# Portability / Infrastructure / Deployment

> Every principle in this category is listed as a record.

Page: Ontology · Principles
Canonical: https://banes-lab.com/ontology#architecture-category-portability-infrastructure-deployment

Listed in [Ontology · Principles](https://banes-lab.com/api/pages/ontology/principles.md), after [Correctness / Determinism / Verification](https://banes-lab.com/ontology/principles/architecture-category-correctness-determinism-verification.md) and before [Core Modular Design](https://banes-lab.com/ontology/principles/architecture-category-core-modular-design.md).

Every principle in this category is listed as a record. Each record carries its kind, its severity, the scopes it applies at and the layer it lives in, then the edge relations that join it to other records, the records that point back at it, the contracts that answer to it and the tensions it takes part in. The descriptors say how it is violated, detected, measured, repaired and enforced. Where the record carries one, an exemplar shows the shape before and after the principle is applied.

Relations diagram

The relations inside this category.

```mermaid
flowchart LR
n_portability["Portability"]
n_platform_independence["Platform Independence"]
n_environment_parity["Environment Parity"]
n_containerization["Containerization"]
n_infrastructure_as_code["Infrastructure as Code"]
n_standards_compliance["Standards Compliance"]
n_protocol_independence["Protocol Independence"]
n_configuration_externalization["Configuration Externalization"]
n_immutable_infrastructure["Immutable Infrastructure"]
n_platform_independence --> n_portability
n_environment_parity --> n_configuration_externalization
n_environment_parity --> n_infrastructure_as_code
n_containerization --> n_portability
n_containerization --> n_environment_parity
n_protocol_independence --> n_portability
n_configuration_externalization --> n_portability
n_configuration_externalization --> n_environment_parity
n_immutable_infrastructure --> n_infrastructure_as_code
n_immutable_infrastructure --> n_environment_parity
```

### Portability

- Kind: [quality-attribute](https://banes-lab.com/records/kind/quality-attribute.md)
- Category: [Portability / Infrastructure / Deployment](https://banes-lab.com/ontology/principles/architecture-category-portability-infrastructure-deployment.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: application, infrastructure, runtime
- Layer: [Resource Core](https://banes-lab.com/records/layer/resource-core.md)

Details

Definition
The degree to which software runs on another platform or environment without code changes.

Requires
[Abstraction](https://banes-lab.com/records/architecture/abstraction.md), [Standards](https://banes-lab.com/records/lexicon/standards.md)

Reinforces
[Replaceability](https://banes-lab.com/records/architecture/replaceability.md)

Enables
[Platform Migration](https://banes-lab.com/records/lexicon/platform-migration.md)

In tension with
[Platform Optimization](https://banes-lab.com/records/lexicon/platform-optimization.md)

Conflicts with
[Platform-Specific Coupling](https://banes-lab.com/records/lexicon/platform-specific-coupling.md)

Referenced by
[Interoperability](https://banes-lab.com/records/architecture/interoperability.md), [Platform Independence](https://banes-lab.com/records/architecture/platform-independence.md), [Containerization](https://banes-lab.com/records/architecture/containerization.md), [Protocol Independence](https://banes-lab.com/records/architecture/protocol-independence.md), [Configuration Externalization](https://banes-lab.com/records/architecture/configuration-externalization.md), [Low Coupling](https://banes-lab.com/records/architecture/low-coupling.md), [Abstraction](https://banes-lab.com/records/architecture/abstraction.md), [Independence](https://banes-lab.com/records/architecture/independence.md), [Case Dialect](https://banes-lab.com/records/architecture/case-dialect.md)

Tensions
[Portability / Platform Optimization](https://banes-lab.com/records/tension/platform-optimization-portability.md)

Distinct from
[Integration](https://banes-lab.com/records/lexicon/integration.md): Portability is running on another platform, while integration is being connected to other systems.

Distinct from
[Platform Optimization](https://banes-lab.com/records/lexicon/platform-optimization.md): Portability is running anywhere unchanged, while platform optimization is the tuning for one platform that it gives up.

