[{"data":1,"prerenderedAt":1745},["ShallowReactive",2],{"navigation":3,"/operations/best-practices":879,"/operations/best-practices-surround":1740},[4,22,45,115,156,187,214,235,264,295,318,361,389,418,436,470,491,534,548,571,632,670,693,757,850],{"title":5,"path":6,"stem":7,"children":8,"icon":11},"Introduction","/introduction","01.introduction/1.index",[9,12,17],{"title":10,"path":6,"stem":7,"icon":11},"What is Orkestia?","i-lucide-sparkles",{"title":13,"path":14,"stem":15,"icon":16},"Core Philosophy","/introduction/core-philosophy","01.introduction/2.core-philosophy","i-lucide-shield-check",{"title":18,"path":19,"stem":20,"icon":21},"Key Benefits","/introduction/key-benefits","01.introduction/3.key-benefits","i-lucide-trophy",{"title":23,"path":24,"stem":25,"children":26,"icon":29},"Getting Started","/getting-started","02.getting-started/1.index",[27,30,35,40],{"title":28,"path":24,"stem":25,"icon":29},"Quick Start","i-lucide-rocket",{"title":31,"path":32,"stem":33,"icon":34},"Architecture Overview","/getting-started/architecture-overview","02.getting-started/2.architecture-overview","i-lucide-layout-dashboard",{"title":36,"path":37,"stem":38,"icon":39},"Concepts at a Glance","/getting-started/concepts","02.getting-started/3.concepts","i-lucide-list",{"title":41,"path":42,"stem":43,"icon":44},"Connect an AI Assistant","/getting-started/connect-an-ai-assistant","02.getting-started/4.connect-an-ai-assistant","i-lucide-bot",{"title":46,"path":47,"stem":48,"children":49,"icon":51},"Core Concepts","/concepts","03.concepts/01.index",[50,52,57,62,67,71,76,81,86,91,96,100,105,110],{"title":46,"path":47,"stem":48,"icon":51},"i-lucide-book-open",{"title":53,"path":54,"stem":55,"icon":56},"Workflows","/concepts/workflows","03.concepts/02.workflows","i-lucide-workflow",{"title":58,"path":59,"stem":60,"icon":61},"DGI — Dialog Generative Interface","/concepts/dgi","03.concepts/03.dgi","i-lucide-brain",{"title":63,"path":64,"stem":65,"icon":66},"Staff & AI Workforce Governance","/concepts/staff-governance","03.concepts/04.staff-governance","i-lucide-users-round",{"title":68,"path":69,"stem":70,"icon":44},"Agents — the execution substrate","/concepts/agents-platform","03.concepts/05.agents-platform",{"title":72,"path":73,"stem":74,"icon":75},"Runners & Execution Environments","/concepts/runners","03.concepts/06.runners","i-lucide-server-cog",{"title":77,"path":78,"stem":79,"icon":80},"Lumen Observability","/concepts/lumen","03.concepts/07.lumen","i-lucide-activity",{"title":82,"path":83,"stem":84,"icon":85},"Identity & Multi-Tenancy","/concepts/identity-multi-tenancy","03.concepts/08.identity-multi-tenancy","i-lucide-users",{"title":87,"path":88,"stem":89,"icon":90},"Billing, Pricing & Seats","/concepts/billing-and-seats","03.concepts/09.billing-and-seats","i-lucide-credit-card",{"title":92,"path":93,"stem":94,"icon":95},"App Data","/concepts/appdata","03.concepts/10.appdata","i-lucide-database",{"title":97,"path":98,"stem":99,"icon":61},"Engram","/concepts/engram","03.concepts/11.engram",{"title":101,"path":102,"stem":103,"icon":104},"DevKit","/concepts/devkit","03.concepts/12.devkit","i-lucide-terminal",{"title":106,"path":107,"stem":108,"icon":109},"App Host","/concepts/app-host","03.concepts/13.app-host","i-lucide-globe",{"title":111,"path":112,"stem":113,"icon":114},"Agent Exchange","/concepts/agent-exchange","03.concepts/14.agent-exchange","i-lucide-landmark",{"title":116,"path":117,"stem":118,"children":119,"icon":121},"Guides","/guides","04.guides/1.index",[120,122,127,132,137,142,147,151],{"title":116,"path":117,"stem":118,"icon":121},"i-lucide-compass",{"title":123,"path":124,"stem":125,"icon":126},"Building with DGI","/guides/building-with-dgi","04.guides/2.building-with-dgi","i-lucide-brain-circuit",{"title":128,"path":129,"stem":130,"icon":131},"Creating & Exposing Virtual Workflows","/guides/virtual-workflows","04.guides/4.virtual-workflows","i-lucide-blocks",{"title":133,"path":134,"stem":135,"icon":136},"Runner Management & Provisioning","/guides/runner-management","04.guides/5.runner-management","i-lucide-server",{"title":138,"path":139,"stem":140,"icon":141},"Security & Compliance","/guides/security-and-compliance","04.guides/7.security-and-compliance","i-lucide-shield",{"title":143,"path":144,"stem":145,"icon":146},"Tickets & Software Delivery","/guides/tickets-and-software-delivery","04.guides/8.tickets-and-software-delivery","i-lucide-ticket",{"title":148,"path":149,"stem":150},"Orkestia for AI-driven cloud infrastructure automation","/guides/cloud-automation-alternatives","04.guides/9.cloud-automation-alternatives",{"title":152,"path":153,"stem":154,"icon":155},"Typed decisions with TypeSafe","/guides/typed-decisions-with-typesafe","04.guides/9.typed-decisions-with-typesafe","i-lucide-git-branch",{"title":157,"path":158,"stem":159,"children":160,"icon":162},"Reference","/reference","05.reference/1.index",[161,163,168,173,177,182],{"title":157,"path":158,"stem":159,"icon":162},"i-lucide-library",{"title":164,"path":165,"stem":166,"icon":167},"Workflow Types & Registry","/reference/workflow-types-registry","05.reference/2.workflow-types-registry","i-lucide-list-tree",{"title":169,"path":170,"stem":171,"icon":172},"MCP Integration","/reference/mcp-integration","05.reference/3.mcp-integration","i-lucide-plug-zap",{"title":174,"path":175,"stem":176,"icon":104},"API & Tooling","/reference/api-tooling","05.reference/4.api-tooling",{"title":178,"path":179,"stem":180,"icon":181},"Integrations Catalog","/reference/integrations-catalog","05.reference/6.integrations-catalog","i-lucide-plug",{"title":183,"path":184,"stem":185,"icon":186},"Platform Services","/reference/platform-services","05.reference/7.platform-services","i-lucide-boxes",{"title":188,"path":189,"stem":190,"children":191,"icon":193},"Advanced Topics","/advanced","06.advanced/1.index",[192,194,199,204,209],{"title":188,"path":189,"stem":190,"icon":193},"i-lucide-flask-conical",{"title":195,"path":196,"stem":197,"icon":198},"Hybrid AI + Deterministic Execution","/advanced/hybrid-execution-model","06.advanced/2.hybrid-execution-model","i-lucide-git-merge",{"title":200,"path":201,"stem":202,"icon":203},"Drift Detection & Self-Healing","/advanced/drift-detection-self-healing","06.advanced/3.drift-detection-self-healing","i-lucide-heart-pulse",{"title":205,"path":206,"stem":207,"icon":208},"Governance & Approvals","/advanced/governance-and-approvals","06.advanced/4.governance-and-approvals","i-lucide-scale",{"title":210,"path":211,"stem":212,"icon":213},"Cost & Performance Optimization","/advanced/cost-and-performance","06.advanced/5.cost-and-performance","i-lucide-zap",{"title":215,"path":216,"stem":217,"children":218,"icon":220},"Operations","/operations","07.operations/1.index",[219,221,225,230],{"title":215,"path":216,"stem":217,"icon":220},"i-lucide-settings-2",{"title":222,"path":223,"stem":224,"icon":186},"Deployment Models","/operations/deployment-models","07.operations/2.deployment-models",{"title":226,"path":227,"stem":228,"icon":229},"Monitoring & Debugging","/operations/monitoring-and-debugging","07.operations/3.monitoring-and-debugging","i-lucide-bug",{"title":231,"path":232,"stem":233,"icon":234},"Best Practices","/operations/best-practices","07.operations/4.best-practices","i-lucide-check-check",{"title":236,"path":237,"stem":238,"children":239,"icon":241},"AWS Connections","/aws-connections","08.aws-connections/1.index",[240,242,245,250,255,260],{"title":236,"path":237,"stem":238,"icon":241},"i-simple-icons-amazonaws",{"title":23,"path":243,"stem":244,"icon":29},"/aws-connections/getting-started","08.aws-connections/2.getting-started",{"title":246,"path":247,"stem":248,"icon":249},"Setup Methods","/aws-connections/setup-methods","08.aws-connections/3.setup-methods","i-lucide-wrench",{"title":251,"path":252,"stem":253,"icon":254},"Managing Connections","/aws-connections/managing-connections","08.aws-connections/4.managing-connections","i-lucide-settings",{"title":256,"path":257,"stem":258,"icon":259},"Security Best Practices","/aws-connections/security-best-practices","08.aws-connections/5.security-best-practices","i-lucide-lock",{"title":261,"path":262,"stem":263,"icon":229},"Troubleshooting","/aws-connections/troubleshooting","08.aws-connections/6.troubleshooting",{"title":265,"path":266,"stem":267,"children":268,"icon":270},"Cloud Connections","/cloud-connections","09.cloud-connections/1.index",[269,271,276,281,286,291],{"title":265,"path":266,"stem":267,"icon":270},"i-lucide-cable",{"title":272,"path":273,"stem":274,"icon":275},"Google Cloud (GCP)","/cloud-connections/gcp","09.cloud-connections/2.gcp","i-simple-icons-googlecloud",{"title":277,"path":278,"stem":279,"icon":280},"Microsoft Azure","/cloud-connections/azure","09.cloud-connections/3.azure","i-simple-icons-microsoftazure",{"title":282,"path":283,"stem":284,"icon":285},"Magalu Cloud","/cloud-connections/magalu","09.cloud-connections/4.magalu","i-lucide-cloud",{"title":287,"path":288,"stem":289,"icon":290},"Kubernetes","/cloud-connections/kubernetes","09.cloud-connections/5.kubernetes","i-simple-icons-kubernetes",{"title":292,"path":293,"stem":294,"icon":208},"TypeSafe","/cloud-connections/typesafe","09.cloud-connections/6.typesafe",{"title":296,"path":297,"stem":298,"children":299,"icon":136},"DNS Providers","/dns-providers","10.dns-providers/1.index",[300,302,305,308,311,315],{"title":301,"path":297,"stem":298,"icon":136},"DNS Provider Connections",{"title":23,"path":303,"stem":304,"icon":29},"/dns-providers/getting-started","10.dns-providers/2.getting-started",{"title":246,"path":306,"stem":307,"icon":249},"/dns-providers/setup-methods","10.dns-providers/3.setup-methods",{"title":251,"path":309,"stem":310,"icon":254},"/dns-providers/managing-connections","10.dns-providers/4.managing-connections",{"title":312,"path":313,"stem":314,"icon":39},"Zones and Records","/dns-providers/zones-and-records","10.dns-providers/5.zones-and-records",{"title":261,"path":316,"stem":317,"icon":229},"/dns-providers/troubleshooting","10.dns-providers/6.troubleshooting",{"title":319,"path":320,"stem":321,"children":322,"icon":29},"Cloud Deploy","/cloud-deploy","11.cloud-deploy/01.index",[323,324,327,332,336,341,345,349,354,358],{"title":319,"path":320,"stem":321,"icon":29},{"title":23,"path":325,"stem":326,"icon":29},"/cloud-deploy/getting-started","11.cloud-deploy/02.getting-started",{"title":328,"path":329,"stem":330,"icon":331},"Creating a Site","/cloud-deploy/creating-a-site","11.cloud-deploy/03.creating-a-site","i-lucide-plus-circle",{"title":333,"path":334,"stem":335,"icon":34},"Site Overview and Deployments","/cloud-deploy/site-overview","11.cloud-deploy/04.site-overview",{"title":337,"path":338,"stem":339,"icon":340},"Deployment Progress and Success","/cloud-deploy/deployment-progress","11.cloud-deploy/05.deployment-progress","i-lucide-loader",{"title":342,"path":343,"stem":344,"icon":254},"Settings","/cloud-deploy/settings","11.cloud-deploy/06.settings",{"title":346,"path":347,"stem":348,"icon":109},"Custom Domains","/cloud-deploy/custom-domains","11.cloud-deploy/07.custom-domains",{"title":350,"path":351,"stem":352,"icon":353},"Resources, Releases, and Danger Zone","/cloud-deploy/resources-releases","11.cloud-deploy/08.resources-releases","i-lucide-package",{"title":355,"path":356,"stem":357,"icon":141},"Admin Dashboard","/cloud-deploy/admin-dashboard","11.cloud-deploy/09.admin-dashboard",{"title":261,"path":359,"stem":360,"icon":229},"/cloud-deploy/troubleshooting","11.cloud-deploy/10.troubleshooting",{"title":362,"path":363,"stem":364,"children":365,"icon":368},"User Onboarding","/user-onboarding","12.user-onboarding/1.index",[366,369,372,377,382,386],{"title":367,"path":363,"stem":364,"icon":368},"User Creation and Onboarding","i-lucide-user-plus",{"title":23,"path":370,"stem":371,"icon":29},"/user-onboarding/getting-started","12.user-onboarding/2.getting-started",{"title":373,"path":374,"stem":375,"icon":376},"Creating Your Organization","/user-onboarding/onboarding","12.user-onboarding/3.onboarding","i-lucide-building-2",{"title":378,"path":379,"stem":380,"icon":381},"Invitations","/user-onboarding/invitations","12.user-onboarding/4.invitations","i-lucide-mail",{"title":383,"path":384,"stem":385,"icon":254},"Managing Your Account","/user-onboarding/managing-account","12.user-onboarding/5.managing-account",{"title":261,"path":387,"stem":388,"icon":229},"/user-onboarding/troubleshooting","12.user-onboarding/6.troubleshooting",{"title":342,"path":390,"stem":391,"children":392,"icon":394},"/settings","13.settings/1.index",[393,395,400,404,409,413],{"title":342,"path":390,"stem":391,"icon":394},"i-lucide-sliders-horizontal",{"title":396,"path":397,"stem":398,"icon":399},"General