Saltar al contenido principal

ADR 036 — Control / data / money plane boundaries

Context​

AlphaSwarm already separates concerns across packages. Source docs risk reintroducing a unified “Simulation platform” that owns infra, data, and orders. Track A+E/D verified:

  • Mutation: WorkloadRuntime, TerraformRuntime, /manage/*.
  • Execution dispatch: alphaswarm_worker with Plane LLM vs MONEY.
  • Data writes: iceberg_catalog.append_arrow; agents via DataMCP.
  • Cells: Kustomize + ArgoCD — no Terraform cell module.
  • Postgres is canonical for ledgers; controller sinks audit via HTTP/JSONL.

Decision​

PlaneSole authoritiesForbidden
Controlalphaswarm_controller /manage/*; WorkloadRuntime; TerraformRuntime; DeploymentSpecSecond deploy/scheduler CP; raw terraform/kubectl outside providers
DataIceberg wrapper; DataMCP; LineageBus; ingest/streaming ownersAgent ORM/Iceberg direct; silent critical event drops
MoneyNativeExecutor; BotRuntime adapters; RiskLimits; kill switch; GateChain/metadata_gateLLM consultation inside risk gate; Ray/Dask/Spark for MONEY
LLM / AgentAgentRuntime / WorkflowRuntime / KB toolsVenue credentials; raising hard risk limits; order send without OrderIntent

Do not create a second scheduler, execution, MLOps, or deployment control plane. Compose the existing ones via the alphaswarm facade (ADR-033).

Consequences​

  • New features must declare their plane and owner package.
  • Default-OFF flags that protect plane isolation (enable_money_plane, RLS, MCP audience, halt propagation) require explicit enablement plans before live expansion.
  • Cell topology changes go through Kustomize/GitOps, not a new Terraform cell module.