Violated by
direct dependency on non-abstracted platform APIs

Detected by
platform-specific imports in core

Measured by
portability violation count

Refactored by
Add Adapter, Externalize Platform Dependency

Enforced by
dependency rules

Before

```typescript
const path = "C:\\foo\\data\\foos.json";
const processId = windowsApi.currentProcessId();
```

After

```typescript
const path = join(config.dataDirectory, "foos.json");
const processId = runtime.processId();
```

How it is checked

Checked by
dependency rules

Population
Every platform call, environment, configuration value and infrastructure resource the deployment uses

Freshness
A verdict stands until the code, the image, the configuration or the live infrastructure changes

Refusal
The import rule, config scan or drift detection fails the change or the deploy

Observation
Platform imports read from source, and the declared infrastructure compared with the live state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared infrastructure, which the live state is compared against

Depends on
[Abstraction](https://banes-lab.com/records/architecture/abstraction.md), [Standards](https://banes-lab.com/records/lexicon/standards.md), [Replaceability](https://banes-lab.com/records/architecture/replaceability.md), [Platform Migration](https://banes-lab.com/records/lexicon/platform-migration.md)

Shape it refuses
[Platform-Specific Coupling](https://banes-lab.com/records/lexicon/platform-specific-coupling.md)

### Platform Independence

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Portability / Infrastructure / Deployment](https://banes-lab.com/ontology/principles/architecture-category-portability-infrastructure-deployment.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: application, runtime
- Layer: [Resource Core](https://banes-lab.com/records/layer/resource-core.md)

Details

Definition
A design rule that portable layers reach the operating system and vendor services only through abstractions.

Requires
[Platform Abstraction](https://banes-lab.com/records/lexicon/platform-abstraction.md)

Reinforces
[Portability](https://banes-lab.com/records/architecture/portability.md)

Enables
[Cross-Platform Deployment](https://banes-lab.com/records/lexicon/cross-platform-deployment.md)

In tension with
[Native Optimization](https://banes-lab.com/records/lexicon/native-optimization.md)

Conflicts with
[OS/Vendor Lock-In](https://banes-lab.com/records/lexicon/os-vendor-lock-in.md)

Tensions
[Platform Independence / Native Optimization](https://banes-lab.com/records/tension/native-optimization-platform-independence.md)

Violated by
hardcoded platform assumptions

Detected by
OS-specific paths/APIs in portable layers

Measured by
cross-platform test pass rate

Refactored by
Abstract Platform API, Normalize Paths

Enforced by
cross-platform CI

Before

```typescript
function saveFoo(foo: Foo) { return winRegistry.write("Foo", foo); }
```

After

```typescript
interface FooPersistence { save(foo: Foo): Promise<void>; }
function saveFoo(foo: Foo, persistence: FooPersistence) { return persistence.save(foo); }
```

How it is checked

Checked by
cross-platform CI

Population
Every platform call, environment, configuration value and infrastructure resource the deployment uses

Freshness
A verdict stands until the code, the image, the configuration or the live infrastructure changes

Refusal
The import rule, config scan or drift detection fails the change or the deploy

Observation
Platform imports read from source, and the declared infrastructure compared with the live state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared infrastructure, which the live state is compared against

Depends on
[Platform Abstraction](https://banes-lab.com/records/lexicon/platform-abstraction.md), [Portability](https://banes-lab.com/records/architecture/portability.md), [Cross-Platform Deployment](https://banes-lab.com/records/lexicon/cross-platform-deployment.md)

Shape it refuses
[OS/Vendor Lock-In](https://banes-lab.com/records/lexicon/os-vendor-lock-in.md)

### Environment Parity

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Portability / Infrastructure / Deployment](https://banes-lab.com/ontology/principles/architecture-category-portability-infrastructure-deployment.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: dev, test, staging, production
- Layer: [Resource Core](https://banes-lab.com/records/layer/resource-core.md)

Details

Definition
A design rule that development, test, staging and production run the same build, differing only in configuration.

Requires
[Configuration Externalization](https://banes-lab.com/records/architecture/configuration-externalization.md), [Infrastructure as Code](https://banes-lab.com/records/architecture/infrastructure-as-code.md)

Reinforces
[Reproducibility](https://banes-lab.com/records/architecture/reproducibility.md)

Enables
[Reliable Deployment](https://banes-lab.com/records/lexicon/reliable-deployment.md)

In tension with
[Cost](https://banes-lab.com/records/lexicon/cost.md)

Conflicts with
[Snowflake Environments](https://banes-lab.com/records/lexicon/snowflake-environments.md)

Referenced by
[Containerization](https://banes-lab.com/records/architecture/containerization.md), [Configuration Externalization](https://banes-lab.com/records/architecture/configuration-externalization.md), [Immutable Infrastructure](https://banes-lab.com/records/architecture/immutable-infrastructure.md)

Tensions
[Environment Parity / Cost](https://banes-lab.com/records/tension/cost-environment-parity.md)

Distinct from
[Configuration Externalization](https://banes-lab.com/records/architecture/configuration-externalization.md): Environment parity runs the same build everywhere, while configuration externalization is how the differences are kept outside that build.

Violated by
environment-specific behavior not config-driven

Detected by
works-in-dev-only defects

Measured by
[environment drift](https://banes-lab.com/records/lexicon/environment-drift.md)

Refactored by
Containerize, Externalize Config, Use IaC

Enforced by
environment drift checks

Before

```typescript
if (env === "dev") useMemoryFooStore();
if (env === "prod") useSqlFooStore();
```

After

```typescript
const container = buildFooImage("foo-app:1.0.0");
runEnvironment("dev", container, devConfig);
runEnvironment("prod", container, prodConfig);
```

How it is checked

Checked by
environment drift checks

Population
Every platform call, environment, configuration value and infrastructure resource the deployment uses

Freshness
A verdict stands until the code, the image, the configuration or the live infrastructure changes

Refusal
The import rule, config scan or drift detection fails the change or the deploy

Observation
Platform imports read from source, and the declared infrastructure compared with the live state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared infrastructure, which the live state is compared against

Depends on
[Configuration Externalization](https://banes-lab.com/records/architecture/configuration-externalization.md), [Infrastructure as Code](https://banes-lab.com/records/architecture/infrastructure-as-code.md), [Reproducibility](https://banes-lab.com/records/architecture/reproducibility.md), [Reliable Deployment](https://banes-lab.com/records/lexicon/reliable-deployment.md)

Shape it refuses
[Snowflake Environments](https://banes-lab.com/records/lexicon/snowflake-environments.md)

### Containerization

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Portability / Infrastructure / Deployment](https://banes-lab.com/ontology/principles/architecture-category-portability-infrastructure-deployment.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: application, runtime, deployment
- Layer: [Resource Core](https://banes-lab.com/records/layer/resource-core.md)

Details

Definition
A mechanism that packages an application with its runtime dependencies into an image that runs the same on any host.

Requires
[Image Definition](https://banes-lab.com/records/lexicon/image-definition.md), [Externalized Config](https://banes-lab.com/records/lexicon/externalized-config.md)

Reinforces
[Portability](https://banes-lab.com/records/architecture/portability.md), [Environment Parity](https://banes-lab.com/records/architecture/environment-parity.md)

Enables
[Repeatable Runtime Packaging](https://banes-lab.com/records/lexicon/repeatable-runtime-packaging.md)

In tension with
[Image Complexity](https://banes-lab.com/records/lexicon/image-complexity.md)

Conflicts with
[Host-Coupled Deployment](https://banes-lab.com/records/lexicon/host-coupled-deployment.md)

Tensions
[Containerization / Image Complexity](https://banes-lab.com/records/tension/containerization-image-complexity.md)

Violated by
undeclared host dependency

Detected by
manual host setup requirements

Measured by
image reproducibility

Refactored by
Add Containerfile, Externalize Runtime Dependencies

Enforced by
image scans, build pipeline

Before

```typescript
installFooDependenciesOnHost();
startFooWithHostRuntime();
```

After

```typescript
const image = containerImage({
base: "node:22-alpine",
copy: ["dist", "package.json"],
command: ["node", "dist/main.js"],
});
```

How it is checked

Checked by
image scans, build pipeline

Population
Every platform call, environment, configuration value and infrastructure resource the deployment uses

Freshness
A verdict stands until the code, the image, the configuration or the live infrastructure changes

Refusal
The import rule, config scan or drift detection fails the change or the deploy

Observation
Platform imports read from source, and the declared infrastructure compared with the live state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared infrastructure, which the live state is compared against

Depends on
[Image Definition](https://banes-lab.com/records/lexicon/image-definition.md), [Externalized Config](https://banes-lab.com/records/lexicon/externalized-config.md), [Portability](https://banes-lab.com/records/architecture/portability.md), [Environment Parity](https://banes-lab.com/records/architecture/environment-parity.md), [Repeatable Runtime Packaging](https://banes-lab.com/records/lexicon/repeatable-runtime-packaging.md)

Shape it refuses
[Host-Coupled Deployment](https://banes-lab.com/records/lexicon/host-coupled-deployment.md)

### Infrastructure as Code

- Kind: [activity](https://banes-lab.com/records/kind/activity.md)
- Category: [Portability / Infrastructure / Deployment](https://banes-lab.com/ontology/principles/architecture-category-portability-infrastructure-deployment.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Mandatory for: managed infrastructure
- Scope: infrastructure, deployment
- Aliases: IaC
- Layer: [Resource Core](https://banes-lab.com/records/layer/resource-core.md)

Details

Definition
The practice of declaring infrastructure in versioned files and provisioning it from them.

Requires
[Declarative Configuration](https://banes-lab.com/records/architecture/declarative-configuration.md), [Version Control](https://banes-lab.com/records/lexicon/version-control.md)

Reinforces
[Reproducibility](https://banes-lab.com/records/architecture/reproducibility.md), [Governance](https://banes-lab.com/records/architecture/governance.md)

Enables
[Automated Provisioning](https://banes-lab.com/records/lexicon/automated-provisioning.md)

In tension with
[Tooling Complexity](https://banes-lab.com/records/lexicon/tooling-complexity.md)

Conflicts with
[Manual Infrastructure Changes](https://banes-lab.com/records/lexicon/manual-infrastructure-changes.md)

Referenced by
[Environment Parity](https://banes-lab.com/records/architecture/environment-parity.md), [Immutable Infrastructure](https://banes-lab.com/records/architecture/immutable-infrastructure.md), [Declarative Configuration](https://banes-lab.com/records/architecture/declarative-configuration.md)

Tensions
[Infrastructure as Code / Tooling Complexity](https://banes-lab.com/records/tension/infrastructure-as-code-tooling-complexity.md)

Violated by
untracked manual infra mutation

Detected by
drift between code and live infra

Measured by
drift count, IaC coverage

Refactored by
Codify Resource, Import State

Enforced by
[policy-as-code](https://banes-lab.com/records/architecture/policy-as-code.md), drift detection

Before

```typescript
cloudConsole.createDatabase("foo-prod");
cloudConsole.openPort(5432);
```

After

```typescript
const fooDatabase = databaseResource({
name: "foo-prod",
engine: "postgres",
encrypted: true,
networkPolicy: "foo-only",
});
```

How it is checked

Checked by
policy-as-code, drift detection

Population
Every platform call, environment, configuration value and infrastructure resource the deployment uses

Freshness
A verdict stands until the code, the image, the configuration or the live infrastructure changes

Refusal
The import rule, config scan or drift detection fails the change or the deploy

Observation
Platform imports read from source, and the declared infrastructure compared with the live state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared infrastructure, which the live state is compared against

Depends on
[Declarative Configuration](https://banes-lab.com/records/architecture/declarative-configuration.md), [Version Control](https://banes-lab.com/records/lexicon/version-control.md), [Reproducibility](https://banes-lab.com/records/architecture/reproducibility.md), [Governance](https://banes-lab.com/records/architecture/governance.md), [Automated Provisioning](https://banes-lab.com/records/lexicon/automated-provisioning.md)

Shape it refuses
[Manual Infrastructure Changes](https://banes-lab.com/records/lexicon/manual-infrastructure-changes.md)

### Standards Compliance

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Portability / Infrastructure / Deployment](https://banes-lab.com/ontology/principles/architecture-category-portability-infrastructure-deployment.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: protocol, security, data, infrastructure
- Layer: [Resource Core](https://banes-lab.com/records/layer/resource-core.md)

Details

Definition
A rule or precondition that an implementation conforms to the published standard for its protocol, format or domain.

Requires
[Applicable Standard](https://banes-lab.com/records/lexicon/applicable-standard.md)

Reinforces
[Interoperability](https://banes-lab.com/records/architecture/interoperability.md), [Compliance](https://banes-lab.com/records/architecture/compliance.md)

Enables
[Certification/Compatibility](https://banes-lab.com/records/lexicon/certification-compatibility.md)

In tension with
[Innovation/Flexibility](https://banes-lab.com/records/lexicon/innovation-flexibility.md)

Conflicts with
[Proprietary Deviation](https://banes-lab.com/records/lexicon/proprietary-deviation.md)

Tensions
[Standards Compliance / Innovation/Flexibility](https://banes-lab.com/records/tension/innovation-flexibility-standards-compliance.md)

Distinct from
[Compliance](https://banes-lab.com/records/architecture/compliance.md): Standards compliance is technical conformance to a published protocol or format, while compliance is implementing and evidencing the controls a regulation requires.

