Repository navigation
docs: define Applications and isolated Environments - #182
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe documentation now defines Applications as owners of Agent and Workflow definitions and Environments as runtime and isolation boundaries. It updates key, session, Conversation, Connection, consent, and policy definitions, adds ADR-0022, and marks ADR-0004 superseded. ChangesApplication and Environment model
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Merge Risk: ⚪ Minimal · up to This documentation clarifies which resources belong to Applications and Environments without changing runtime behavior. No concrete issue remains in the supplied review context, so it is ready to merge subject to normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The target model preserves production isolation, protected identity configuration, and human consent requirements. No introduced security weakness is established. Implementation is explicitly deferred, however, and authorization behavior during revocation, concurrent execution, and reset remains unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Comment |
|



Applications currently describe deployment environments, which conflicts with the intended product hierarchy. Record the accepted model: Applications own Agent and Workflow definitions; Development and Production Environments own deployed versions and runtime authority.
Update the domain glossary, supersede ADR 0004 with ADR 0022, and record shared Connection access/reviewer ownership and the permitted local reset boundary. This PR records the target model only; schema, API, SDK and UI implementation remain tracked in #181. It does not close that issue.
Validation: pnpm lint, pnpm typecheck and pnpm format:check passed. No database or runtime code changed.
Summary by CodeRabbit