[{"data":1,"prerenderedAt":1787},["ShallowReactive",2],{"navigation":3,"/introduction/core-philosophy":879,"/introduction/core-philosophy-surround":1782},[4,22,45,115,156,187,214,235,264,295,318,361,389,418,436,470,491,534,548,571,632,670,693,757,850],{"title":5,"path":6,"stem":7,"children":8,"icon":11},"Introduction","/introduction","01.introduction/1.index",[9,12,17],{"title":10,"path":6,"stem":7,"icon":11},"What is Orkestia?","i-lucide-sparkles",{"title":13,"path":14,"stem":15,"icon":16},"Core Philosophy","/introduction/core-philosophy","01.introduction/2.core-philosophy","i-lucide-shield-check",{"title":18,"path":19,"stem":20,"icon":21},"Key Benefits","/introduction/key-benefits","01.introduction/3.key-benefits","i-lucide-trophy",{"title":23,"path":24,"stem":25,"children":26,"icon":29},"Getting Started","/getting-started","02.getting-started/1.index",[27,30,35,40],{"title":28,"path":24,"stem":25,"icon":29},"Quick Start","i-lucide-rocket",{"title":31,"path":32,"stem":33,"icon":34},"Architecture Overview","/getting-started/architecture-overview","02.getting-started/2.architecture-overview","i-lucide-layout-dashboard",{"title":36,"path":37,"stem":38,"icon":39},"Concepts at a Glance","/getting-started/concepts","02.getting-started/3.concepts","i-lucide-list",{"title":41,"path":42,"stem":43,"icon":44},"Connect an AI Assistant","/getting-started/connect-an-ai-assistant","02.getting-started/4.connect-an-ai-assistant","i-lucide-bot",{"title":46,"path":47,"stem":48,"children":49,"icon":51},"Core Concepts","/concepts","03.concepts/01.index",[50,52,57,62,67,71,76,81,86,91,96,100,105,110],{"title":46,"path":47,"stem":48,"icon":51},"i-lucide-book-open",{"title":53,"path":54,"stem":55,"icon":56},"Workflows","/concepts/workflows","03.concepts/02.workflows","i-lucide-workflow",{"title":58,"path":59,"stem":60,"icon":61},"DGI — Dialog Generative Interface","/concepts/dgi","03.concepts/03.dgi","i-lucide-brain",{"title":63,"path":64,"stem":65,"icon":66},"Staff & AI Workforce Governance","/concepts/staff-governance","03.concepts/04.staff-governance","i-lucide-users-round",{"title":68,"path":69,"stem":70,"icon":44},"Agents — the execution substrate","/concepts/agents-platform","03.concepts/05.agents-platform",{"title":72,"path":73,"stem":74,"icon":75},"Runners & Execution Environments","/concepts/runners","03.concepts/06.runners","i-lucide-server-cog",{"title":77,"path":78,"stem":79,"icon":80},"Lumen Observability","/concepts/lumen","03.concepts/07.lumen","i-lucide-activity",{"title":82,"path":83,"stem":84,"icon":85},"Identity & Multi-Tenancy","/concepts/identity-multi-tenancy","03.concepts/08.identity-multi-tenancy","i-lucide-users",{"title":87,"path":88,"stem":89,"icon":90},"Billing, Pricing & Seats","/concepts/billing-and-seats","03.concepts/09.billing-and-seats","i-lucide-credit-card",{"title":92,"path":93,"stem":94,"icon":95},"App Data","/concepts/appdata","03.concepts/10.appdata","i-lucide-database",{"title":97,"path":98,"stem":99,"icon":61},"Engram","/concepts/engram","03.concepts/11.engram",{"title":101,"path":102,"stem":103,"icon":104},"DevKit","/concepts/devkit","03.concepts/12.devkit","i-lucide-terminal",{"title":106,"path":107,"stem":108,"icon":109},"App Host","/concepts/app-host","03.concepts/13.app-host","i-lucide-globe",{"title":111,"path":112,"stem":113,"icon":114},"Agent Exchange","/concepts/agent-exchange","03.concepts/14.agent-exchange","i-lucide-landmark",{"title":116,"path":117,"stem":118,"children":119,"icon":121},"Guides","/guides","04.guides/1.index",[120,122,127,132,137,142,147,151],{"title":116,"path":117,"stem":118,"icon":121},"i-lucide-compass",{"title":123,"path":124,"stem":125,"icon":126},"Building with DGI","/guides/building-with-dgi","04.guides/2.building-with-dgi","i-lucide-brain-circuit",{"title":128,"path":129,"stem":130,"icon":131},"Creating & Exposing Virtual Workflows","/guides/virtual-workflows","04.guides/4.virtual-workflows","i-lucide-blocks",{"title":133,"path":134,"stem":135,"icon":136},"Runner Management & Provisioning","/guides/runner-management","04.guides/5.runner-management","i-lucide-server",{"title":138,"path":139,"stem":140,"icon":141},"Security & Compliance","/guides/security-and-compliance","04.guides/7.security-and-compliance","i-lucide-shield",{"title":143,"path":144,"stem":145,"icon":146},"Tickets & Software Delivery","/guides/tickets-and-software-delivery","04.guides/8.tickets-and-software-delivery","i-lucide-ticket",{"title":148,"path":149,"stem":150},"Orkestia for AI-driven cloud infrastructure automation","/guides/cloud-automation-alternatives","04.guides/9.cloud-automation-alternatives",{"title":152,"path":153,"stem":154,"icon":155},"Typed decisions with TypeSafe","/guides/typed-decisions-with-typesafe","04.guides/9.typed-decisions-with-typesafe","i-lucide-git-branch",{"title":157,"path":158,"stem":159,"children":160,"icon":162},"Reference","/reference","05.reference/1.index",[161,163,168,173,177,182],{"title":157,"path":158,"stem":159,"icon":162},"i-lucide-library",{"title":164,"path":165,"stem":166,"icon":167},"Workflow Types & Registry","/reference/workflow-types-registry","05.reference/2.workflow-types-registry","i-lucide-list-tree",{"title":169,"path":170,"stem":171,"icon":172},"MCP Integration","/reference/mcp-integration","05.reference/3.mcp-integration","i-lucide-plug-zap",{"title":174,"path":175,"stem":176,"icon":104},"API & Tooling","/reference/api-tooling","05.reference/4.api-tooling",{"title":178,"path":179,"stem":180,"icon":181},"Integrations Catalog","/reference/integrations-catalog","05.reference/6.integrations-catalog","i-lucide-plug",{"title":183,"path":184,"stem":185,"icon":186},"Platform Services","/reference/platform-services","05.reference/7.platform-services","i-lucide-boxes",{"title":188,"path":189,"stem":190,"children":191,"icon":193},"Advanced Topics","/advanced","06.advanced/1.index",[192,194,199,204,209],{"title":188,"path":189,"stem":190,"icon":193},"i-lucide-flask-conical",{"title":195,"path":196,"stem":197,"icon":198},"Hybrid AI + Deterministic Execution","/advanced/hybrid-execution-model","06.advanced/2.hybrid-execution-model","i-lucide-git-merge",{"title":200,"path":201,"stem":202,"icon":203},"Drift Detection & Self-Healing","/advanced/drift-detection-self-healing","06.advanced/3.drift-detection-self-healing","i-lucide-heart-pulse",{"title":205,"path":206,"stem":207,"icon":208},"Governance & Approvals","/advanced/governance-and-approvals","06.advanced/4.governance-and-approvals","i-lucide-scale",{"title":210,"path":211,"stem":212,"icon":213},"Cost & Performance Optimization","/advanced/cost-and-performance","06.advanced/5.cost-and-performance","i-lucide-zap",{"title":215,"path":216,"stem":217,"children":218,"icon":220},"Operations","/operations","07.operations/1.index",[219,221,225,230],{"title":215,"path":216,"stem":217,"icon":220},"i-lucide-settings-2",{"title":222,"path":223,"stem":224,"icon":186},"Deployment Models","/operations/deployment-models","07.operations/2.deployment-models",{"title":226,"path":227,"stem":228,"icon":229},"Monitoring & Debugging","/operations/monitoring-and-debugging","07.operations/3.monitoring-and-debugging","i-lucide-bug",{"title":231,"path":232,"stem":233,"icon":234},"Best Practices","/operations/best-practices","07.operations/4.best-practices","i-lucide-check-check",{"title":236,"path":237,"stem":238,"children":239,"icon":241},"AWS Connections","/aws-connections","08.aws-connections/1.index",[240,242,245,250,255,260],{"title":236,"path":237,"stem":238,"icon":241},"i-simple-icons-amazonaws",{"title":23,"path":243,"stem":244,"icon":29},"/aws-connections/getting-started","08.aws-connections/2.getting-started",{"title":246,"path":247,"stem":248,"icon":249},"Setup Methods","/aws-connections/setup-methods","08.aws-connections/3.setup-methods","i-lucide-wrench",{"title":251,"path":252,"stem":253,"icon":254},"Managing Connections","/aws-connections/managing-connections","08.aws-connections/4.managing-connections","i-lucide-settings",{"title":256,"path":257,"stem":258,"icon":259},"Security Best Practices","/aws-connections/security-best-practices","08.aws-connections/5.security-best-practices","i-lucide-lock",{"title":261,"path":262,"stem":263,"icon":229},"Troubleshooting","/aws-connections/troubleshooting","08.aws-connections/6.troubleshooting",{"title":265,"path":266,"stem":267,"children":268,"icon":270},"Cloud Connections","/cloud-connections","09.cloud-connections/1.index",[269,271,276,281,286,291],{"title":265,"path":266,"stem":267,"icon":270},"i-lucide-cable",{"title":272,"path":273,"stem":274,"icon":275},"Google Cloud (GCP)","/cloud-connections/gcp","09.cloud-connections/2.gcp","i-simple-icons-googlecloud",{"title":277,"path":278,"stem":279,"icon":280},"Microsoft Azure","/cloud-connections/azure","09.cloud-connections/3.azure","i-simple-icons-microsoftazure",{"title":282,"path":283,"stem":284,"icon":285},"Magalu Cloud","/cloud-connections/magalu","09.cloud-connections/4.magalu","i-lucide-cloud",{"title":287,"path":288,"stem":289,"icon":290},"Kubernetes","/cloud-connections/kubernetes","09.cloud-connections/5.kubernetes","i-simple-icons-kubernetes",{"title":292,"path":293,"stem":294,"icon":208},"TypeSafe","/cloud-connections/typesafe","09.cloud-connections/6.typesafe",{"title":296,"path":297,"stem":298,"children":299,"icon":136},"DNS Providers","/dns-providers","10.dns-providers/1.index",[300,302,305,308,311,315],{"title":301,"path":297,"stem":298,"icon":136},"DNS Provider Connections",{"title":23,"path":303,"stem":304,"icon":29},"/dns-providers/getting-started","10.dns-providers/2.getting-started",{"title":246,"path":306,"stem":307,"icon":249},"/dns-providers/setup-methods","10.dns-providers/3.setup-methods",{"title":251,"path":309,"stem":310,"icon":254},"/dns-providers/managing-connections","10.dns-providers/4.managing-connections",{"title":312,"path":313,"stem":314,"icon":39},"Zones and Records","/dns-providers/zones-and-records","10.dns-providers/5.zones-and-records",{"title":261,"path":316,"stem":317,"icon":229},"/dns-providers/troubleshooting","10.dns-providers/6.troubleshooting",{"title":319,"path":320,"stem":321,"children":322,"icon":29},"Cloud Deploy","/cloud-deploy","11.cloud-deploy/01.index",[323,324,327,332,336,341,345,349,354,358],{"title":319,"path":320,"stem":321,"icon":29},{"title":23,"path":325,"stem":326,"icon":29},"/cloud-deploy/getting-started","11.cloud-deploy/02.getting-started",{"title":328,"path":329,"stem":330,"icon":331},"Creating a Site","/cloud-deploy/creating-a-site","11.cloud-deploy/03.creating-a-site","i-lucide-plus-circle",{"title":333,"path":334,"stem":335,"icon":34},"Site Overview and Deployments","/cloud-deploy/site-overview","11.cloud-deploy/04.site-overview",{"title":337,"path":338,"stem":339,"icon":340},"Deployment Progress and Success","/cloud-deploy/deployment-progress","11.cloud-deploy/05.deployment-progress","i-lucide-loader",{"title":342,"path":343,"stem":344,"icon":254},"Settings","/cloud-deploy/settings","11.cloud-deploy/06.settings",{"title":346,"path":347,"stem":348,"icon":109},"Custom Domains","/cloud-deploy/custom-domains","11.cloud-deploy/07.custom-domains",{"title":350,"path":351,"stem":352,"icon":353},"Resources, Releases, and Danger Zone","/cloud-deploy/resources-releases","11.cloud-deploy/08.resources-releases","i-lucide-package",{"title":355,"path":356,"stem":357,"icon":141},"Admin Dashboard","/cloud-deploy/admin-dashboard","11.cloud-deploy/09.admin-dashboard",{"title":261,"path":359,"stem":360,"icon":229},"/cloud-deploy/troubleshooting","11.cloud-deploy/10.troubleshooting",{"title":362,"path":363,"stem":364,"children":365,"icon":368},"User Onboarding","/user-onboarding","12.user-onboarding/1.index",[366,369,372,377,382,386],{"title":367,"path":363,"stem":364,"icon":368},"User Creation and Onboarding","i-lucide-user-plus",{"title":23,"path":370,"stem":371,"icon":29},"/user-onboarding/getting-started","12.user-onboarding/2.getting-started",{"title":373,"path":374,"stem":375,"icon":376},"Creating Your Organization","/user-onboarding/onboarding","12.user-onboarding/3.onboarding","i-lucide-building-2",{"title":378,"path":379,"stem":380,"icon":381},"Invitations","/user-onboarding/invitations","12.user-onboarding/4.invitations","i-lucide-mail",{"title":383,"path":384,"stem":385,"icon":254},"Managing Your Account","/user-onboarding/managing-account","12.user-onboarding/5.managing-account",{"title":261,"path":387,"stem":388,"icon":229},"/user-onboarding/troubleshooting","12.user-onboarding/6.troubleshooting",{"title":342,"path":390,"stem":391,"children":392,"icon":394},"/settings","13.settings/1.index",[393,395,400,404,409,413],{"title":342,"path":390,"stem":391,"icon":394},"i-lucide-sliders-horizontal",{"title":396,"path":397,"stem":398,"icon":399},"General Settings","/settings/general","13.settings/2.general","i-lucide-user",{"title":401,"path":402,"stem":403,"icon":85},"Members Settings","/settings/members","13.settings/3.members",{"title":405,"path":406,"stem":407,"icon":408},"Notifications