Distinct from
[Applicable Standard](https://banes-lab.com/records/lexicon/applicable-standard.md): Standards compliance is conforming, while the applicable standard is the one standard identified to conform to.

Violated by
nonconforming implementation

Detected by
conformance test failure

Measured by
standard compliance score

Refactored by
Align Implementation, Add Conformance Tests

Enforced by
standards checks

Before

```typescript
const payload = encodePrivateFooBinary(foo);
```

After

```typescript
const payload: JsonFooV1 = toJsonFoo(foo);
http.send(JSON.stringify(payload), { contentType: "application/json; charset=utf-8" });
```

How it is checked

Checked by
standards checks

Population
Every platform call, environment, configuration value and infrastructure resource the deployment uses

Freshness
A verdict stands until the code, the image, the configuration or the live infrastructure changes

Refusal
The import rule, config scan or drift detection fails the change or the deploy

Observation
Platform imports read from source, and the declared infrastructure compared with the live state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared infrastructure, which the live state is compared against

Depends on
[Applicable Standard](https://banes-lab.com/records/lexicon/applicable-standard.md), [Interoperability](https://banes-lab.com/records/architecture/interoperability.md), [Compliance](https://banes-lab.com/records/architecture/compliance.md), [Certification/Compatibility](https://banes-lab.com/records/lexicon/certification-compatibility.md)

Shape it refuses
[Proprietary Deviation](https://banes-lab.com/records/lexicon/proprietary-deviation.md)

### Protocol Independence

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Portability / Infrastructure / Deployment](https://banes-lab.com/ontology/principles/architecture-category-portability-infrastructure-deployment.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: integration, service boundary
- Layer: [Resource Core](https://banes-lab.com/records/layer/resource-core.md)

Details

Definition
A design rule that domain logic is written against ports, and each transport protocol reaches it through its own adapter.

Requires
[Adapter/Port Abstraction](https://banes-lab.com/records/lexicon/adapter-port-abstraction.md)

Reinforces
[Portability](https://banes-lab.com/records/architecture/portability.md), [Replaceability](https://banes-lab.com/records/architecture/replaceability.md)

Enables
[Protocol Swap](https://banes-lab.com/records/lexicon/protocol-swap.md)

In tension with
[Protocol-Specific Features](https://banes-lab.com/records/lexicon/protocol-specific-features.md)

Conflicts with
[Protocol-Coupled Domain Logic](https://banes-lab.com/records/lexicon/protocol-coupled-domain-logic.md)

Tensions
[Protocol Independence / Protocol-Specific Features](https://banes-lab.com/records/tension/protocol-independence-protocol-specific-features.md)

Violated by
HTTP/gRPC/etc. types in domain core

Detected by
protocol imports in core layer

Measured by
protocol leakage count

Refactored by
Add Port, Add Protocol Adapter

Enforced by
import rules

Before

```typescript
class FooService {
handleHttp(request: HttpRequest) { return fooStore.save(request.body); }
}
```

After

```typescript
class CreateFoo {
constructor(private readonly store: FooStore) {}
execute(input: CreateFooInput) { return this.store.save(Foo.create(input)); }
}
httpAdapter.bind(createFoo);
grpcAdapter.bind(createFoo);
```

How it is checked

Checked by
import rules

Population
Every platform call, environment, configuration value and infrastructure resource the deployment uses

Freshness
A verdict stands until the code, the image, the configuration or the live infrastructure changes

Refusal
The import rule, config scan or drift detection fails the change or the deploy

Observation
Platform imports read from source, and the declared infrastructure compared with the live state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared infrastructure, which the live state is compared against

Depends on
[Adapter/Port Abstraction](https://banes-lab.com/records/lexicon/adapter-port-abstraction.md), [Portability](https://banes-lab.com/records/architecture/portability.md), [Replaceability](https://banes-lab.com/records/architecture/replaceability.md), [Protocol Swap](https://banes-lab.com/records/lexicon/protocol-swap.md)

Shape it refuses
[Protocol-Coupled Domain Logic](https://banes-lab.com/records/lexicon/protocol-coupled-domain-logic.md)

### Configuration Externalization

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Portability / Infrastructure / Deployment](https://banes-lab.com/ontology/principles/architecture-category-portability-infrastructure-deployment.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: application, deployment, runtime
- Layer: [Resource Core](https://banes-lab.com/records/layer/resource-core.md)

Details

Definition
A design rule that environment-specific values are read from validated external configuration at startup.

