SmartGare
Operations

Security and recovery

Fail-closed access, safe degradation, event recovery, database evidence, and deployment recovery boundaries.

Fail closed

  • Missing or invalid JWTs receive 401.
  • Authenticated principals without the required capability receive 403.
  • Invalid CORS configuration stops startup.
  • An unconfigured device capability cannot invent an operational success.
  • Missing master data produces an explicit refusal, never an assumed identity.

Safe degradation

An outage must not invent identity, payment, settlement, or physical passage. Offline boarding may validate existing signed credentials. Offline counter sale remains a separate product decision and is not implied by the offline package.

Event recovery

Business state and the event-publication record commit together. Uncompleted publications are republished after restart. Consumers handle redelivery idempotently.

Kafka is transport. Recovery of authoritative state begins with the owning PostgreSQL schema and referenced evidence objects.

Historical evidence

Referential preserves retired stations, revoked identifiers and permits, effective-dated beneficiaries, itinerary revisions, schedule revisions, carrier changes, and import conflicts. Recovery procedures must preserve that history; rebuilding a projection must never rewrite its source.

Deployment checks

  1. Verify OIDC discovery and issuer URL.
  2. Verify public-path restrictions for identity administration.
  3. Exercise counter login, callback, deep link, and logout.
  4. Exercise back-office SSR, a server-function API call, and logout.
  5. Upload a multipart permit CSV through the gateway.
  6. Redeploy one upstream and verify DNS recovery.

On this page