Settings","/settings/notifications","13.settings/4.notifications","i-lucide-bell",{"title":410,"path":411,"stem":412,"icon":141},"Security Settings","/settings/security","13.settings/5.security",{"title":414,"path":415,"stem":416,"icon":417},"Signing Keys","/settings/keys","13.settings/6.keys","i-lucide-key-round",{"title":419,"path":420,"stem":421,"children":422,"icon":29},"App Enablement","/app-enablement","14.app-enablement/1.index",[423,424,428,432],{"title":419,"path":420,"stem":421,"icon":29},{"title":425,"path":426,"stem":427,"icon":417},"Sign in with Orkestia","/app-enablement/sign-in-with-orkestia","14.app-enablement/2.sign-in-with-orkestia",{"title":429,"path":430,"stem":431,"icon":95},"End-user data","/app-enablement/end-user-data","14.app-enablement/3.end-user-data",{"title":433,"path":434,"stem":435,"icon":131},"Compositions — use, invoke, share","/app-enablement/compositions","14.app-enablement/4.compositions",{"title":437,"path":438,"stem":439,"children":440,"icon":80},"Lumen","/lumen","15.lumen/1.index",[441,442,447,452,457,461,465],{"title":437,"path":438,"stem":439,"icon":80},{"title":443,"path":444,"stem":445,"icon":446},"Enable Lumen","/lumen/enable","15.lumen/2.enable","i-lucide-power",{"title":448,"path":449,"stem":450,"icon":451},"Send data","/lumen/send-data","15.lumen/3.send-data","i-lucide-upload",{"title":453,"path":454,"stem":455,"icon":456},"Collector","/lumen/collector","15.lumen/4.collector","i-lucide-container",{"title":458,"path":459,"stem":460,"icon":34},"Use Lumen","/lumen/observe","15.lumen/5.observe",{"title":462,"path":463,"stem":464,"icon":44},"Lumen MCP","/lumen/mcp","15.lumen/6.mcp",{"title":466,"path":467,"stem":468,"icon":469},"Query API","/lumen/query-api","15.lumen/7.query-api","i-lucide-search",{"title":471,"path":472,"stem":473,"children":474,"icon":476},"SDKs","/sdks","16.sdks/1.index",[475,477,482,487],{"title":471,"path":472,"stem":473,"icon":476},"i-lucide-code",{"title":478,"path":479,"stem":480,"icon":481},"Workflows SDK — Node / TypeScript","/sdks/workflows-nodejs","16.sdks/2.workflows-nodejs","i-lucide-file-ts",{"title":483,"path":484,"stem":485,"icon":486},"Workflows SDK — Python","/sdks/workflows-python","16.sdks/3.workflows-python","i-simple-icons-python",{"title":488,"path":489,"stem":490,"icon":417},"Auth SDK — Sign in with Orkestia","/sdks/auth","16.sdks/4.auth",{"title":92,"path":492,"stem":493,"children":494,"icon":95},"/appdata","17.appdata/1.index",[495,496,501,506,510,515,520,525,530],{"title":92,"path":492,"stem":493,"icon":95},{"title":497,"path":498,"stem":499,"icon":500},"Declare structures","/appdata/declare","17.appdata/2.declare","i-lucide-table",{"title":502,"path":503,"stem":504,"icon":505},"Records & Data API","/appdata/data-api","17.appdata/3.data-api","i-lucide-rows-3",{"title":507,"path":508,"stem":509,"icon":376},"Ownership & workspaces","/appdata/ownership","17.appdata/4.ownership",{"title":511,"path":512,"stem":513,"icon":514},"Expose App Data to end-users","/appdata/expose","17.appdata/5.expose","i-lucide-app-window",{"title":516,"path":517,"stem":518,"icon":519},"PostgREST HTTP","/appdata/postgrest","17.appdata/6.postgrest","i-lucide-unplug",{"title":521,"path":522,"stem":523,"icon":524},"Ordered append","/appdata/append","17.appdata/7.append","i-lucide-list-ordered",{"title":526,"path":527,"stem":528,"icon":529},"Databases and instances","/appdata/instances","17.appdata/8.instances","i-lucide-hard-drive",{"title":531,"path":532,"stem":533,"icon":104},"Query console and SQL","/appdata/query","17.appdata/9.query",{"title":97,"path":535,"stem":536,"children":537,"icon":61},"/engram","18.engram/1.index",[538,539,543],{"title":97,"path":535,"stem":536,"icon":61},{"title":540,"path":541,"stem":542,"icon":155},"Write & recall","/engram/write-recall","18.engram/2.write-recall",{"title":544,"path":545,"stem":546,"icon":547},"Field & feed","/engram/agent-memory","18.engram/3.agent-memory","i-lucide-radio",{"title":101,"path":549,"stem":550,"children":551,"icon":104},"/devkit","19.devkit/1.index",[552,553,558,562,567],{"title":101,"path":549,"stem":550,"icon":104},{"title":554,"path":555,"stem":556,"icon":557},"Install DevKit","/devkit/install","19.devkit/2.install","i-lucide-download",{"title":559,"path":560,"stem":561,"icon":519},"Hook redirect","/devkit/hooks","19.devkit/3.hooks",{"title":563,"path":564,"stem":565,"icon":566},"Local coding runner","/devkit/local-runner","19.devkit/4.local-runner","i-lucide-cpu",{"title":568,"path":569,"stem":570,"icon":131},"Compositions from DevKit","/devkit/compositions","19.devkit/5.compositions",{"title":572,"path":573,"stem":574,"children":575,"icon":44},"Staff & Agents","/staff-and-agents","20.staff-and-agents/01.index",[576,577,582,586,590,594,598,602,606,611,615,620,625,629],{"title":572,"path":573,"stem":574,"icon":44},{"title":578,"path":579,"stem":580,"icon":581},"Prerequisites","/staff-and-agents/prerequisites","20.staff-and-agents/02.prerequisites","i-lucide-list-checks",{"title":583,"path":584,"stem":585,"icon":368},"Hire an actor","/staff-and-agents/hire-an-actor","20.staff-and-agents/03.hire-an-actor",{"title":587,"path":588,"stem":589,"icon":34},"Console","/staff-and-agents/console","20.staff-and-agents/04.console",{"title":591,"path":592,"stem":593,"icon":11},"Configs, skills, and MCP","/staff-and-agents/configs-skills-mcp","20.staff-and-agents/05.configs-skills-mcp",{"title":595,"path":596,"stem":597,"icon":136},"Agent runner groups","/staff-and-agents/runner-groups","20.staff-and-agents/06.runner-groups",{"title":599,"path":600,"stem":601,"icon":16},"Governance","/staff-and-agents/governance","20.staff-and-agents/07.governance",{"title":603,"path":604,"stem":605,"icon":417},"Identity and tokens","/staff-and-agents/identity","20.staff-and-agents/08.identity",{"title":607,"path":608,"stem":609,"icon":610},"Memory and cost","/staff-and-agents/memory-and-cost","20.staff-and-agents/09.memory-and-cost","i-lucide-wallet",{"title":612,"path":613,"stem":614,"icon":155},"Coding agents","/staff-and-agents/coding-agents","20.staff-and-agents/10.coding-agents",{"title":616,"path":617,"stem":618,"icon":619},"Wire a repository for coding agents","/staff-and-agents/wire-a-repository","20.staff-and-agents/11.wire-a-repository","i-lucide-link",{"title":621,"path":622,"stem":623,"icon":624},"Run a ticket end to end","/staff-and-agents/run-a-ticket","20.staff-and-agents/12.run-a-ticket","i-lucide-play",{"title":626,"path":627,"stem":628,"icon":66},"Build a product team of