Requires
[Config Schema](https://banes-lab.com/records/lexicon/config-schema.md), [Secure Config Handling](https://banes-lab.com/records/lexicon/secure-config-handling.md)

Reinforces
[Portability](https://banes-lab.com/records/architecture/portability.md), [Environment Parity](https://banes-lab.com/records/architecture/environment-parity.md)

Enables
[Environment-Specific Deployment](https://banes-lab.com/records/lexicon/environment-specific-deployment.md)

In tension with
[Config Sprawl](https://banes-lab.com/records/lexicon/config-sprawl.md)

Conflicts with
[Hardcoded Configuration](https://banes-lab.com/records/architecture/hardcoded-configuration.md)

Referenced by
[Environment Parity](https://banes-lab.com/records/architecture/environment-parity.md)

Tensions
[Configuration Externalization / Config Sprawl](https://banes-lab.com/records/tension/config-sprawl-configuration-externalization.md)

Violated by
environment values hardcoded in code

Detected by
hardcoded URLs/secrets/paths

Measured by
externalized config coverage

Refactored by
Move to Config, Add Validation

Enforced by
secret/config scans

Before

```typescript
const config = {
fooUrl: "https://foo.prod.example",
retries: 3,
};
```

After

```typescript
type FooConfig = Readonly<{ fooUrl: URL; retries: number }>;
const config = FooConfigSchema.parse({
fooUrl: process.env.FOO_URL,
retries: process.env.FOO_RETRIES,
});
```

How it is checked

Checked by
secret/config scans

Population
Every platform call, environment, configuration value and infrastructure resource the deployment uses

Freshness
A verdict stands until the code, the image, the configuration or the live infrastructure changes

Refusal
The import rule, config scan or drift detection fails the change or the deploy

Observation
Platform imports read from source, and the declared infrastructure compared with the live state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared infrastructure, which the live state is compared against

Depends on
[Config Schema](https://banes-lab.com/records/lexicon/config-schema.md), [Secure Config Handling](https://banes-lab.com/records/lexicon/secure-config-handling.md), [Portability](https://banes-lab.com/records/architecture/portability.md), [Environment Parity](https://banes-lab.com/records/architecture/environment-parity.md), [Environment-Specific Deployment](https://banes-lab.com/records/lexicon/environment-specific-deployment.md)

Shape it refuses
[Hardcoded Configuration](https://banes-lab.com/records/architecture/hardcoded-configuration.md)

### Immutable Infrastructure

- Kind: [approach](https://banes-lab.com/records/kind/approach.md)
- Category: [Portability / Infrastructure / Deployment](https://banes-lab.com/ontology/principles/architecture-category-portability-infrastructure-deployment.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Mandatory for: managed infrastructure
- Scope: infrastructure, deployment, reproducibility
- Layer: [Resource Core](https://banes-lab.com/records/layer/resource-core.md)

Details

Definition
An approach in which servers are replaced from a new image for every change, instead of being patched in place.

Requires
[Infrastructure as Code](https://banes-lab.com/records/architecture/infrastructure-as-code.md)

Reinforces
[Environment Parity](https://banes-lab.com/records/architecture/environment-parity.md), [Reproducibility](https://banes-lab.com/records/architecture/reproducibility.md)

Enables
[Deterministic Redeploys](https://banes-lab.com/records/lexicon/deterministic-redeploys.md), [Instance Replacement over Mutation](https://banes-lab.com/records/lexicon/instance-replacement-over-mutation.md)

In tension with
[Deploy Time](https://banes-lab.com/records/lexicon/deploy-time.md)

Conflicts with
[In-Place Server Mutation](https://banes-lab.com/records/lexicon/in-place-server-mutation.md)

Tensions
[Immutable Infrastructure / Deploy Time](https://banes-lab.com/records/tension/deploy-time-immutable-infrastructure.md)