Settings","/settings/general","13.settings/2.general","i-lucide-user",{"title":401,"path":402,"stem":403,"icon":85},"Members Settings","/settings/members","13.settings/3.members",{"title":405,"path":406,"stem":407,"icon":408},"Notifications Settings","/settings/notifications","13.settings/4.notifications","i-lucide-bell",{"title":410,"path":411,"stem":412,"icon":141},"Security Settings","/settings/security","13.settings/5.security",{"title":414,"path":415,"stem":416,"icon":417},"Signing Keys","/settings/keys","13.settings/6.keys","i-lucide-key-round",{"title":419,"path":420,"stem":421,"children":422,"icon":29},"App Enablement","/app-enablement","14.app-enablement/1.index",[423,424,428,432],{"title":419,"path":420,"stem":421,"icon":29},{"title":425,"path":426,"stem":427,"icon":417},"Sign in with Orkestia","/app-enablement/sign-in-with-orkestia","14.app-enablement/2.sign-in-with-orkestia",{"title":429,"path":430,"stem":431,"icon":95},"End-user data","/app-enablement/end-user-data","14.app-enablement/3.end-user-data",{"title":433,"path":434,"stem":435,"icon":131},"Compositions — use, invoke, share","/app-enablement/compositions","14.app-enablement/4.compositions",{"title":437,"path":438,"stem":439,"children":440,"icon":80},"Lumen","/lumen","15.lumen/1.index",[441,442,447,452,457,461,465],{"title":437,"path":438,"stem":439,"icon":80},{"title":443,"path":444,"stem":445,"icon":446},"Enable Lumen","/lumen/enable","15.lumen/2.enable","i-lucide-power",{"title":448,"path":449,"stem":450,"icon":451},"Send data","/lumen/send-data","15.lumen/3.send-data","i-lucide-upload",{"title":453,"path":454,"stem":455,"icon":456},"Collector","/lumen/collector","15.lumen/4.collector","i-lucide-container",{"title":458,"path":459,"stem":460,"icon":34},"Use Lumen","/lumen/observe","15.lumen/5.observe",{"title":462,"path":463,"stem":464,"icon":44},"Lumen MCP","/lumen/mcp","15.lumen/6.mcp",{"title":466,"path":467,"stem":468,"icon":469},"Query API","/lumen/query-api","15.lumen/7.query-api","i-lucide-search",{"title":471,"path":472,"stem":473,"children":474,"icon":476},"SDKs","/sdks","16.sdks/1.index",[475,477,482,487],{"title":471,"path":472,"stem":473,"icon":476},"i-lucide-code",{"title":478,"path":479,"stem":480,"icon":481},"Workflows SDK — Node / TypeScript","/sdks/workflows-nodejs","16.sdks/2.workflows-nodejs","i-lucide-file-ts",{"title":483,"path":484,"stem":485,"icon":486},"Workflows SDK — Python","/sdks/workflows-python","16.sdks/3.workflows-python","i-simple-icons-python",{"title":488,"path":489,"stem":490,"icon":417},"Auth SDK — Sign in with Orkestia","/sdks/auth","16.sdks/4.auth",{"title":92,"path":492,"stem":493,"children":494,"icon":95},"/appdata","17.appdata/1.index",[495,496,501,506,510,515,520,525,530],{"title":92,"path":492,"stem":493,"icon":95},{"title":497,"path":498,"stem":499,"icon":500},"Declare structures","/appdata/declare","17.appdata/2.declare","i-lucide-table",{"title":502,"path":503,"stem":504,"icon":505},"Records & Data API","/appdata/data-api","17.appdata/3.data-api","i-lucide-rows-3",{"title":507,"path":508,"stem":509,"icon":376},"Ownership & workspaces","/appdata/ownership","17.appdata/4.ownership",{"title":511,"path":512,"stem":513,"icon":514},"Expose App Data to end-users","/appdata/expose","17.appdata/5.expose","i-lucide-app-window",{"title":516,"path":517,"stem":518,"icon":519},"PostgREST HTTP","/appdata/postgrest","17.appdata/6.postgrest","i-lucide-unplug",{"title":521,"path":522,"stem":523,"icon":524},"Ordered append","/appdata/append","17.appdata/7.append","i-lucide-list-ordered",{"title":526,"path":527,"stem":528,"icon":529},"Databases and instances","/appdata/instances","17.appdata/8.instances","i-lucide-hard-drive",{"title":531,"path":532,"stem":533,"icon":104},"Query console and SQL","/appdata/query","17.appdata/9.query",{"title":97,"path":535,"stem":536,"children":537,"icon":61},"/engram","18.engram/1.index",[538,539,543],{"title":97,"path":535,"stem":536,"icon":61},{"title":540,"path":541,"stem":542,"icon":155},"Write & recall","/engram/write-recall","18.engram/2.write-recall",{"title":544,"path":545,"stem":546,"icon":547},"Field & feed","/engram/agent-memory","18.engram/3.agent-memory","i-lucide-radio",{"title":101,"path":549,"stem":550,"children":551,"icon":104},"/devkit","19.devkit/1.index",[552,553,558,562,567],{"title":101,"path":549,"stem":550,"icon":104},{"title":554,"path":555,"stem":556,"icon":557},"Install DevKit","/devkit/install","19.devkit/2.install","i-lucide-download",{"title":559,"path":560,"stem":561,"icon":519},"Hook redirect","/devkit/hooks","19.devkit/3.hooks",{"title":563,"path":564,"stem":565,"icon":566},"Local coding runner","/devkit/local-runner","19.devkit/4.local-runner","i-lucide-cpu",{"title":568,"path":569,"stem":570,"icon":131},"Compositions from DevKit","/devkit/compositions","19.devkit/5.compositions",{"title":572,"path":573,"stem":574,"children":575,"icon":44},"Staff & Agents","/staff-and-agents","20.staff-and-agents/01.index",[576,577,582,586,590,594,598,602,606,611,615,620,625,629],{"title":572,"path":573,"stem":574,"icon":44},{"title":578,"path":579,"stem":580,"icon":581},"Prerequisites","/staff-and-agents/prerequisites","20.staff-and-agents/02.prerequisites","i-lucide-list-checks",{"title":583,"path":584,"stem":585,"icon":368},"Hire an actor","/staff-and-agents/hire-an-actor","20.staff-and-agents/03.hire-an-actor",{"title":587,"path":588,"stem":589,"icon":34},"Console","/staff-and-agents/console","20.staff-and-agents/04.console",{"title":591,"path":592,"stem":593,"icon":11},"Configs, skills, and MCP","/staff-and-agents/configs-skills-mcp","20.staff-and-agents/05.configs-skills-mcp",{"title":595,"path":596,"stem":597,"icon":136},"Agent runner groups","/staff-and-agents/runner-groups","20.staff-and-agents/06.runner-groups",{"title":599,"path":600,"stem":601,"icon":16},"Governance","/staff-and-agents/governance","20.staff-and-agents/07.governance",{"title":603,"path":604,"stem":605,"icon":417},"Identity and tokens","/staff-and-agents/identity","20.staff-and-agents/08.identity",{"title":607,"path":608,"stem":609,"icon":610},"Memory and cost","/staff-and-agents/memory-and-cost","20.staff-and-agents/09.memory-and-cost","i-lucide-wallet",{"title":612,"path":613,"stem":614,"icon":155},"Coding agents","/staff-and-agents/coding-agents","20.staff-and-agents/10.coding-agents",{"title":616,"path":617,"stem":618,"icon":619},"Wire a repository for coding agents","/staff-and-agents/wire-a-repository","20.staff-and-agents/11.wire-a-repository","i-lucide-link",{"title":621,"path":622,"stem":623,"icon":624},"Run a ticket end to end","/staff-and-agents/run-a-ticket","20.staff-and-agents/12.run-a-ticket","i-lucide-play",{"title":626,"path":627,"stem":628,"icon":66},"Build a product team of actors","/staff-and-agents/build-a-product-team","20.staff-and-agents/13.build-a-product-team",{"title":261,"path":630,"stem":631,"icon":249},"/staff-and-agents/troubleshooting","20.staff-and-agents/14.troubleshooting",{"title":106,"path":633,"stem":634,"children":635,"icon":109},"/app-host","21.app-host/1.index",[636,637,641,644,649,653,658,662,666],{"title":106,"path":633,"stem":634,"icon":109},{"title":638,"path":639,"stem":640,"icon":514},"Your app and site","/app-host/your-app","21.app-host/2.your-app",{"title":92,"path":642,"stem":643,"icon":95},"/app-host/app-data","21.app-host/3.app-data",{"title":645,"path":646,"stem":647,"icon":648},"Website and process","/app-host/hosting","21.app-host/4.hosting","i-lucide-cloud-upload",{"title":650,"path":651,"stem":652,"icon":547},"Buzz","/app-host/buzz","21.app-host/5.buzz",{"title":654,"path":655,"stem":656,"icon":657},"Files","/app-host/files","21.app-host/6.files","i-lucide-folder",{"title":659,"path":660,"stem":661,"icon":109},"Your own domain","/app-host/your-domain","21.app-host/7.your-domain",{"title":663,"path":664,"stem":665,"icon":229},"Troubleshooting App Host","/app-host/troubleshooting","21.app-host/8.troubleshooting",{"title":667,"path":668,"stem":669,"icon":417},"Signing keys","/app-host/signing-keys","21.app-host/9.signing-keys",{"title":111,"path":671,"stem":672,"children":673,"icon":114},"/agent-exchange","22.agent-exchange/01.index",[674,675,678,682,686,690],{"title":111,"path":671,"stem":672,"icon":114},{"title":583,"path":676,"stem":677,"icon":368},"/agent-exchange/hire","22.agent-exchange/02.hire",{"title":679,"path":680,"stem":681,"icon":208},"List an actor","/agent-exchange/list","22.agent-exchange/03.list",{"title":683,"path":684,"stem":685,"icon":104},"Invoke & leases","/agent-exchange/invoke","22.agent-exchange/04.invoke",{"title":687,"path":688,"stem":689,"icon":141},"Settlement & trust","/agent-exchange/settlement","22.agent-exchange/05.settlement",{"title":53,"path":691,"stem":692,"icon":56},"/agent-exchange/workflows","22.agent-exchange/06.workflows",{"title":694,"path":695,"stem":696,"children":697,"icon":75},"Runners","/runners","23.runners/1.index",[698,700,704,709,713,717,721,726,730,734,738,741,745,749,753],{"title":699,"path":695,"stem":696,"icon":75},"Runner groups",{"title":701,"path":702,"stem":703,"icon":275},"Cloud Run","/runners/cloud-run","23.runners/10.cloud-run",{"title":705,"path":706,"stem":707,"icon":708},"DigitalOcean App Job","/runners/do-app-job","23.runners/11.do-app-job","i-simple-icons-digitalocean",{"title":710,"path":711,"stem":712,"icon":708},"DigitalOcean Droplet","/runners/do-droplet","23.runners/12.do-droplet",{"title":714,"path":715,"stem":716,"icon":285},"Magalu Cloud VM","/runners/magalu-vm","23.runners/13.magalu-vm",{"title":101,"path":718,"stem":719,"icon":720},"/runners/devkit","23.runners/14.devkit","i-lucide-laptop",{"title":722,"path":723,"stem":724,"icon":725},"Purposes & integrations","/runners/purposes","23.runners/16.purposes","i-lucide-layers",{"title":727,"path":728,"stem":729,"icon":241},"Fargate","/runners/fargate","23.runners/2.fargate",{"title":731,"path":732,"stem":733,"icon":241},"EC2 Auto Scaling","/runners/ec2-auto-scaling","23.runners/3.ec2-auto-scaling",{"title":735,"path":736,"stem":737,"icon":241},"EC2 VM","/runners/ec2-vm","23.runners/4.ec2-vm",{"title":287,"path":739,"stem":740,"icon":290},"/runners/kubernetes","23.runners/5.kubernetes",{"title":742,"path":743,"stem":744,"icon":280},"Azure Container Apps","/runners/azure-container-apps","23.runners/6.azure-container-apps",{"title":746,"path":747,"stem":748,"icon":280},"Azure VMSS","/runners/azure-vmss","23.runners/7.azure-vmss",{"title":750,"path":751,"stem":752,"icon":280},"Azure VM","/runners/azure-vm","23.runners/8.azure-vm",{"title":754,"path":755,"stem":756,"icon":275},"GCE","/runners/gce","23.runners/9.gce",{"title":758,"path":759,"stem":760,"children":761,"icon":763},"Chat","/chat","24.chat/01.index",[762,764,768,773,777,782,787,791,796,800,805,810,814,819,824,828,832,836,840,845],{"title":758,"path":759,"stem":760,"icon":763},"i-lucide-messages-square",{"title":765,"path":766,"stem":767,"icon":446},"Enable and publish","/chat/enable-and-publish","24.chat/02.enable-and-publish",{"title":769,"path":770,"stem":771,"icon":772},"Theme and customization","/chat/theme-and-customization","24.chat/03.theme-and-customization","i-lucide-palette",{"title":774,"path":775,"stem":776,"icon":85},"Members and moderation","/chat/members-and-moderation","24.chat/04.members-and-moderation",{"title":778,"path":779,"stem":780,"icon":781},"Channels","/chat/channels","24.chat/05.channels","i-lucide-hash",{"title":783,"path":784,"stem":785,"icon":786},"Using the chat","/chat/using-the-chat","24.chat/06.using-the-chat","i-lucide-message-circle",{"title":788,"path":789,"stem":790,"icon":44},"Actors in chat","/chat/actors-in-chat","24.chat/07.actors-in-chat",{"title":792,"path":793,"stem":794,"icon":795},"Internal support actor","/chat/internal-support-actor","24.chat/08.internal-support-actor","i-lucide-life-buoy",{"title":797,"path":798,"stem":799,"icon":104},"API and console","/chat/api-and-console","24.chat/09.api-and-console",{"title":801,"path":802,"stem":803,"icon":804},"Limits","/chat/limits","24.chat/10.limits","i-lucide-triangle-alert",{"title":806,"path":807,"stem":808,"icon":809},"Structured chat with DGI","/chat/structured-chat","24.chat/11.structured-chat","i-lucide-layout-list",{"title":811,"path":812,"stem":813,"icon":109},"Option A: hosted chat with DGI","/chat/option-a-hosted-chat","24.chat/12.option-a-hosted-chat",{"title":815,"path":816,"stem":817,"icon":818},"Option B: embed the chat component","/chat/option-b-embed-component","24.chat/13.option-b-embed-component","i-lucide-component",{"title":820,"path":821,"stem":822,"icon":823},"Option C: custom