Skip to content

Build Application ownership and isolated Environment deployments #183

Description

@rohittcodes

Parent

#181 — Applications as product containers with isolated Environments.

What to build

Operators can create an Application, author its Workflows, and configure separate Development and Production Environments. Each Environment selects the published Workflow versions it serves and supplies its own runtime keys, identity trust, Connections and runtime configuration. Public API, SDK and web management consistently distinguish product ownership from deployed authority. This is a wide organization refactor delivered as one integrated, verified branch; no customer compatibility layer is required.

Acceptance criteria

  • A new Application owns exactly its initial Development and Production Environments.
  • Workflows belong to an Application; listing, authoring, publishing and execution preserve that ownership across the API and web interface.
  • Each Environment selects an immutable published Workflow version independently; existing executions retain their starting version.
  • Keys, subjects' environment access, trust configuration, origins, provider policy, retention and runtime resources are scoped to the Environment.
  • Cross-workspace, cross-Application and cross-Environment access is rejected, including Development credentials attempting Production access.
  • Current personal Connection authorization, exact-action consent and revocation race guarantees continue to hold under Environment ownership.
  • Management UI, public protocol, generated contracts and SDK distinguish Application from Environment consistently; obsolete organization contracts are removed.
  • Fresh local initialization is verified against an explicitly identified isolated local database; unspecified hosted databases are never reset.
  • No Agent runtime placeholders are added; Application ownership is the foundation for the subsequent Agent feature.
  • Lint, typecheck, formatting, affected integration tests, generated contract checks and launch gates pass.

Blocked by

None (can start immediately). The accepted domain glossary is recorded by PR #182 and ADR 0022.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestready-for-agentSpec is complete and ready for an agent to pick up

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions