Seven Deployment Classes
Self-hosted, BYOC, managed dedicated cloud, shared SaaS, hybrid, air-gapped, and edge/constrained — each with distinct bootstrap authority, bundle semantics, endpoint strategy, update path, telemetry posture, and operator surface behavior. Deployment-class collapse is a constitutional violation.
CRTL / CRTS / coRTS Authority Chain
CRTL coordinates authority and admission. CRTS substrate domains satisfy declared profiles across network, resource, secret, bundle, database, accelerator, telemetry, governance, and lifecycle mechanics. coRTS receives admitted runtime units without becoming a second authority tier or product runtime.
Priority Endpoint Bundles
Signed ordered candidate endpoints and routing policy for hybrid and split deployments. Clients resolve from bootstrap authority through route manifests and data availability manifests — not hardcoded URLs, DNS reachability, or provider dashboard state promoted into authority.
Bootstrap Authority & Client Projection
One configured bootstrap authority reference returns deployment identity, runtime bundles, endpoint projections, and activation state. EndpointBundleProjection exposes candidate refs, precedence policy, certificate bindings, and manifest signatures — never raw infrastructure inventory.
Control Plane Desired-State Reconciliation
Master control backend owns estate-level policy, endpoint authority, licensing projection, activation projection, telemetry policy, update policy, and cross-scope registry truth. Reconcile loops project staged changes with verification windows, diagnostic evidence, and rollback-trigger state as durable records.
Site Agent & Local Execution Carrier
Site agent is the local execution-side carrier of control-plane authority in customer-owned, hybrid, air-gapped, and edge/constrained scopes. Heartbeat, bundle refresh, verification reports, and encrypted evidence spool/rejoin without per-customer glue scripts.
Host Supervisor Runtime Admission
Admission evaluates identity, runtime mode, resource ceilings, port and endpoint claims, DB/cache/broker ownership conflicts, accelerator claim conflicts, and lifecycle legality before launch. Hard denials — not warnings buried in installer logs.
Product Runtime Manifest Contract
Part 14 machine-readable declarations: runtime class, runtime mode, source mode, topology requirements, endpoint and route declarations, telemetry/licensing/activation hooks, backup/restore contracts, health/readiness contracts, and no-conflict requirements before activation.
Deployment Compatibility Contracts
Products declare supported operating modes, forbidden modes, deployment classes, data domains, and evidence hooks. CRTL validates ProductCompatibilityProfile as derived state bound to scope chain, policy version, route epoch, and bundle epoch.
Runtime Hook Transport & Criticality
Protobuf-first hook contract with fast_health, normal_operational, heavy_summary, and critical_blocking timeout classes. Hook failure classes distinguish install blockers from degraded-mode triggers with typed denial vocabulary across every control surface.
ARGUS Constitutional Governance Gate
ARGUS is the sole base foundational-core connection. Every mutating control surface invokes control_plane.resolve_identity synchronously, stages ProvenanceFrame evidence refs, and fails closed on missing authorization or evidence unless a bounded offline/local authority profile permits the action.
Foundational Core Convergence
Multiple products in one governed scope bind to one compatible foundational-core instance. Per-product, per-customer, namespace, quota, telemetry, audit, and lifecycle boundaries remain intact — convergence kills duplicate uncontrolled instances, not product ownership.
Database HA Backend Orchestration
Patroni and Stolon as HA orchestration backends with deployment-class-aware topology selection. Failover and switchover require evidence inside staleness bounds with RPO/RTO gates — HA-healthy is not restore-ready.
Backup, Restore & PITR Policy Engine
CRTL owns backup policy, override windows, exceptional triggers, and numeric RPO/RTO/WAL/archive/freshness gates. pgBackRest, WAL-G, and Barman integrate as adapter targets with credential-ref custody — not as policy shortcuts.
Operational Cockpit & Control Surface Parity
GUI cockpit displays infrastructure metrics, topology, costs, runtime state, and allowed actions with the same ControlSurfaceEnvelope fields as CLI, API, SDK, WebSocket, site-agent, host-supervisor, and support export projections.
Signed Runtime Bundles
Versioned payloads carrying runtime values, endpoint refs, secrets references, policy toggles, and product activation state per deployment, tenant, site, or product instance. Offline signed bundles for air-gapped and compact signed bundles for edge/constrained profiles.
Staged Bootstrap & Product Admission
Bootstrap agent install or offline bundle through fact gathering, signed registration, inventory graph, role-fit scoring, operator approval, substrate provisioning, product admission, and continuous reconciliation — evidence-backed, not installer optimism.
Feature Flag DAG & Integration Policy
Explicit KEEP/DISCARD integration decisions with dependency closure. Undeclared coupling and accidental shared-runtime drift are forbidden; declared crate, sidecar, and full-service integrations are all legal CRTL-supported runtime forms.
Universal Product Update Authority
CRTL orchestrates product updates: schedule, preflight, provenance verification, drain, apply, verification window, rollback, fallback, and update evidence — governed mutations with ARGUS authorization and staged evidence before success.
Regulated & Air-Gapped Runtime Continuity
FedRAMP, classified, MIL-STD, and air-gapped discovery profiles with source-pin discipline, raw-secret prohibitions, local authority for runtime admission, telemetry spooling, audit evidence, backup/restore, and update package admission without live cloud control-plane dependency on the hot path.