client (wire contract)","/chat/option-c-custom-client","24.chat/14.option-c-custom-client","i-lucide-braces",{"title":825,"path":826,"stem":827,"icon":394},"Responder configuration reference","/chat/responder-reference","24.chat/15.responder-reference",{"title":829,"path":830,"stem":831,"icon":547},"Cards, live updates and proactive posts","/chat/cards-live-and-proactive","24.chat/16.cards-live-and-proactive",{"title":833,"path":834,"stem":835,"icon":16},"Structured chat security model","/chat/structured-chat-security","24.chat/17.structured-chat-security",{"title":837,"path":838,"stem":839,"icon":181},"Option D: any app or API (dgi.chat)","/chat/option-d-chat-api","24.chat/18.option-d-chat-api",{"title":841,"path":842,"stem":843,"icon":844},"Card catalog","/chat/card-catalog","24.chat/19.card-catalog","i-lucide-layout-grid",{"title":846,"path":847,"stem":848,"icon":849},"Living Surfaces","/chat/living-surfaces","24.chat/20.living-surfaces","i-lucide-sprout",{"title":851,"path":852,"stem":853,"children":854,"icon":61},"DGI","/dgi","25.dgi/1.index",[855,857,862,866,870,874],{"title":856,"path":852,"stem":853,"icon":61},"What is DGI",{"title":858,"path":859,"stem":860,"icon":861},"How DGI works","/dgi/how-it-works","25.dgi/2.how-it-works","i-lucide-cog",{"title":863,"path":864,"stem":865,"icon":844},"Interfaces","/dgi/interfaces","25.dgi/3.interfaces",{"title":867,"path":868,"stem":869,"icon":29},"Quickstart","/dgi/quickstart","25.dgi/4.quickstart",{"title":871,"path":872,"stem":873,"icon":16},"Trust and safety","/dgi/trust-and-safety","25.dgi/5.trust-and-safety",{"title":875,"path":876,"stem":877,"icon":878},"FAQ","/dgi/faq","25.dgi/6.faq","i-lucide-circle-help",{"id":880,"title":231,"body":881,"description":1733,"extension":1734,"links":1735,"meta":1736,"navigation":1737,"path":232,"seo":1738,"stem":233,"__hash__":1739},"docs/07.operations/4.best-practices.md",{"type":882,"value":883,"toc":1716},"minimark",[884,889,898,901,930,953,957,1011,1015,1025,1035,1106,1120,1132,1136,1147,1161,1167,1217,1226,1231,1235,1250,1286,1298,1302,1312,1360,1372,1376,1384,1462,1467,1471,1476,1507,1512,1516,1522,1560,1565,1569,1576,1621,1626,1630,1633,1689,1693],[885,886,888],"h2",{"id":887},"tldr","TL;DR",[890,891,892,893,897],"p",{},"This page distills the operational habits that keep an Orkestia deployment reliable,\ngoverned, and cheap to run. None of it is novel — it is the disciplined application of\nthe mechanisms documented elsewhere in this track. Treat it as a pre-flight checklist:\neach item links to the deep page that explains ",[894,895,896],"em",{},"why",", so you can audit your own setup\nagainst it.",[890,899,900],{},"The themes, in priority order:",[902,903,904,912,918,924],"ol",{},[905,906,907,911],"li",{},[908,909,910],"strong",{},"Design for repeatability"," — idempotent workflows, compositions over bespoke code.",[905,913,914,917],{},[908,915,916],{},"Govern the AI"," — let DGI design, but compile flows once stable and gate high-impact actors with approvals.",[905,919,920,923],{},[908,921,922],{},"Lock down the blast radius"," — least-privilege cloud roles, proper tenant isolation.",[905,925,926,929],{},[908,927,928],{},"See everything"," — Lumen alerts on the signals that matter, right-sized runners with drift detection on.",[931,932,933],"note",{},[890,934,935,936,939,940,944,945,952],{},"Orkestia is ",[908,937,938],{},"generally available",". Some controls referenced here (per-workflow rate limits,\nspecific cost dashboards, fine-grained alert rules) are still stabilizing. Where a control\nis not yet GA it is flagged ",[941,942,943],"code",{},"(beta)",". For per-workflow specifics — exact input schemas,\nflags, and limits — always defer to the ",[946,947,951],"a",{"href":948,"rel":949},"https://reference.orkestia.dev",[950],"nofollow","workflow catalog",".",[885,954,956],{"id":955},"the-checklist-at-a-glance","The checklist at a glance",[958,959,960,968,974,980,986,993,999,1005],"card-group",{},[961,962,965],"card",{"icon":963,"title":964,"to":54},"i-lucide-repeat","Design idempotent workflows",[890,966,967],{},"Every step should be safe to run twice. Retries and self-healing depend on it.",[961,969,971],{"icon":198,"title":970,"to":196},"Compile AI flows once stable",[890,972,973],{},"Explore with DGI, then capture the result as a deterministic composition — no LLM in the hot path.",[961,975,977],{"icon":417,"title":976,"to":237},"Scope least-privilege roles",[890,978,979],{},"Grant runners and connections only the permissions a workflow actually exercises.",[961,981,983],{"icon":16,"title":982,"to":64},"Govern AI actors",[890,984,985],{},"Put approval gates in front of high-impact agent actions; bind roles, audit everything.",[961,987,990],{"icon":988,"title":989,"to":459},"i-lucide-bell-ring","Set Lumen alerts",[890,991,992],{},"Alert on failure rate, stuck workflows, and drift — not just raw logs.",[961,994,996],{"icon":75,"title":995,"to":73},"Right-size runners",[890,997,998],{},"Match capacity to load, keep drift detection on, let self-healing reconcile.",[961,1000,1002],{"icon":725,"title":1001,"to":83},"Isolate tenants properly",[890,1003,1004],{},"Scope identity, connections, and state per organization; never share credentials across tenants.",[961,1006,1008],{"icon":131,"title":1007,"to":129},"Prefer compositions over code",[890,1009,1010],{},"Reuse the validated catalog and the virtual engine instead of hand-rolling bespoke logic.",[885,1012,1014],{"id":1013},"_1-design-idempotent-workflows","1. Design idempotent workflows",[890,1016,1017,1018,1021,1022,952],{},"The single most leveraged habit. Orkestia's reliability machinery — retries,\n",[946,1019,1020],{"href":201},"drift detection and self-healing",", and the\nevent-sourced engine that may replay a transition after a pod restart — all assume that\n",[908,1023,1024],{},"re-running a step produces the same end state, not a duplicate side effect",[890,1026,1027,1028,1031,1032,952],{},"A step that creates a resource should first check whether it already exists. A step that\ncharges, emits, or provisions should carry an idempotency key so the provider deduplicates.