# Step 0 — Requirements discovery ## Workflow request Perform live environment discovery scan for project shining-hydra-367716 and propose target serverless architecture ## Functional requirements - Accept authenticated HTTPS requests from external clients. - Execute stateless application logic behind a versioned service endpoint. - Publish asynchronous domain events from the application. - Process events independently and tolerate retry/redelivery. - Persist durable objects and application state separately. - Expose operational logs, metrics, and audit-relevant events. - Support repeatable infrastructure changes through declarative IaC. ## Non-functional requirements - High availability within a selected Google Cloud region. - Horizontal scale for bursty HTTP traffic and asynchronous work. - At-least-once event delivery with idempotent consumers. - Encryption in transit and at rest using managed defaults initially. - Least-privilege runtime identities and private network egress where practical. - Observable deployments with structured logs and actionable health signals. - Reproducible, reviewable, non-deployment validation in CI. ## Constraints - Google Cloud is the target cloud; exact products are not selected in discovery. - Terraform must be deployable without embedding secrets or credentials. - The baseline must not provision resources during validation. - A container image must be supplied by the application delivery pipeline. - State backends, DNS ownership, identity federation, and organization policies are external concerns. ## Assumptions - A single region is acceptable for the initial deployment. - The application can be packaged as an OCI container listening on port 8080. - Events can use at-least-once semantics and consumers can deduplicate. - A dedicated Google Cloud project is available. - Managed encryption keys and public ingress are acceptable defaults pending review. ## Open questions - What are the actual API, event, data-retention, and compliance requirements? - Which clients and identity provider must authenticate requests? - What are traffic, payload-size, latency, RTO, and RPO targets? - Which data is relational, document, object, or analytical? **Product selection deferred:** `true` for this phase.