45 lines
2.2 KiB
Markdown
Executable File
45 lines
2.2 KiB
Markdown
Executable File
# Step 0 — Requirements discovery
|
|
|
|
## Workflow request
|
|
Create a high-scale containerized data ingestion pipeline with least-privilege IAM service accounts and automated validation.
|
|
|
|
## Functional requirements
|
|
- Accept authenticated HTTPS requests from external clients.
|
|
- Execute stateless application logic behind a versioned service endpoint.
|
|
- Publish asynchronous domain events from the application.
|
|
- Process events independently and tolerate retry/redelivery.
|
|
- Persist durable objects and application state separately.
|
|
- Expose operational logs, metrics, and audit-relevant events.
|
|
- Support repeatable infrastructure changes through declarative IaC.
|
|
|
|
## Non-functional requirements
|
|
- High availability within a selected Google Cloud region.
|
|
- Horizontal scale for bursty HTTP traffic and asynchronous work.
|
|
- At-least-once event delivery with idempotent consumers.
|
|
- Encryption in transit and at rest using managed defaults initially.
|
|
- Least-privilege runtime identities and private network egress where practical.
|
|
- Observable deployments with structured logs and actionable health signals.
|
|
- Reproducible, reviewable, non-deployment validation in CI.
|
|
|
|
## Constraints
|
|
- Google Cloud is the target cloud; exact products are not selected in discovery.
|
|
- Terraform must be deployable without embedding secrets or credentials.
|
|
- The baseline must not provision resources during validation.
|
|
- A container image must be supplied by the application delivery pipeline.
|
|
- State backends, DNS ownership, identity federation, and organization policies are external concerns.
|
|
|
|
## Assumptions
|
|
- A single region is acceptable for the initial deployment.
|
|
- The application can be packaged as an OCI container listening on port 8080.
|
|
- Events can use at-least-once semantics and consumers can deduplicate.
|
|
- A dedicated Google Cloud project is available.
|
|
- Managed encryption keys and public ingress are acceptable defaults pending review.
|
|
|
|
## Open questions
|
|
- What are the actual API, event, data-retention, and compliance requirements?
|
|
- Which clients and identity provider must authenticate requests?
|
|
- What are traffic, payload-size, latency, RTO, and RPO targets?
|
|
- Which data is relational, document, object, or analytical?
|
|
|
|
**Product selection deferred:** `true` for this phase.
|