\nThe atomic workflows in the base library follow a three-state pattern\n(",[941,1029,1030],{},"PENDING → COMPLETED / FAILED","); design your compositions so any state can be safely\nre-entered from ",[941,1033,1034],{},"PENDING",[1036,1037,1038,1054],"table",{},[1039,1040,1041],"thead",{},[1042,1043,1044,1048,1051],"tr",{},[1045,1046,1047],"th",{},"Pattern",[1045,1049,1050],{},"Do",[1045,1052,1053],{},"Avoid",[1055,1056,1057,1073,1084,1095],"tbody",{},[1042,1058,1059,1063,1066],{},[1060,1061,1062],"td",{},"Resource creation",[1060,1064,1065],{},"Check-then-create, or create-if-not-exists",[1060,1067,1068,1069,1072],{},"Blind ",[941,1070,1071],{},"create"," that errors on the second run",[1042,1074,1075,1078,1081],{},[1060,1076,1077],{},"External mutations",[1060,1079,1080],{},"Pass an idempotency key the provider honors",[1060,1082,1083],{},"Relying on \"it only runs once\"",[1042,1085,1086,1089,1092],{},[1060,1087,1088],{},"Counters / appends",[1060,1090,1091],{},"Make the operation set-absolute, not increment",[1060,1093,1094],{},"Increment without a guard",[1042,1096,1097,1100,1103],{},[1060,1098,1099],{},"Cleanup",[1060,1101,1102],{},"Tolerate \"already gone\"",[1060,1104,1105],{},"Fail when the target is missing",[1107,1108,1109],"tip",{},[890,1110,1111,1112,1115,1116,1119],{},"If you cannot make a step naturally idempotent, make it ",[908,1113,1114],{},"detectable",": have it record\na marker the next run can read. The engine's retry and recovery paths (",[941,1117,1118],{},"retry_workflow",",\nself-healing) become safe to use only once every step is replay-safe.",[1121,1122,1123],"warning",{},[890,1124,1125,1126,1129,1130,952],{},"Workflows that are ",[894,1127,1128],{},"not"," idempotent are the most common cause of damage during automatic\nretry. Before enabling self-healing on a runner group, audit the workflows it runs for\nreplay-safety. See ",[946,1131,200],{"href":201},[885,1133,1135],{"id":1134},"_2-compile-ai-flows-once-they-are-stable","2. Compile AI flows once they are stable",[890,1137,1138,1139,1142,1143,1146],{},"DGI's strength is ",[908,1140,1141],{},"design"," — figuring out ",[894,1144,1145],{},"what"," steps to run for a novel intent. That\nis open-ended work where AI reasoning earns its keep. But you do not want an LLM in the\nhot path of a flow you run a thousand times a day: it is slower, costlier, and\nnon-deterministic.",[890,1148,1149,1150,1153,1154,1160],{},"The platform's answer is the ",[946,1151,1152],{"href":196},"hybrid execution model",":\nexplore once with DGI, then ",[908,1155,1156,1157],{},"capture the result as a deterministic\n",[946,1158,1159],{"href":129},"virtual workflow (composition)",". The virtual engine\nvalidates the AI-authored plan against the live catalog (does every referenced workflow\ntype exist? do the input mappings type-check?) and compiles it to a plain DAG config the\nengine runs with no LLM involved.",[1162,1163],"dag-diagram",{":edges":1164,":nodes":1165,"direction":1166},"[{\"from\":\"intent\",\"to\":\"dgi\"},{\"from\":\"dgi\",\"to\":\"plan\"},{\"from\":\"plan\",\"to\":\"ve\"},{\"from\":\"ve\",\"to\":\"comp\"},{\"from\":\"comp\",\"to\":\"eng\",\"label\":\"run N times, no LLM\"}]","[{\"id\":\"intent\",\"label\":\"Novel intent\",\"kind\":\"start\"},{\"id\":\"dgi\",\"label\":\"DGI — AI design\",\"kind\":\"ai\"},{\"id\":\"plan\",\"label\":\"Workflow plan (DAG)\"},{\"id\":\"ve\",\"label\":\"Virtual engine\",\"sub\":\"validate + compile\",\"kind\":\"engine\"},{\"id\":\"comp\",\"label\":\"Composition\",\"sub\":\"deterministic DAG\"},{\"id\":\"eng\",\"label\":\"Workflow engine\",\"kind\":\"engine\"}]","LR",[1036,1168,1169,1182],{},[1039,1170,1171],{},[1042,1172,1173,1176,1179],{},[1045,1174,1175],{},"When",[1045,1177,1178],{},"Use",[1045,1180,1181],{},"Why",[1055,1183,1184,1195,1206],{},[1042,1185,1186,1189,1192],{},[1060,1187,1188],{},"One-off / exploratory",[1060,1190,1191],{},"DGI live design",[1060,1193,1194],{},"Flexibility beats repeatability",[1042,1196,1197,1200,1203],{},[1060,1198,1199],{},"Recurring / production",[1060,1201,1202],{},"Compiled composition",[1060,1204,1205],{},"Byte-stable, cheap, auditable, no LLM latency",[1042,1207,1208,1211,1214],{},[1060,1209,1210],{},"Plan changed",[1060,1212,1213],{},"Re-design with DGI, re-compile",[1060,1215,1216],{},"Keep the composition as the source of truth",[1107,1218,1219],{},[890,1220,1221,1222,1225],{},"A compiled composition is ",[908,1223,1224],{},"deterministic",": same input plus same installed catalog\nproduces byte-stable output. That makes plans diffable and reviewable — treat a\ncompiled composition like code in review.",[1121,1227,1228],{},[890,1229,1230],{},"Compile-time catalog is a snapshot. If the author environment runs an older library than\nthe runtime, compilation can succeed but dispatch can fail on a missing workflow type. Pin\nlibrary versions across authoring and runtime, or compile in the same process that\ndispatches. (beta)",[885,1232,1234],{"id":1233},"_3-scope-least-privilege-cloud-roles","3. Scope least-privilege cloud roles",[890,1236,1237,1238,1241,1242,1245,1246,1249],{},"Orkestia's ",[946,1239,1240],{"href":139},"Zero Trust / Zero Code Custody"," posture means\nexecution happens in ",[908,1243,1244],{},"your"," cloud accounts — Orkestia orchestrates and stores only\nworkflow state and observability data. The corollary: the ",[946,1247,1248],{"href":237},"connections","\nand roles you grant define the entire blast radius. Scope them tightly.",[1251,1252,1253,1263,1269,1280],"ul",{},[905,1254,1255,1258,1259,1262],{},[908,1256,1257],{},"Grant only what a workflow exercises."," Start from the workflow's declared\nprerequisites (",[941,1260,1261],{},"get_workflow_prerequisites"," returns the exact platform principal and\nscope), not a broad managed policy.",[905,1264,1265,1268],{},[908,1266,1267],{},"One role per purpose, per tenant."," Avoid a single god-role shared across workflows\nand organizations. Separate read-only collection from mutating actions.",[905,1270,1271,1274,1275,1277,1278,952],{},[908,1272,1273],{},"Prefer connection prerequisites over ad-hoc credentials."," Connections are the\ncanonical, auditable way to grant access; see ",[946,1276,236],{"href":237}," and\n",[946,1279,296],{"href":297},[905,1281,1282,1285],{},[908,1283,1284],{},"Rotate and review."," Treat every granted role as standing risk; review them on the\nsame cadence as Lumen alerts.",[1287,1288,1289],"callout",{"icon":259},[890,1290,1291,1292,1295,1296,952],{},"Because Orkestia