K07 · evidence-bundled critical-infrastructure assurance
Architecture Decision Records
Direct answer
K07 publishes ten reversible reference decisions so critical-datacenter architecture can be challenged, sourced, site-tailored, and superseded rather than hidden inside prose.
Decision register
Power boundary and load-rejection protection
Separate safety, generation, microgrid and compute control authority; define safe load-shed and load-rejection envelopes; require independent protection and event evidence.
Cooling independent safe state
Define minimum cooling functions, independent local control, fail-safe states, protected sensors, and restoration priority outside the ordinary compute orchestration plane.
Deterministic OT isolation
Use independent trust zones, explicit one-way or narrowly mediated flows, deny-by-default control paths, and non-digital or independently controlled safety functions where consequence analysis requires them.
Management-plane separation and recovery
Separate management networks and identities, require hardware-rooted attestation where available, restrict update authority, and maintain an independently recoverable management baseline.
Trusted time, sequence, and event ordering
Use multiple time sources, bounded drift, authenticated distribution where supported, local monotonic sequence, and explicit degraded-time operation.
Workload, device, and service identity
Bind every workload, device, model service and actuator to a scoped cryptographic identity, policy decision, key lifecycle, and revocation path.
Model and data provenance gate
Require model, code, prompt-policy, tool, evaluation and data-lineage manifests; gate promotion on signed or checksummed evidence and rollback readiness.
Multi-sensor physical evidence and disagreement
Require independent modalities, confidence and time quality, disagreement handling, safe delay measures, and authority-separated actuation.
Communications-loss autonomy envelope
Define local minimum mission, pre-authorized containment actions, degraded-time and degraded-sensor rules, expiration, return-to-safe-state, and evidence synchronization after reconnection.
Restoration known-good chain
Maintain immutable or protected manifests, clean-room recovery, independent key and artifact verification, sequenced restoration, and post-restoration monitoring before readiness is restored.
Decision discipline
Each record preserves context, proposed decision, alternatives, consequences, source relationships, and conditions that defeat or reverse the choice. A reference ADR does not decide a named facility without authorized site facts and accountable approval.