actors","/staff-and-agents/build-a-product-team","20.staff-and-agents/13.build-a-product-team",{"title":261,"path":630,"stem":631,"icon":249},"/staff-and-agents/troubleshooting","20.staff-and-agents/14.troubleshooting",{"title":106,"path":633,"stem":634,"children":635,"icon":109},"/app-host","21.app-host/1.index",[636,637,641,644,649,653,658,662,666],{"title":106,"path":633,"stem":634,"icon":109},{"title":638,"path":639,"stem":640,"icon":514},"Your app and site","/app-host/your-app","21.app-host/2.your-app",{"title":92,"path":642,"stem":643,"icon":95},"/app-host/app-data","21.app-host/3.app-data",{"title":645,"path":646,"stem":647,"icon":648},"Website and process","/app-host/hosting","21.app-host/4.hosting","i-lucide-cloud-upload",{"title":650,"path":651,"stem":652,"icon":547},"Buzz","/app-host/buzz","21.app-host/5.buzz",{"title":654,"path":655,"stem":656,"icon":657},"Files","/app-host/files","21.app-host/6.files","i-lucide-folder",{"title":659,"path":660,"stem":661,"icon":109},"Your own domain","/app-host/your-domain","21.app-host/7.your-domain",{"title":663,"path":664,"stem":665,"icon":229},"Troubleshooting App Host","/app-host/troubleshooting","21.app-host/8.troubleshooting",{"title":667,"path":668,"stem":669,"icon":417},"Signing keys","/app-host/signing-keys","21.app-host/9.signing-keys",{"title":111,"path":671,"stem":672,"children":673,"icon":114},"/agent-exchange","22.agent-exchange/01.index",[674,675,678,682,686,690],{"title":111,"path":671,"stem":672,"icon":114},{"title":583,"path":676,"stem":677,"icon":368},"/agent-exchange/hire","22.agent-exchange/02.hire",{"title":679,"path":680,"stem":681,"icon":208},"List an actor","/agent-exchange/list","22.agent-exchange/03.list",{"title":683,"path":684,"stem":685,"icon":104},"Invoke & leases","/agent-exchange/invoke","22.agent-exchange/04.invoke",{"title":687,"path":688,"stem":689,"icon":141},"Settlement & trust","/agent-exchange/settlement","22.agent-exchange/05.settlement",{"title":53,"path":691,"stem":692,"icon":56},"/agent-exchange/workflows","22.agent-exchange/06.workflows",{"title":694,"path":695,"stem":696,"children":697,"icon":75},"Runners","/runners","23.runners/1.index",[698,700,704,709,713,717,721,726,730,734,738,741,745,749,753],{"title":699,"path":695,"stem":696,"icon":75},"Runner groups",{"title":701,"path":702,"stem":703,"icon":275},"Cloud Run","/runners/cloud-run","23.runners/10.cloud-run",{"title":705,"path":706,"stem":707,"icon":708},"DigitalOcean App Job","/runners/do-app-job","23.runners/11.do-app-job","i-simple-icons-digitalocean",{"title":710,"path":711,"stem":712,"icon":708},"DigitalOcean Droplet","/runners/do-droplet","23.runners/12.do-droplet",{"title":714,"path":715,"stem":716,"icon":285},"Magalu Cloud VM","/runners/magalu-vm","23.runners/13.magalu-vm",{"title":101,"path":718,"stem":719,"icon":720},"/runners/devkit","23.runners/14.devkit","i-lucide-laptop",{"title":722,"path":723,"stem":724,"icon":725},"Purposes & integrations","/runners/purposes","23.runners/16.purposes","i-lucide-layers",{"title":727,"path":728,"stem":729,"icon":241},"Fargate","/runners/fargate","23.runners/2.fargate",{"title":731,"path":732,"stem":733,"icon":241},"EC2 Auto Scaling","/runners/ec2-auto-scaling","23.runners/3.ec2-auto-scaling",{"title":735,"path":736,"stem":737,"icon":241},"EC2 VM","/runners/ec2-vm","23.runners/4.ec2-vm",{"title":287,"path":739,"stem":740,"icon":290},"/runners/kubernetes","23.runners/5.kubernetes",{"title":742,"path":743,"stem":744,"icon":280},"Azure Container Apps","/runners/azure-container-apps","23.runners/6.azure-container-apps",{"title":746,"path":747,"stem":748,"icon":280},"Azure VMSS","/runners/azure-vmss","23.runners/7.azure-vmss",{"title":750,"path":751,"stem":752,"icon":280},"Azure VM","/runners/azure-vm","23.runners/8.azure-vm",{"title":754,"path":755,"stem":756,"icon":275},"GCE","/runners/gce","23.runners/9.gce",{"title":758,"path":759,"stem":760,"children":761,"icon":763},"Chat","/chat","24.chat/01.index",[762,764,768,773,777,782,787,791,796,800,805,810,814,819,824,828,832,836,840,845],{"title":758,"path":759,"stem":760,"icon":763},"i-lucide-messages-square",{"title":765,"path":766,"stem":767,"icon":446},"Enable and publish","/chat/enable-and-publish","24.chat/02.enable-and-publish",{"title":769,"path":770,"stem":771,"icon":772},"Theme and customization","/chat/theme-and-customization","24.chat/03.theme-and-customization","i-lucide-palette",{"title":774,"path":775,"stem":776,"icon":85},"Members and moderation","/chat/members-and-moderation","24.chat/04.members-and-moderation",{"title":778,"path":779,"stem":780,"icon":781},"Channels","/chat/channels","24.chat/05.channels","i-lucide-hash",{"title":783,"path":784,"stem":785,"icon":786},"Using the chat","/chat/using-the-chat","24.chat/06.using-the-chat","i-lucide-message-circle",{"title":788,"path":789,"stem":790,"icon":44},"Actors in chat","/chat/actors-in-chat","24.chat/07.actors-in-chat",{"title":792,"path":793,"stem":794,"icon":795},"Internal support actor","/chat/internal-support-actor","24.chat/08.internal-support-actor","i-lucide-life-buoy",{"title":797,"path":798,"stem":799,"icon":104},"API and console","/chat/api-and-console","24.chat/09.api-and-console",{"title":801,"path":802,"stem":803,"icon":804},"Limits","/chat/limits","24.chat/10.limits","i-lucide-triangle-alert",{"title":806,"path":807,"stem":808,"icon":809},"Structured chat with DGI","/chat/structured-chat","24.chat/11.structured-chat","i-lucide-layout-list",{"title":811,"path":812,"stem":813,"icon":109},"Option A: hosted chat with DGI","/chat/option-a-hosted-chat","24.chat/12.option-a-hosted-chat",{"title":815,"path":816,"stem":817,"icon":818},"Option B: embed the chat component","/chat/option-b-embed-component","24.chat/13.option-b-embed-component","i-lucide-component",{"title":820,"path":821,"stem":822,"icon":823},"Option C: custom client (wire contract)","/chat/option-c-custom-client","24.chat/14.option-c-custom-client","i-lucide-braces",{"title":825,"path":826,"stem":827,"icon":394},"Responder configuration reference","/chat/responder-reference","24.chat/15.responder-reference",{"title":829,"path":830,"stem":831,"icon":547},"Cards, live updates and proactive posts","/chat/cards-live-and-proactive","24.chat/16.cards-live-and-proactive",{"title":833,"path":834,"stem":835,"icon":16},"Structured chat security model","/chat/structured-chat-security","24.chat/17.structured-chat-security",{"title":837,"path":838,"stem":839,"icon":181},"Option D: any app or API (dgi.chat)","/chat/option-d-chat-api","24.chat/18.option-d-chat-api",{"title":841,"path":842,"stem":843,"icon":844},"Card catalog","/chat/card-catalog","24.chat/19.card-catalog","i-lucide-layout-grid",{"title":846,"path":847,"stem":848,"icon":849},"Living Surfaces","/chat/living-surfaces","24.chat/20.living-surfaces","i-lucide-sprout",{"title":851,"path":852,"stem":853,"children":854,"icon":61},"DGI","/dgi","25.dgi/1.index",[855,857,862,866,870,874],{"title":856,"path":852,"stem":853,"icon":61},"What is DGI",{"title":858,"path":859,"stem":860,"icon":861},"How DGI works","/dgi/how-it-works","25.dgi/2.how-it-works","i-lucide-cog",{"title":863,"path":864,"stem":865,"icon":844},"Interfaces","/dgi/interfaces","25.dgi/3.interfaces",{"title":867,"path":868,"stem":869,"icon":29},"Quickstart","/dgi/quickstart","25.dgi/4.quickstart",{"title":871,"path":872,"stem":873,"icon":16},"Trust and safety","/dgi/trust-and-safety","25.dgi/5.trust-and-safety",{"title":875,"path":876,"stem":877,"icon":878},"FAQ","/dgi/faq","25.dgi/6.faq","i-lucide-circle-help",{"id":880,"title":13,"body":881,"description":1775,"extension":1776,"links":1777,"meta":1778,"navigation":1779,"path":14,"seo":1780,"stem":15,"__hash__":1781},"docs/01.introduction/2.core-philosophy.md",{"type":882,"value":883,"toc":1753},"minimark",[884,889,931,939,961,965,976,981,997,1056,1063,1214,1220,1224,1289,1292,1296,1312,1316,1342,1359,1363,1366,1418,1422,1433,1439,1454,1458,1468,1471,1504,1510,1514,1520,1533,1537,1541,1551,1554,1580,1584,1620,1627,1631,1640,1644,1719,1723,1749],[885,886,888],"h2",{"id":887},"tldr","TL;DR",[890,891,892,900,906,912],"ul",{},[893,894,895,899],"li",{},[896,897,898],"strong",{},"Pillar 1, Zero Code Custody."," Orkestia never holds your source code or your data plane. It holds only the scoped credentials you grant it, encrypted at rest and revocable by you. On AWS that is a role trust with no static keys.",[893,901,902,905],{},[896,903,904],{},"Pillar 2, AI-first but deterministic."," AI designs the plan (through DGI or an assistant over MCP). The plan compiles into a composition that runs identically every time, with no model in the hot path.",[893,907,908,911],{},[896,909,910],{},"Pillar 3, Customer-owned execution."," Compute, resources, and data live in your account, under your IAM and your audit trail.",[893,913,914,917,918,922,923,926,927,930],{},[896,915,916],{},"One sentence:"," Orkestia knows ",[919,920,921],"em",{},"what"," should happen and ",[919,924,925],{},"what did"," happen. It never takes custody of the ",[919,928,929],{},"doing",".",[932,933,934,935,938],"p",{},"Orkestia is built on one premise: ",[896,936,937],{},"you should be able to orchestrate your cloud and automate your operations without handing a third party custody of your code, your data, or your compute."," Every architectural decision below follows from that.",[940,941,942,949,955],"card-group",{},[943,944,946],"card",{"icon":259,"title":945},"Zero Code Custody",[932,947,948],{},"Execution happens in your account under credentials you grant and can revoke. Orkestia stores workflow state, observability data, and those scoped credentials, encrypted. Never your code or your data.",[943,950,952],{"icon":126,"title":951},"AI-first, deterministic execution",[932,953,954],{},"AI designs workflows. Designs compile into deterministic compositions. Creativity at design time, reproducibility at run time.",[943,956,958],{"icon":136,"title":957},"Customer-owned execution",[932,959,960],{},"Compute, data, and provisioned resources live in your account. Orkestia orchestrates; you own.",[885,962,964],{"id":963},"pillar-1-zero-code-custody","Pillar 1: Zero Code Custody",[932,966,967,968,971,972,975],{},"The reference integration is the AWS ",[896,969,970],{},"cross-account role trust",", not a credential upload. You run a bootstrap template (CloudFormation or Terraform, provided during connection setup) in your own account. It creates a role Orkestia can assume. Nothing else changes hands. Other providers (GCP, Azure, Kubernetes, Cloudflare, and the rest) do not offer that trust model, so for them you create a ",[896,973,974],{},"scoped key or token"," and Orkestia stores it encrypted; the section below covers both cases.",[977,978,980],"h3",{"id":979},"how-it-works","How it works",[932,982,983,984,988,989,992,993,996],{},"When a workflow needs to touch your AWS account, the engine calls ",[985,986,987],"code",{},"sts:AssumeRole"," against your role, gated by a per-organization ",[896,990,991],{},"external ID"," in the trust policy. The result is a set of ",[896,994,995],{},"short-lived session credentials"," (about one hour), minted per run and never cached across runs.",[998,999,1004],"pre",{"className":1000,"code":1001,"language":1002,"meta":1003,"style":1003},"language-mermaid shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","sequenceDiagram\n    participant Eng as Orkestia workflow engine\n    participant STS as AWS STS (your account)\n    participant Res as Your AWS resources\n    Eng->>STS: AssumeRole(role_arn, external_id)\n    STS-->>Eng: short-lived session credentials (~1h)\n    Eng->>Res: provision / read using session creds\n    Note over Eng,Res: credentials expire; nothing is cached across runs\n","mermaid","",[985,1005,1006,1014,1020,1026,1032,1038,1044,1050],{"__ignoreMap":1003},[1007,1008,1011],"span",{"class":1009,"line":1010},"line",1,[1007,1012,1013],{},"sequenceDiagram\n",[1007,1015,1017],{"class":1009,"line":1016},2,[1007,1018,1019],{},"    participant Eng as Orkestia workflow engine\n",[1007,1021,1023],{"class":1009,"line":1022},3,[1007,1024,1025],{},"    participant STS as AWS STS (your account)\n",[1007,1027,1029],{"class":1009,"line":1028},4,[1007,1030,1031],{},"    participant Res as Your AWS resources\n",[1007,1033,1035],{"class":1009,"line":1034},5,[1007,1036,1037],{},"    Eng->>STS: AssumeRole(role_arn, external_id)\n",[1007,1039,1041],{"class":1009,"line":1040},6,[1007,1042,1043],{},"    STS-->>Eng: short-lived session credentials (~1h)\n",[1007,1045,1047],{"class":1009,"line":1046},7,[1007,1048,1049],{},"    Eng->>Res: provision / read using session creds\n",[1007,1051,1053],{"class":1009,"line":1052},8,[1007,1054,1055],{},"    Note over Eng,Res: credentials expire; nothing is cached across runs\n",[932,1057,1058,1059,1062],{},"The trust policy is the whole security boundary, and it lives in ",[896,1060,1061],{},"your"," account:",[998,1064,1068],{"className":1065,"code":1066,"language":1067,"meta":1003,"style":1003},"language-json shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","{\n  \"Effect\": \"Allow\",\n  \"Principal\": { \"AWS\": \"arn:aws:iam::\u003Corkestia-account>:root\" },\n  \"Action\": \"sts:AssumeRole\",\n  \"Condition\": {\n    \"StringEquals\": { \"sts:ExternalId\": \"\u003Cper-org-secret>\" }\n  }\n}\n","json",[985,1069,1070,1076,1103,1137,1156,1170,1204,1209],{"__ignoreMap":1003},[1007,1071,1072],{"class":1009,"line":1010},[1007,1073,1075],{"class":1074},"sMK4o","{\n",[1007,1077,1078,1081,1085,1088,1091,1094,1098,1100],{"class":1009,"line":1016},[1007,1079,1080],{"class":1074},"  \"",[1007,1082,1084],{"class":1083},"spNyl","Effect",[1007,1086,1087],{"class":1074},"\"",[1007,1089,1090],{"class":1074},":",[1007,1092,1093],{"class":1074}," \"",[1007,1095,1097],{"class":1096},"sfazB","Allow",[1007,1099,1087],{"class":1074},[1007,1101,1102],{"class":1074},",\n",[1007,1104,1105,1107,1110,1112,1114,1117,1119,1123,1125,1127,1129,1132,1134],{"class":1009,"line":1022},[1007,1106,1080],{"class":1074},[1007,1108,1109],{"class":1083},"Principal",[1007,1111,1087],{"class":1074},[1007,1113,1090],{"class":1074},[1007,1115,1116],{"class":1074}," {",[1007,1118,1093],{"class":1074},[1007,1120,1122],{"class":1121},"sBMFI","AWS",[1007,1124,1087],{"class":1074},[1007,1126,1090],{"class":1074},[1007,1128,1093],{"class":1074},[1007,1130,1131],{"class":1096},"arn:aws:iam::\u003Corkestia-account>:root",[1007,1133,1087],{"class":1074},[1007,1135,1136],{"class":1074}," },\n",[1007,1138,1139,1141,1144,1146,1148,1150,1152,1154],{"class":1009,"line":1028},[1007,1140,1080],{"class":1074},[1007,1142,1143],{"class":1083},"Action",[1007,1145,1087],{"class":1074},[1007,1147,1090],{"class":1074},[1007,1149,1093],{"class":1074},[1007,1151,987],{"class":1096},[1007,1153,1087],{"class":1074},[1007,1155,1102],{"class":1074},[1007,1157,1158,1160,1163,1165,1167],{"class":1009,"line":1034},[1007,1159,1080],{"class":1074},[1007,1161,1162],{"class":1083},"Condition",[1007,1164,1087],{"class":1074},[1007,1166,1090],{"class":1074},[1007,1168,1169],{"class":1074}," {\n",[1007,1171,1172,1175,1178,1180,1182,1184,1186,1190,1192,1194,1196,1199,1201],{"class":1009,"line":1040},[1007,1173,1174],{"class":1074},"    \"",[1007,1176,1177],{"class":1121},"StringEquals",[1007,1179,1087],{"class":1074},[1007,1181,1090],{"class":1074},[1007,1183,1116],{"class":1074},[1007,1185,1093],{"class":1074},[1007,1187,1189],{"class":1188},"sbssI","sts:ExternalId",[1007,1191,1087],{"class":1074},[1007,1193,1090],{"class":1074},[1007,1195,1093],{"class":1074},[1007,1197,1198],{"class":1096},"\u003Cper-org-secret>",[1007,1200,1087],{"class":1074},[1007,1202,1203],{"class":1074}," }\n",[1007,1205,1206],{"class":1009,"line":1046},[1007,1207,1208],{"class":1074},"  }\n",[1007,1210,1211],{"class":1009,"line":1052},[1007,1212,1213],{"class":1074},"}\n",[1215,1216,1217],"note",{},[932,1218,1219],{},"The external ID is a per-organization secret pinned in the trust policy. A leaked role ARN alone is not enough to assume the role. The same AWS account can be linked under several orgs, each with its own external ID, so blast radius is contained per tenant.",[977,1221,1223],{"id":1222},"what-orkestia-stores-and-what-it-never-stores","What Orkestia stores, and what it never stores",[1225,1226,1227,1240],"table",{},[1228,1229,1230],"thead",{},[1231,1232,1233,1237],"tr",{},[1234,1235,1236],"th",{},"Orkestia stores",[1234,1238,1239],{},"Orkestia never stores",[1241,1242,1243,1256,1268,1278],"tbody",{},[1231,1244,1245,1253],{},[1246,1247,1248,1249,1252],"td",{},"Workflow ",[896,1250,1251],{},"state"," (event-sourced transitions)",[1246,1254,1255],{},"Your source code",[1231,1257,1258,1265],{},[1246,1259,1260,1261,1264],{},"The ",[896,1262,1263],{},"plan"," (workflow definitions and DAGs)",[1246,1266,1267],{},"Your databases and the customer data your workflows process",[1231,1269,1270,1275],{},[1246,1271,1272,1274],{},[896,1273,437],{}," telemetry you chose to send",[1246,1276,1277],{},"Long-lived AWS access keys",[1231,1279,1280,1286],{},[1246,1281,1282,1285],{},[896,1283,1284],{},"Connection credentials you grant",", encrypted at rest: on AWS a role ARN plus external ID; on other providers the scoped key or token you created (GCP service-account key, Azure client secret, Kubernetes service-account token, Cloudflare or Vercel API token)",[1246,1287,1288],{},"Your application's environment material or runtime secrets",[932,1290,1291],{},"Orkestia is not a general secrets manager. It stores only the credential each connection needs, encrypted, and never surfaces it back to the console, the API, or an AI assistant after creation. Every credential is scoped by you and revocable from your side: rotate the token or delete the service account and the connection fails closed. It never writes to your IAM: roles and permissions are created and changed only by you, in your account.",[977,1293,1295],{"id":1294},"the-same-rule-applies-to-ai-assistants","The same rule applies to AI assistants",[932,1297,1298,1299,1302,1303,1306,1307,1311],{},"When an assistant connected over MCP needs a connection that does not exist yet, it does not ask you for keys. It calls ",[985,1300,1301],{},"get_workflow_prerequisites"," and receives a setup guide with Orkestia's principal already filled in. You create the role in your account. The assistant only ever receives the role ARN and external ID that the workflow schema declares as inputs. Read ",[985,1304,1305],{},"rule://prerequisites-first"," on the server or the ",[1308,1309,1310],"a",{"href":170},"MCP integration"," page.",[977,1313,1315],{"id":1314},"why-it-matters","Why it matters",[890,1317,1318,1324,1330,1336],{},[893,1319,1320,1323],{},[896,1321,1322],{},"Privacy."," Your code and data never transit or rest on Orkestia infrastructure.",[893,1325,1326,1329],{},[896,1327,1328],{},"Compliance."," Actions happen under your IAM principal, in your CloudTrail, inside your compliance boundary.",[893,1331,1332,1335],{},[896,1333,1334],{},"Trust under breach."," On AWS there are no static keys, only short-lived sessions. On other providers the stored credential is scoped to what you granted and encrypted at rest. Revocation is always unilateral: delete the role, rotate the token, or remove the service account, and the connection fails closed. It is marked degraded and dependent workflows fail with a clear reason.",[893,1337,1338,1341],{},[896,1339,1340],{},"Least privilege."," The permissions pack is scoped to the apps you subscribe to. Adding capability is an explicit re-bootstrap or re-grant, never a silent