never holds custody of your code or data, the cloud role ",[894,1293,1294],{},"is"," the\ntrust boundary. A least-privilege role that can only do what the workflow needs is the\nstrongest single control you have. Detail: ",[946,1297,138],{"href":139},[885,1299,1301],{"id":1300},"_4-govern-your-ai-actors-with-approvals","4. Govern your AI actors with approvals",[890,1303,1304,1307,1308,1311],{},[946,1305,1306],{"href":64},"Staff"," is the governance layer for fleets of AI agents —\norganizational structure, RBAC, sessions, and oversight. Agents are powerful precisely\nbecause they can discover and run capabilities over ",[946,1309,1310],{"href":170},"MCP","; that\nsame power is why high-impact actions need a human gate.",[1251,1313,1314,1328,1334,1340,1350],{},[905,1315,1316,1319,1320,1323,1324,1327],{},[908,1317,1318],{},"Bind roles, don't grant ambient power."," RBAC is enforced in the workflow engine via\ndeclared workflow ",[941,1321,1322],{},"Capability"," metadata (",[941,1325,1326],{},"RbacGuard","). An actor can only run what its\nrole binding allows; denied attempts surface in audit.",[905,1329,1330,1333],{},[908,1331,1332],{},"Put approval gates in front of high-impact actions."," Provisioning, spend, destructive\noperations, and anything customer-facing should require human-in-the-loop sign-off.",[905,1335,1336,1339],{},[908,1337,1338],{},"Scope actors into units."," Model staff as an organization (org → unit → actor) so\noversight and cost attribution have structure, not a flat pile of agents.",[905,1341,1342,1345,1346,1349],{},[908,1343,1344],{},"Audit everything, and read the audit."," ",[941,1347,1348],{},"staff.list-audit-events"," and workflow-run\nhistory are only useful if someone (or a Lumen alert) actually watches them.",[905,1351,1352,1355,1356,1359],{},[908,1353,1354],{},"Right-size the model and budget per actor."," Cost controls and model pricing live in\nthe ",[946,1357,1358],{"href":573},"Staff console","; a cheap model on a low-stakes task\nis the default, not the exception.",[1107,1361,1362],{},[890,1363,1364,1365,1368,1369,1371],{},"Start every new AI actor in the most restrictive mode that still lets it be useful, then\ngraduate its authority based on ",[908,1366,1367],{},"observed"," quality — not optimism. ",[946,1370,572],{"href":573}," walks through role bindings and\napproval setup.",[885,1373,1375],{"id":1374},"_5-set-lumen-alerts-on-the-signals-that-matter","5. Set Lumen alerts on the signals that matter",[890,1377,1378,1380,1381,952],{},[946,1379,437],{"href":78}," is the observability plane — it stores workflow state transitions\nand observability data so you can see what ran, what failed, and where time and money went.\nLogs alone are noise; alert on ",[908,1382,1383],{},"signals",[1036,1385,1386,1398],{},[1039,1387,1388],{},[1042,1389,1390,1393,1395],{},[1045,1391,1392],{},"Alert on",[1045,1394,1181],{},[1045,1396,1397],{},"Where",[1055,1399,1400,1413,1426,1439,1450],{},[1042,1401,1402,1405,1408],{},[1060,1403,1404],{},"Workflow failure rate (per type)",[1060,1406,1407],{},"Catches a broken integration or a bad deploy early",[1060,1409,1410],{},[946,1411,1412],{"href":459},"Observability with Lumen",[1042,1414,1415,1418,1421],{},[1060,1416,1417],{},"Stuck / stalled workflows",[1060,1419,1420],{},"A run that never reaches a terminal state ties up capacity",[1060,1422,1423],{},[941,1424,1425],{},"list_stuck_workflows",[1042,1427,1428,1431,1434],{},[1060,1429,1430],{},"Drift events",[1060,1432,1433],{},"Desired vs. observed runner state diverged",[1060,1435,1436],{},[946,1437,1438],{"href":201},"Drift Detection",[1042,1440,1441,1444,1447],{},[1060,1442,1443],{},"Denied RBAC attempts",[1060,1445,1446],{},"An actor reaching beyond its role binding",[1060,1448,1449],{},"Staff audit",[1042,1451,1452,1455,1458],{},[1060,1453,1454],{},"Cost per useful output",[1060,1456,1457],{},"Catches runaway agent spend before the invoice does",[1060,1459,1460],{},[946,1461,1358],{"href":573},[1107,1463,1464],{},[890,1465,1466],{},"Wire the alerts that have a clear owner and a clear response. An alert nobody acts on is\nworse than none — it trains people to ignore the dashboard.",[885,1468,1470],{"id":1469},"_6-right-size-your-runners","6. Right-size your runners",[890,1472,1473,1475],{},[946,1474,694],{"href":73}," are the execution capacity in your cloud — Kubernetes and\nmulti-cloud — that the engine dispatches work onto. Both under- and over-provisioning cost\nyou: too little capacity stalls workflows; too much burns money idle.",[1251,1477,1478,1484,1492,1498],{},[905,1479,1480,1483],{},[908,1481,1482],{},"Match capacity to observed load,"," not to peak fear. Use Lumen to see real\nconcurrency and queue depth before scaling.",[905,1485,1486,1489,1490,952],{},[908,1487,1488],{},"Keep drift detection on."," The reconciliation loop continuously compares desired vs.\nobserved runner state and surfaces — or, where you allow it, corrects — divergence. See\n",[946,1491,200],{"href":201},[905,1493,1494,1497],{},[908,1495,1496],{},"Let self-healing reconcile, but only over idempotent work"," (see section 1). Enable\nautomatic correction once you trust replay-safety; start with propose-only.",[905,1499,1500,1503,1504,952],{},[908,1501,1502],{},"Separate runner groups by purpose."," Keep agent-session runner groups distinct from\ngeneral workflow capacity so a noisy agent fleet can't starve production flows. See the\n",[946,1505,1506],{"href":134},"runner management guide",[1121,1508,1509],{},[890,1510,1511],{},"Enabling automatic self-healing over non-idempotent workflows can amplify a problem\ninstead of fixing it — a reconcile loop that re-runs a non-replay-safe step repeats its\nside effects. Audit first, automate second.",[885,1513,1515],{"id":1514},"_7-isolate-tenants-properly","7. Isolate tenants properly",[890,1517,935,1518,1521],{},[946,1519,1520],{"href":83},"multi-tenant by design",", down to \"Sign in\nwith Orkestia\" for exposing workflows to your own end-users. Isolation is not a single\nswitch — it is consistent scoping at every layer.",[1251,1523,1524,1534,1543,1554],{},[905,1525,1526,1529,1530,1533],{},[908,1527,1528],{},"Scope state per organization."," Your ",[941,1531,1532],{},"organization_uuid"," is resolved server-side from\nyour token and scopes every run automatically — never