Security and recovery
Fail-closed access, safe degradation, event recovery, database evidence, and deployment recovery boundaries.
Fail closed
- Missing or invalid JWTs receive
401. - Authenticated principals without the required capability receive
403. - Invalid CORS configuration stops startup.
- An unconfigured device capability cannot invent an operational success.
- Missing master data produces an explicit refusal, never an assumed identity.
Safe degradation
An outage must not invent identity, payment, settlement, or physical passage. Offline boarding may validate existing signed credentials. Offline counter sale remains a separate product decision and is not implied by the offline package.
Event recovery
Business state and the event-publication record commit together. Uncompleted publications are republished after restart. Consumers handle redelivery idempotently.
Kafka is transport. Recovery of authoritative state begins with the owning PostgreSQL schema and referenced evidence objects.
Historical evidence
Referential preserves retired stations, revoked identifiers and permits, effective-dated beneficiaries, itinerary revisions, schedule revisions, carrier changes, and import conflicts. Recovery procedures must preserve that history; rebuilding a projection must never rewrite its source.
Deployment checks
- Verify OIDC discovery and issuer URL.
- Verify public-path restrictions for identity administration.
- Exercise counter login, callback, deep link, and logout.
- Exercise back-office SSR, a server-function API call, and logout.
- Upload a multipart permit CSV through the gateway.
- Redeploy one upstream and verify DNS recovery.