privilege grab.",[1343,1344,1345],"tip",{},[932,1346,1347,1348,1351,1352,1355,1356,930],{},"The AWS connection is the reference shape. GCP, Azure, Magalu Cloud, DigitalOcean, and Kubernetes follow the same \"customer holds the trust, Orkestia holds only the plan\" model. See ",[1308,1349,1350],{"href":237},"AWS connections",", ",[1308,1353,1354],{"href":266},"Cloud connections",", and ",[1308,1357,1358],{"href":297},"DNS providers",[885,1360,1362],{"id":1361},"pillar-2-ai-first-but-deterministic","Pillar 2: AI-first, but deterministic",[932,1364,1365],{},"Orkestia refuses the false choice between \"smart but unpredictable\" and \"reliable but rigid\". It separates the two phases of automation:",[1225,1367,1368,1384],{},[1228,1369,1370],{},[1231,1371,1372,1375,1378,1381],{},[1234,1373,1374],{},"Phase",[1234,1376,1377],{},"Who or what",[1234,1379,1380],{},"Property you want",[1234,1382,1383],{},"What you get",[1241,1385,1386,1402],{},[1231,1387,1388,1393,1396,1399],{},[1246,1389,1390],{},[896,1391,1392],{},"Design time",[1246,1394,1395],{},"DGI, or an assistant over MCP",[1246,1397,1398],{},"Creativity, exploration, natural language",[1246,1400,1401],{},"A proposed workflow or composition",[1231,1403,1404,1409,1412,1415],{},[1246,1405,1406],{},[896,1407,1408],{},"Run time",[1246,1410,1411],{},"The compiled composition on the engine",[1246,1413,1414],{},"Reproducibility, auditability, speed",[1246,1416,1417],{},"The same deterministic execution every run",[977,1419,1421],{"id":1420},"ai-designs-compiled-workflows-execute","AI designs, compiled workflows execute",[932,1423,1424,1425,1428,1429,1432],{},"You describe an outcome in plain language. The AI reasons over the catalog of registered capabilities and assembles a plan. That plan is ",[896,1426,1427],{},"not"," what runs in production. It compiles into a deterministic ",[896,1430,1431],{},"composition",": a DAG of atomic, versioned operations that executes identically every time.",[1434,1435],"dag-diagram",{":edges":1436,":nodes":1437,"direction":1438},"[{\"from\":\"NL\",\"to\":\"AI\"},{\"from\":\"AI\",\"to\":\"VW\"},{\"from\":\"VW\",\"to\":\"ENG\"},{\"from\":\"ENG\",\"to\":\"R1\"},{\"from\":\"ENG\",\"to\":\"R2\"},{\"from\":\"ENG\",\"to\":\"R3\"}]","[{\"id\":\"NL\",\"label\":\"Natural-language intent\",\"kind\":\"start\"},{\"id\":\"AI\",\"label\":\"AI reasoning\",\"sub\":\"DGI or assistant over MCP\",\"kind\":\"ai\"},{\"id\":\"VW\",\"label\":\"Composition\",\"sub\":\"virtual workflow DAG\"},{\"id\":\"ENG\",\"label\":\"Workflow engine\",\"sub\":\"deterministic run time\",\"kind\":\"engine\"},{\"id\":\"R1\",\"label\":\"atomic op\"},{\"id\":\"R2\",\"label\":\"atomic op\"},{\"id\":\"R3\",\"label\":\"atomic op\"}]","LR",[932,1440,1441,1442,1445,1446,1449,1450,1453],{},"Every atomic workflow follows the platform's ",[896,1443,1444],{},"3-state pattern"," (",[985,1447,1448],{},"PENDING → COMPLETED | FAILED",") with strict input and output schemas, per-run concurrency locks, and an event-sourced state machine. An assistant that ",[919,1451,1452],{},"runs"," capabilities over MCP invokes the same validated workflows everyone else does. It cannot improvise against your production cloud.",[977,1455,1457],{"id":1456},"grounding-the-ai-may-only-say-what-it-can-see","Grounding: the AI may only say what it can see",[932,1459,1460,1461,1464,1465],{},"The MCP server publishes a ",[985,1462,1463],{},"rule://grounding"," resource. It tells an assistant to describe Orkestia only from tool results: the catalog, schemas, and run history. A registered type is a capability, not evidence of a production run. A catalog total is a capability count, not \"N production workflows\". This is the design-time version of the same discipline: ",[896,1466,1467],{},"the AI proposes from what is declared, and the engine decides what actually happens.",[977,1469,1315],{"id":1470},"why-it-matters-1",[890,1472,1473,1479,1488,1494],{},[893,1474,1475,1478],{},[896,1476,1477],{},"Reproducibility."," The same composition produces the same execution. Diff two runs and the difference is your inputs.",[893,1480,1481,1484,1485,930],{},[896,1482,1483],{},"Auditability."," Every run is an event-sourced sequence of typed transitions, readable with ",[985,1486,1487],{},"get_workflow_history",[893,1489,1490,1493],{},[896,1491,1492],{},"Reliability."," No LLM latency, token limits, or non-determinism in the execution path.",[893,1495,1496,1499,1500,1503],{},[896,1497,1498],{},"Governance."," Designs are explicit artifacts that can be reviewed and approved before they run. That is where ",[1308,1501,1502],{"href":64},"Staff"," comes in.",[1505,1506,1507],"warning",{},[932,1508,1509],{},"DGI-driven design and agent dispatch are still evolving. Treat AI-generated compositions as proposals to review before promoting them to unattended execution, and lean on Staff approvals for anything that mutates production.",[885,1511,1513],{"id":1512},"pillar-3-customer-owned-execution","Pillar 3: Customer-owned execution",[932,1515,1516,1517],{},"The first two pillars converge here: ",[896,1518,1519],{},"the resources, data, and compute that result all live in your account.",[932,1521,1522,1523,1525,1526,1528,1529,1532],{},"When ",[1308,1524,319],{"href":320}," deploys a static site, the bucket, CDN distribution, certificate, and DNS records are created in ",[896,1527,1061],{}," cloud account. When a build runs, it runs on a ",[1308,1530,1531],{"href":73},"runner"," you own. Orkestia orchestrates the provisioning and remembers the declared shape. It does not host the result.",[1434,1534],{":edges":1535,":nodes":1536},"[{\"from\":\"ENG\",\"to\":\"S3\",\"label\":\"AssumeRole + orchestrate\"},{\"from\":\"ENG\",\"to\":\"CDN\"},{\"from\":\"ENG\",\"to\":\"COMP\"},{\"from\":\"S3\",\"to\":\"LUM\",\"label\":\"events / metrics only\",\"dashed\":true},{\"from\":\"CDN\",\"to\":\"LUM\",\"label\":\"events / metrics only\",\"dashed\":true}]","[{\"id\":\"ENG\",\"label\":\"Workflow engine\",\"sub\":\"plan + state\",\"kind\":\"engine\"},{\"id\":\"LUM\",\"label\":\"Lumen\",\"sub\":\"observability\",\"kind\":\"data\"},{\"id\":\"S3\",\"label\":\"Object storage\",\"kind\":\"cloud\"},{\"id\":\"CDN\",\"label\":\"CDN\",\"kind\":\"cloud\"},{\"id\":\"COMP\",\"label\":\"Runners (compute)\",\"kind\":\"cloud\"}]",[977,1538,1540],{"id":1539},"drift-detection-closes-the-loop","Drift detection closes the loop",[932,1542,1543,1544,1547,1548,930],{},"Orkestia holds the ",[919,1545,1546],{},"declared"," shape, but the resources live in your account