Violated by
patching running servers in place

Detected by
SSH mutation of live instances

Measured by
config drift across instances

Refactored by
Replace Instances from Immutable Images

Enforced by
deployment review

Before

```typescript
ssh(server, "apt-get update && systemctl restart foo");
```

After

```typescript
const image = buildFooImage("foo:1.4.0");
replaceInstances("foo", image);
```

How it is checked

Checked by
deployment review

Population
Every platform call, environment, configuration value and infrastructure resource the deployment uses

Freshness
A verdict stands until the code, the image, the configuration or the live infrastructure changes

Refusal
The import rule, config scan or drift detection fails the change or the deploy

Observation
Platform imports read from source, and the declared infrastructure compared with the live state

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared infrastructure, which the live state is compared against

Depends on
[Infrastructure as Code](https://banes-lab.com/records/architecture/infrastructure-as-code.md), [Environment Parity](https://banes-lab.com/records/architecture/environment-parity.md), [Reproducibility](https://banes-lab.com/records/architecture/reproducibility.md), [Deterministic Redeploys](https://banes-lab.com/records/lexicon/deterministic-redeploys.md), [Instance Replacement over Mutation](https://banes-lab.com/records/lexicon/instance-replacement-over-mutation.md)

Shape it refuses
[In-Place Server Mutation](https://banes-lab.com/records/lexicon/in-place-server-mutation.md)

