49 lines
2.6 KiB
Markdown
49 lines
2.6 KiB
Markdown
# Step 0 — Requirements discovery
|
|
|
|
## Workflow request
|
|
No application-specific workflow request was supplied. This baseline therefore documents an event-driven HTTP application reference architecture and marks all product choices as deferred during discovery.
|
|
|
|
## Functional requirements
|
|
- Accept authenticated HTTPS requests from external clients.
|
|
- Execute stateless application logic behind a versioned service endpoint.
|
|
- Publish asynchronous domain events from the application.
|
|
- Process events independently and tolerate retry/redelivery.
|
|
- Persist durable objects and application state separately.
|
|
- Expose operational logs, metrics, and audit-relevant events.
|
|
- Support repeatable infrastructure changes through declarative IaC.
|
|
|
|
## Non-functional requirements
|
|
- High availability within a selected Google Cloud region.
|
|
- Horizontal scale for bursty HTTP traffic and asynchronous work.
|
|
- At-least-once event delivery with idempotent consumers.
|
|
- Encryption in transit and at rest using managed defaults initially.
|
|
- Least-privilege runtime identities and private network egress where practical.
|
|
- Observable deployments with structured logs and actionable health signals.
|
|
- Reproducible, reviewable, non-deployment validation in CI.
|
|
|
|
## Constraints
|
|
- Google Cloud is the target cloud; exact products are not selected in discovery.
|
|
- Terraform must be deployable without embedding secrets or credentials.
|
|
- The baseline must not provision resources during validation.
|
|
- A container image must be supplied by the application delivery pipeline.
|
|
- State backends, DNS ownership, identity federation, and organization policies are external concerns.
|
|
|
|
## Assumptions
|
|
- A single region is acceptable for the initial deployment.
|
|
- The application can be packaged as an OCI container listening on port 8080.
|
|
- Events can use at-least-once semantics and consumers can deduplicate.
|
|
- A dedicated Google Cloud project is available.
|
|
- Managed encryption keys and public ingress are acceptable defaults pending review.
|
|
|
|
## Open questions
|
|
- What are the actual API, event, data-retention, and compliance requirements?
|
|
- Which clients and identity provider must authenticate requests?
|
|
- What are traffic, payload-size, latency, RTO, and RPO targets?
|
|
- Which data is relational, document, object, or analytical?
|
|
- Should ingress be public, private, or protected by an enterprise edge?
|
|
- Are customer-managed keys, VPC Service Controls, or regional DR required?
|
|
- What image registry, CI identity, environment promotion, and rollback policy apply?
|
|
- What budget, quota, naming, tagging, and organization-policy constraints apply?
|
|
|
|
**Product selection deferred:** `true` for this phase.
|