Status
contract (production hardness)
Conceptual layer
④ Decision
Repo layer
L4 knowledge-reasoning
Source
architecture section 2.2 KR CI, section 14
ADR
027
Siblings
16-operations.md · 12-trace-and-eval.md · 20-benchmark.md · 27-ports-and-reliability.md · 21-registries-and-stage-graph.md

Purpose#

Decision integrity (kernel) is necessary but not sufficient. This doc locks the software contracts: versioning, tests, CI gates, schema evolution, observability SLOs, and store durability — so execution later cannot “skip the boring parts.”


Versioning#

ArtifactVersioned how
l4-kernelSemver in kernel doc + ADR on bump
Release lockfileContent hash; immutable once pinned
Contracts L3↔L4↔L5Explicit schema version; dual-read on bump (18)
RegistriesPer-entry version + lockfile pin
OE corpusCorpus version + embedding model id
Service buildsGit SHA + lockfile hash in CardSink provenance

Breaking wire changes: dual-read window; never silent field reuse.


Test architecture (required suites)#

SuiteProtects
Contract testsFinding intake, CardSink payload, topology records
Kernel goldenHard gates fire; money; write ban; disagreement withhold
ConcurrencyQueue priorities, dedupe, sweep vs Finding (25)
LifecycleCrash resume, lease expiry, cancel, idempotent emit (26)
Port fault injectionTimeouts, breakers, calculator down (27)
Replay / pass^kFrozen ledgers (12, 20)
DiscoveryShift sweep enqueue idempotency; pattern shadow
OE advisoryOE on/off does not invent ₹
Safe-startEmit blocked when checklist false (28)

No pin to plant default without green required suites for that lockfile candidate.


CI / release gates (normative intent)#

PR → unit + contract + kernel golden
     → concurrency + lifecycle + fault injection (required for runtime PRs)
lockfile candidate → replay holdouts + pass^k
                  → shadow on plant
                  → canary
                  → plant owner accept (plant scope)
                  → pin

Soft-gate threshold PRs must attach opportunity-ledger evidence (22). Kernel PRs require ADR.


Observability SLOs (architecture-level)#

SLISLO intent (ops locks numbers)
P0/P1 queue waitBound for exception Findings
Case wall success (terminal or held, not infra fail)High % per latency tier
CardSink success after terminalizingNear-perfect with idempotent retry
Shift-sweep completion per shift≥ 1 successful enqueue+finish or alert
Stale PSM hard-limit withholdsAlert on spike (data path)
Infra fail ratePage; not soft-gate tune

Every case carries correlation_id through queue → ports → trace → CardSink. Metrics join on decision_case_id.

Abort vs withhold: infra abort increments infra fail SLI; semantic withhold increments gate_id counters only.


L4 store durability#

ConcernRule
What is durableCases, traces, opportunity ledger, case library, held proposals, PSM snapshots, control-plane audit
RPO / RTODeclared per deploy profile in ops runbook; architecture requires non-zero backup — no “disk is fine”
Replay corpusExport of frozen ledgers retained per policy for pass^k
Backup testRestore drill before first emit_enabled (28)
EncryptionAt rest and in transit; keys not in git

Compatibility and migrations#

  • PSMPlant Situation Model element builders: expand/contract with admission rule.
  • Gate idStable id of the hard or soft gate that blocked a candidate renames: alias table for one lockfile generation.
  • Dropping a soft gateThreshold in registry; calibrated from opportunity ledger + exploration: migrate ledger queries; never delete historical rows.

Rejected alternatives#

AlternativeWhy
“We’ll add tests after Pilot cards ship”Non-product
Pin without shadowFloor risk
Metrics without correlation idCannot debug multi-port cases
Single shared DB user across plantsTenancy hole

What would change this#

  • Suite runtime too slow for every PR → split required vs nightly; do not drop concurrency/lifecycle from release gate.
  • Multi-region → ADR for store replication and CardSink idempotency region.

v1 slice vs later#

v1Later
Suites + CI gates above; backup before emitAutomated canary scorecards in CI
SLO intents; ops locks numbersError budgets auto-block pins
Single-region durabilityHA topology

Change class#

SLO numbers: ops data. Removing a required suite from release gate: ADR.

Page history: last 4 changes
  1. 2026-10-07 docs(technical): rewrite l4 21-30, glossary and README; reconcile architecture gaps e7fead7
  2. 2026-10-03 docs(decisions): add ADR-033..038 (twin runtime, fast read path, plant-side writer, message classes, alerts and quality-to-lot link, part-keyed parameters), fast-loop technical set, rebuilt index with renumbering map; fix bare-number link text and ranges 22e2872
  3. 2026-10-03 docs(decisions): renumber live ADRs 001-032 in order, mark withdrawn refs ADR-W###, repoint withdrawn links to archive, note partial supersessions 36c944e
  4. 2026-09-25 docs(l4): agentic decision architecture, ADRs, and production hardness 8275e7c

Diagram

100%

Search the architecture