-12.mddocs/delegation/browser-driven-lifecycle-design-2026-09-12.mddocs/delegation/platform-groundwork-landing-2026-09-11.mddocs/platform-business-cases.mddocs/releases/evidence/records-v2-provider-readiness/hosted-three-client-receipt.jsondocs/releases/evidence/shared-provider-repairs/probe-receipt.jsonplatform/contracts/deployment-control-v1.jsonplatform/control-plane/control_plane.pyplatform/control-plane/field_notebook_shared_pool.pyplatform/control-plane/hosted_lifecycle_service.pyplatform/control-plane/records_v2_admin_lifecycle.pyplatform/control-plane/records_v2_admin_projection.pyplatform/control-plane/session_service.pyplatform/control-plane/shared_pool.pyplatform/control-plane/workspace_admission.pyplatform/deployment-console/src/app.js