svc-derbent-api
Derbent app API
- Environment
- operator
- Lifecycle
- runtime foundation
- State
- available
- Source
- static fixture
Read-only status and inventory contracts are represented through support-safe labels.
Wave A read-only evidence
Fixture-backed read models show what the future console may inspect without claiming live backend authority or protected action execution.
This route renders support-safe labels, IDs, timestamps, request/correlation identifiers, and summaries. It does not fetch live data, collect credentials, show secrets, or execute operations.
Current posture
Local records mirror backend-safe read-model fields only.
No auth, RBAC, approval, execution, shell, or live adapter is claimed.
Deploy, rollback, restore, restart, route, backup, and maintenance operations are blocked.
The overview renders labels, IDs, timestamps, and summaries instead of raw internals.
Contract-safe records
svc-derbent-api
Read-only status and inventory contracts are represented through support-safe labels.
svc-control-plane
Fixture-backed evidence is available; live adapters and protected execution remain absent.
route-status-readiness
Health/readiness posture uses bounded labels and does not expose backend origins.
route-evidence-inventory
Service, route, deployment, backup, and audit evidence routes are read-only.
dep-read-model-foundation
Read-only contract evidence exists; rollback execution is not available from this surface.
backup-evidence-fixture
Restore proof and retention posture are labelled as planned, not live backup proof.
audit-read-model-fixture
Synthetic fixture event proves display shape only; audit persistence remains backend-owned.
Required states
Future read clients should preserve layout with skeleton or progress text while evidence resolves.
No records yet is distinct from unavailable authority or failed loading.
Missing read-model families are labelled so operators do not infer complete evidence.
Checked timestamps remain visible when fixture or backend evidence may be old.
Production sign-in is required before this can become an operator console.
Denied states show safe recovery language without token contents or claims payloads.
Safe retry copy can use a request ID, but not stack traces or raw backend payloads.
Escalation copy should use support-safe identifiers and state that no action changed.
Protected operations stay explanatory and non-interactive until backend contracts exist.
Honest authority
Requires backend preflight, permission, approval, execution result, failure handling, and audit contracts.
Requires backend preflight, permission, approval, execution result, failure handling, and audit contracts.
Requires backend preflight, permission, approval, execution result, failure handling, and audit contracts.
Requires backend preflight, permission, approval, execution result, failure handling, and audit contracts.
Requires backend preflight, permission, approval, execution result, failure handling, and audit contracts.
Requires backend preflight, permission, approval, execution result, failure handling, and audit contracts.
Requires backend preflight, permission, approval, execution result, failure handling, and audit contracts.