pass another org's ID, never share\na token across tenants.",[905,1535,1536,1539,1540,1542],{},[908,1537,1538],{},"Never share cloud credentials across tenants."," Each organization's\n",[946,1541,1248],{"href":237}," and roles are its own; a shared credential collapses the\nisolation boundary.",[905,1544,1545,1548,1549,1277,1551,1553],{},[908,1546,1547],{},"Scope identity for end-users."," When exposing workflows via\n",[946,1550,425],{"href":83},[946,1552,419],{"href":420},", keep end-user identity scoped to the tenant that owns\nthe app. (beta)",[905,1555,1556,1559],{},[908,1557,1558],{},"Attribute cost and audit per tenant"," so spend and access reviews map cleanly to an\norganization.",[1287,1561,1562],{"icon":725},[890,1563,1564],{},"Multi-tenancy is only as strong as its weakest shared resource. The most common leak is a\ncredential or connection reused across organizations — keep them strictly per-tenant.",[885,1566,1568],{"id":1567},"_8-prefer-compositions-over-bespoke-code","8. Prefer compositions over bespoke code",[890,1570,1571,1572,1575],{},"The platform ships a validated catalog of atomic workflows (one operation each) and\nbusiness workflows (composed multi-step flows). Before writing custom logic, ask whether a\n",[946,1573,1574],{"href":129},"composition"," of existing catalog entries does the job.",[1251,1577,1578,1593,1603,1609],{},[905,1579,1580,1583,1584,1587,1588,1592],{},[908,1581,1582],{},"Reuse the catalog."," Browse the ",[946,1585,1586],{"href":165},"workflow types registry","\nand the ",[946,1589,1591],{"href":948,"rel":1590},[950],"full catalog"," before building anything new.",[905,1594,1595,1598,1599,1602],{},[908,1596,1597],{},"Compose, don't fork."," The ",[946,1600,1601],{"href":129},"virtual engine"," lets you assemble\nvalidated steps into a DAG with type-checked input mappings — you get catalog knowledge\nand structural validation for free.",[905,1604,1605,1608],{},[908,1606,1607],{},"Let the engine own execution semantics."," Locking, retries, event sourcing, and audit\ncome from the engine; bespoke code outside it has to reimplement all of that (usually\nworse).",[905,1610,1611,1614,1615,1618,1619,952],{},[908,1612,1613],{},"If you must author new workflows,"," keep them atomic and idempotent, follow the\n",[941,1616,1617],{},"{provider}.{service}.{operation}"," naming and three-state pattern, and register them so\nthey're discoverable over ",[946,1620,1310],{"href":170},[1107,1622,1623],{},[890,1624,1625],{},"A composition is reviewable, diffable, and runs on the same reliable substrate as every\nother workflow. Bespoke code outside the engine is a maintenance liability that forfeits\nthe platform's reliability guarantees. When in doubt, compose.",[885,1627,1629],{"id":1628},"pre-production-checklist","Pre-production checklist",[890,1631,1632],{},"Run through this before promoting a workflow or runner group to production:",[1251,1634,1637,1647,1653,1659,1665,1671,1677,1683],{"className":1635},[1636],"contains-task-list",[905,1638,1641,1646],{"className":1639},[1640],"task-list-item",[1642,1643],"input",{"disabled":1644,"type":1645},true,"checkbox"," Every step in the flow is idempotent / replay-safe (§1)",[905,1648,1650,1652],{"className":1649},[1640],[1642,1651],{"disabled":1644,"type":1645}," Exploratory DGI design has been compiled to a stable composition (§2)",[905,1654,1656,1658],{"className":1655},[1640],[1642,1657],{"disabled":1644,"type":1645}," Cloud roles grant only what the workflow exercises (§3)",[905,1660,1662,1664],{"className":1661},[1640],[1642,1663],{"disabled":1644,"type":1645}," High-impact AI actions are gated by approvals; roles are bound, not ambient (§4)",[905,1666,1668,1670],{"className":1667},[1640],[1642,1669],{"disabled":1644,"type":1645}," Lumen alerts exist for failure rate, stuck runs, drift, and cost — each with an owner (§5)",[905,1672,1674,1676],{"className":1673},[1640],[1642,1675],{"disabled":1644,"type":1645}," Runner capacity matches observed load; drift detection is on (§6)",[905,1678,1680,1682],{"className":1679},[1640],[1642,1681],{"disabled":1644,"type":1645}," State, credentials, and identity are scoped per tenant; nothing shared across orgs (§7)",[905,1684,1686,1688],{"className":1685},[1640],[1642,1687],{"disabled":1644,"type":1645}," Catalog/composition reuse was preferred over bespoke code (§8)",[885,1690,1692],{"id":1691},"where-to-go-next","Where to go next",[958,1694,1695,1700,1706,1711],{},[961,1696,1697],{"icon":141,"title":138,"to":139},[890,1698,1699],{},"The Zero Trust / Zero Code Custody model that underpins least-privilege roles and tenant isolation.",[961,1701,1703],{"icon":198,"title":1702,"to":196},"Hybrid Execution Model",[890,1704,1705],{},"Why you design with AI and run with deterministic compositions.",[961,1707,1708],{"icon":80,"title":200,"to":201},[890,1709,1710],{},"The reconciliation loop behind right-sized, self-correcting runners.",[961,1712,1713],{"icon":186,"title":222,"to":223},[890,1714,1715],{},"How the control plane and your execution plane are deployed and operated.",{"title":1717,"searchDepth":1718,"depth":1719,"links":1720},"",1,2,[1721,1722,1723,1724,1725,1726,1727,1728,1729,1730,1731,1732],{"id":887,"depth":1719,"text":888},{"id":955,"depth":1719,"text":956},{"id":1013,"depth":1719,"text":1014},{"id":1134,"depth":1719,"text":1135},{"id":1233,"depth":1719,"text":1234},{"id":1300,"depth":1719,"text":1301},{"id":1374,"depth":1719,"text":1375},{"id":1469,"depth":1719,"text":1470},{"id":1514,"depth":1719,"text":1515},{"id":1567,"depth":1719,"text":1568},{"id":1628,"depth":1719,"text":1629},{"id":1691,"depth":1719,"text":1692},"A checklist-driven field guide for running Orkestia in production — idempotent workflows, least-privilege roles, governed AI actors, and right-sized runners","md",null,{},{"icon":234},{"title":231,"description":1733},"0uPJdM8gS35UyziUrNCs-ODnWQtzC_kRlFBb67DnEmU",[1741,1743],{"title":226,"path":227,"stem":228,"description":1742,"icon":229,"children":-1},"An operational runbook for watching runs, reading history, recovering stuck workflows, and tracing failures with Lumen",{"title":236,"path":237,"stem":238,"description":1744,"icon":241,"children":-1},"Connect your AWS accounts to Orkestia using secure cross-account IAM roles. Your cloud, your code, your control.",1790354046250]