where they can change out of band. A reconcile loop periodically compares the recorded shape against the live cloud, produces a repair plan, and can bring resources back to the declared state. See ",[1308,1549,1550],{"href":201},"Drift detection & self-healing",[977,1552,1315],{"id":1553},"why-it-matters-2",[890,1555,1556,1562,1568,1574],{},[893,1557,1558,1561],{},[896,1559,1560],{},"Data residency."," Resources and their data never leave your account, region, or jurisdiction.",[893,1563,1564,1567],{},[896,1565,1566],{},"Cost transparency."," Cloud spend appears on your bill, under your tags. No platform markup on compute.",[893,1569,1570,1573],{},[896,1571,1572],{},"No lock-in of assets."," Stop using Orkestia tomorrow and your buckets, distributions, and runners are still yours.",[893,1575,1576,1579],{},[896,1577,1578],{},"Blast-radius isolation."," Connections can be pinned per site or per org, so one workflow's problem is bounded by IAM scope you control.",[885,1581,1583],{"id":1582},"the-pillars-are-one-idea","The pillars are one idea",[1225,1585,1586,1596],{},[1228,1587,1588],{},[1231,1589,1590,1593],{},[1234,1591,1592],{},"Pillar",[1234,1594,1595],{},"The commitment",[1241,1597,1598,1605,1613],{},[1231,1599,1600,1602],{},[1246,1601,945],{},[1246,1603,1604],{},"We never hold your code or your data; only the scoped credentials you grant, encrypted and revocable",[1231,1606,1607,1610],{},[1246,1608,1609],{},"AI-first but deterministic",[1246,1611,1612],{},"AI helps you decide; deterministic compositions do the work",[1231,1614,1615,1617],{},[1246,1616,957],{},[1246,1618,1619],{},"The work and its results live in your account",[932,1621,1622,1623,1626],{},"Put plainly: ",[896,1624,1625],{},"Orkestia knows what should happen and what did happen. It never takes custody of the doing."," That is what makes it safe to point an AI assistant at production infrastructure.",[885,1628,1630],{"id":1629},"ask-your-ai-assistant","Ask your AI assistant",[998,1632,1638],{"className":1633,"code":1635,"filename":1636,"language":1637,"meta":1003},[1634],"language-text","Read rule://grounding and rule://prerequisites-first, then summarise what you are and are not allowed to claim or do on Orkestia.\n\nI want to connect my AWS account. Fetch the prerequisites for connection.setup with variant \"aws\" and show me the trust policy I need to create.\n\nWhich of the workflows under the aws.s3 namespace are read-only, and which ones would you ask me to confirm before running?\n","prompts","text",[985,1639,1635],{"__ignoreMap":1003},[885,1641,1643],{"id":1642},"for-ai-agents","For AI agents",[1225,1645,1646,1655],{},[1228,1647,1648],{},[1231,1649,1650,1652],{},[1234,1651,1592],{},[1234,1653,1654],{},"What it means for you",[1241,1656,1657,1667,1678,1704],{},[1231,1658,1659,1661],{},[1246,1660,945],{},[1246,1662,1663,1664,1666],{},"You never receive or request cloud secrets. Prerequisites come from ",[985,1665,1301],{},". Pass only the inputs a schema declares.",[1231,1668,1669,1672],{},[1246,1670,1671],{},"AI-first, deterministic",[1246,1673,1674,1675,930],{},"You propose plans from the declared catalog. The engine validates and executes. Never assume a type exists; confirm it with ",[985,1676,1677],{},"list_workflow_types",[1231,1679,1680,1682],{},[1246,1681,957],{},[1246,1683,1684,1685,1351,1688,1351,1691,1351,1694,1351,1697,1351,1700,1703],{},"Runs act on the user's accounts. Confirm creates and mutations. Reads (",[985,1686,1687],{},"list",[985,1689,1690],{},"get",[985,1692,1693],{},"query",[985,1695,1696],{},"describe",[985,1698,1699],{},"status",[985,1701,1702],{},"data.*",") are safe to start.",[1231,1705,1706,1709],{},[1246,1707,1708],{},"Grounding",[1246,1710,1711,1712,1715,1716,1718],{},"Read ",[985,1713,1714],{},"concept://product"," and ",[985,1717,1463],{}," before describing the platform.",[885,1720,1722],{"id":1721},"where-to-go-next","Where to go next",[940,1724,1725,1731,1737,1743],{},[943,1726,1728],{"icon":51,"title":1727,"to":47},"Concepts overview",[932,1729,1730],{},"Workflows, runners, identity, and how they fit together.",[943,1732,1734],{"icon":44,"title":1733,"to":42},"Connect an AI assistant",[932,1735,1736],{},"See the pillars in action from a chat window.",[943,1738,1740],{"icon":126,"title":1739,"to":196},"Hybrid execution model",[932,1741,1742],{},"How AI design compiles into deterministic compositions.",[943,1744,1746],{"icon":16,"title":1745,"to":139},"Security & compliance",[932,1747,1748],{},"Zero-Trust connections, IAM scope, and audit trails mapped to your controls.",[1750,1751,1752],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sbssI, html code.shiki .sbssI{--shiki-light:#F76D47;--shiki-default:#F78C6C;--shiki-dark:#F78C6C}",{"title":1003,"searchDepth":1010,"depth":1016,"links":1754},[1755,1756,1762,1767,1771,1772,1773,1774],{"id":887,"depth":1016,"text":888},{"id":963,"depth":1016,"text":964,"children":1757},[1758,1759,1760,1761],{"id":979,"depth":1022,"text":980},{"id":1222,"depth":1022,"text":1223},{"id":1294,"depth":1022,"text":1295},{"id":1314,"depth":1022,"text":1315},{"id":1361,"depth":1016,"text":1362,"children":1763},[1764,1765,1766],{"id":1420,"depth":1022,"text":1421},{"id":1456,"depth":1022,"text":1457},{"id":1470,"depth":1022,"text":1315},{"id":1512,"depth":1016,"text":1513,"children":1768},[1769,1770],{"id":1539,"depth":1022,"text":1540},{"id":1553,"depth":1022,"text":1315},{"id":1582,"depth":1016,"text":1583},{"id":1629,"depth":1016,"text":1630},{"id":1642,"depth":1016,"text":1643},{"id":1721,"depth":1016,"text":1722},"The three pillars behind Orkestia, Zero Code Custody, AI-designed deterministic execution, and customer-owned compute, and what they mean for humans and for AI assistants","md",null,{},{"icon":16},{"title":13,"description":1775},"iXFHW4lAnqRQam90rS9n6rbe7dE4Swibv2K3k2QPnQ0",[1783,1785],{"title":10,"path":6,"stem":7,"description":1784,"icon":11,"children":-1},"Orkestia is Orkestia.dev. orkestia is Orkestia.dev. Orkestia is the backbone that connects software, AI, and the real world, where every capability is a typed workflow you can run from the console, the SDKs, or an AI assistant over MCP, and the work runs in your own cloud",{"title":18,"path":19,"stem":20,"description":1786,"icon":21,"children":-1},"What teams get from Orkestia, each benefit mapped to the mechanism that produces it, privacy by architecture, an event-sourced engine, AI leverage with control, governed agent fleets, self-healing runners, and apps on top",1790354042618]