Architecture Decision Records¶
Architecture Decision Records for ABOS. Each ADR is immutable once accepted; supersede rather than edit.
| ADR | Title | Status | Date |
|---|---|---|---|
| ADR-0001 | Orchestration-first, not system-of-record | Accepted | 2026-07-25 |
| ADR-0002 | Engines vs products | Accepted | 2026-07-25 |
| ADR-0003 | Config, not code, for client specificity | Accepted | 2026-07-25 |
| ADR-0004 | Structured predicates only for rules | Accepted | 2026-07-25 |
| ADR-0005 | Rule precedence | Accepted | 2026-07-25 |
| ADR-0006 | Control plane holds the map, not client content | Accepted | 2026-07-25 |
| ADR-0007 | Multi-tenant deployment topology | Accepted | 2026-07-25 |
| ADR-0008 | Data residency and region | Accepted | 2026-07-25 |
| ADR-0009 | LLM provider strategy | Accepted | 2026-07-25 |
| ADR-0010 | Secrets handling | Accepted (extended by ADR-0027) | 2026-07-25 |
| ADR-0011 | Surfaces: BOS Console vs Client App | Accepted | 2026-07-25 |
| ADR-0012 | Client exit / data ownership | Accepted | 2026-07-25 |
| ADR-0013 | Tenant deployment modes (Demo / Pilot / Full) | Accepted | 2026-07-25 |
| ADR-0014 | VPS provisioning & server hardening baseline | Superseded by ADR-0021–0027 | 2026-07-25 |
| ADR-0015 | Staging and production environments | Accepted | 2026-07-25 |
| ADR-0016 | Golden templates vs disposable demo vs client pilot | Accepted | 2026-07-25 |
| ADR-0017 | Employees as Principals; cross-employee isolation via Postgres RLS | Accepted | 2026-07-31 |
| ADR-0018 | Hermes Agent not adopted; Hermes models a future self-hosted candidate | Accepted | 2026-07-31 |
| ADR-0019 | SkillOpt: optional, deferred learned-layer optimiser | Accepted | 2026-07-31 |
| ADR-0020 | WebAssembly/WASI held as a watch item for per-tool sandboxing | Accepted (Watch) | 2026-07-31 |
| ADR-0021 | Host baseline and hardening | Accepted | 2026-08-17 |
| ADR-0022 | Edge routing, TLS and hostname scheme | Accepted | 2026-08-17 |
| ADR-0023 | Container and tenant isolation | Accepted | 2026-08-17 |
| ADR-0024 | Ansible repository layout and provisioning model | Accepted | 2026-08-17 |
| ADR-0025 | Control-plane co-location and migration trigger | Accepted | 2026-08-17 |
| ADR-0026 | Backup and retention posture | Accepted | 2026-08-17 |
| ADR-0027 | Secrets and credential custody | Accepted | 2026-08-17 |
| ADR-0028 | Documentation surface | Accepted | 2026-08-17 |
| ADR-0029 | Deployment targets from a single repository | Accepted | 2026-08-17 |
| ADR-0030 | Multi-host composition — what is global, what is per host | Accepted | 2026-08-17 |
Superseded ADRs¶
ADR-0014 recorded nine unrelated decisions in one document, so no single part could be revised without reopening all of it. It is split as follows:
| ADR-0014 section | Now |
|---|---|
| §1 provider, sizing | ADR-0021 |
| §1 control-plane co-location | ADR-0025 |
| §2 SSH, §3 firewall | ADR-0021 |
| §4 Caddy, TLS | ADR-0022 |
| §5 Docker, §6 Postgres, §7 n8n | ADR-0023 |
| §8 backups | ADR-0026 |
| §9 secrets | ADR-0027 |