## Links to

- [quality-attribute](https://banes-lab.com/records/kind/quality-attribute.md)
- [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- [Resource Core](https://banes-lab.com/records/layer/resource-core.md)
- [Abstraction](https://banes-lab.com/records/architecture/abstraction.md)
- [Standards](https://banes-lab.com/records/lexicon/standards.md)
- [Replaceability](https://banes-lab.com/records/architecture/replaceability.md)
- [Platform Migration](https://banes-lab.com/records/lexicon/platform-migration.md)
- [Platform Optimization](https://banes-lab.com/records/lexicon/platform-optimization.md)
- [Platform-Specific Coupling](https://banes-lab.com/records/lexicon/platform-specific-coupling.md)
- [Interoperability](https://banes-lab.com/records/architecture/interoperability.md)
- [Platform Independence](https://banes-lab.com/records/architecture/platform-independence.md)
- [Containerization](https://banes-lab.com/records/architecture/containerization.md)
- [Protocol Independence](https://banes-lab.com/records/architecture/protocol-independence.md)
- [Configuration Externalization](https://banes-lab.com/records/architecture/configuration-externalization.md)
- [Low Coupling](https://banes-lab.com/records/architecture/low-coupling.md)
- [Independence](https://banes-lab.com/records/architecture/independence.md)
- [Case Dialect](https://banes-lab.com/records/architecture/case-dialect.md)
- [Portability / Platform Optimization](https://banes-lab.com/records/tension/platform-optimization-portability.md)
- [Integration](https://banes-lab.com/records/lexicon/integration.md)
- [principle](https://banes-lab.com/records/kind/principle.md)
- [Platform Abstraction](https://banes-lab.com/records/lexicon/platform-abstraction.md)
- [Portability](https://banes-lab.com/records/architecture/portability.md)
- [Cross-Platform Deployment](https://banes-lab.com/records/lexicon/cross-platform-deployment.md)
- [Native Optimization](https://banes-lab.com/records/lexicon/native-optimization.md)
- [OS/Vendor Lock-In](https://banes-lab.com/records/lexicon/os-vendor-lock-in.md)
- [Platform Independence / Native Optimization](https://banes-lab.com/records/tension/native-optimization-platform-independence.md)
- [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- [Infrastructure as Code](https://banes-lab.com/records/architecture/infrastructure-as-code.md)
- [Reproducibility](https://banes-lab.com/records/architecture/reproducibility.md)
- [Reliable Deployment](https://banes-lab.com/records/lexicon/reliable-deployment.md)
- [Cost](https://banes-lab.com/records/lexicon/cost.md)
- [Snowflake Environments](https://banes-lab.com/records/lexicon/snowflake-environments.md)
- [Immutable Infrastructure](https://banes-lab.com/records/architecture/immutable-infrastructure.md)
- [Environment Parity / Cost](https://banes-lab.com/records/tension/cost-environment-parity.md)
- [Environment Drift](https://banes-lab.com/records/lexicon/environment-drift.md)
- [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- [Image Definition](https://banes-lab.com/records/lexicon/image-definition.md)
- [Externalized Config](https://banes-lab.com/records/lexicon/externalized-config.md)
- [Environment Parity](https://banes-lab.com/records/architecture/environment-parity.md)
- [Repeatable Runtime Packaging](https://banes-lab.com/records/lexicon/repeatable-runtime-packaging.md)
- [Image Complexity](https://banes-lab.com/records/lexicon/image-complexity.md)
- [Host-Coupled Deployment](https://banes-lab.com/records/lexicon/host-coupled-deployment.md)
- [Containerization / Image Complexity](https://banes-lab.com/records/tension/containerization-image-complexity.md)
- [activity](https://banes-lab.com/records/kind/activity.md)
- [Declarative Configuration](https://banes-lab.com/records/architecture/declarative-configuration.md)
- [Version Control](https://banes-lab.com/records/lexicon/version-control.md)
- [Governance](https://banes-lab.com/records/architecture/governance.md)
- [Automated Provisioning](https://banes-lab.com/records/lexicon/automated-provisioning.md)
- [Tooling Complexity](https://banes-lab.com/records/lexicon/tooling-complexity.md)
- [Manual Infrastructure Changes](https://banes-lab.com/records/lexicon/manual-infrastructure-changes.md)
- [Infrastructure as Code / Tooling Complexity](https://banes-lab.com/records/tension/infrastructure-as-code-tooling-complexity.md)
- [Policy as Code](https://banes-lab.com/records/architecture/policy-as-code.md)
- [constraint](https://banes-lab.com/records/kind/constraint.md)
- [Applicable Standard](https://banes-lab.com/records/lexicon/applicable-standard.md)
- [Compliance](https://banes-lab.com/records/architecture/compliance.md)
- [Certification/Compatibility](https://banes-lab.com/records/lexicon/certification-compatibility.md)
- [Innovation/Flexibility](https://banes-lab.com/records/lexicon/innovation-flexibility.md)
- [Proprietary Deviation](https://banes-lab.com/records/lexicon/proprietary-deviation.md)
- [Standards Compliance / Innovation/Flexibility](https://banes-lab.com/records/tension/innovation-flexibility-standards-compliance.md)
- [Adapter/Port Abstraction](https://banes-lab.com/records/lexicon/adapter-port-abstraction.md)
- [Protocol Swap](https://banes-lab.com/records/lexicon/protocol-swap.md)
- [Protocol-Specific Features](https://banes-lab.com/records/lexicon/protocol-specific-features.md)
- [Protocol-Coupled Domain Logic](https://banes-lab.com/records/lexicon/protocol-coupled-domain-logic.md)
- [Protocol Independence / Protocol-Specific Features](https://banes-lab.com/records/tension/protocol-independence-protocol-specific-features.md)
- [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- [Config Schema](https://banes-lab.com/records/lexicon/config-schema.md)
- [Secure Config Handling](https://banes-lab.com/records/lexicon/secure-config-handling.md)
- [Environment-Specific Deployment](https://banes-lab.com/records/lexicon/environment-specific-deployment.md)
- [Config Sprawl](https://banes-lab.com/records/lexicon/config-sprawl.md)
- [Hardcoded Configuration](https://banes-lab.com/records/architecture/hardcoded-configuration.md)
- [Configuration Externalization / Config Sprawl](https://banes-lab.com/records/tension/config-sprawl-configuration-externalization.md)
- [approach](https://banes-lab.com/records/kind/approach.md)
- [Deterministic Redeploys](https://banes-lab.com/records/lexicon/deterministic-redeploys.md)
- [Instance Replacement over Mutation](https://banes-lab.com/records/lexicon/instance-replacement-over-mutation.md)
- [Deploy Time](https://banes-lab.com/records/lexicon/deploy-time.md)
- [In-Place Server Mutation](https://banes-lab.com/records/lexicon/in-place-server-mutation.md)
- [Immutable Infrastructure / Deploy Time](https://banes-lab.com/records/tension/deploy-time-immutable-infrastructure.md)

## Linked from

- [The layer topology](https://banes-lab.com/ontology/schema/the-layer-topology.md)
- [The membership](https://banes-lab.com/ontology/schema/the-membership.md)
