K07 · evidence-bundled critical-infrastructure assurance

Architecture Decision Records

Direct answer

K07 publishes ten reversible reference decisions so critical-datacenter architecture can be challenged, sourced, site-tailored, and superseded rather than hidden inside prose.

Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.

Decision register

ADR-K07-001

Power boundary and load-rejection protection

Separate safety, generation, microgrid and compute control authority; define safe load-shed and load-rejection envelopes; require independent protection and event evidence.

Status: PROPOSED REFERENCE DECISION · 4 reversal or invalidation conditions

ADR-K07-002

Cooling independent safe state

Define minimum cooling functions, independent local control, fail-safe states, protected sensors, and restoration priority outside the ordinary compute orchestration plane.

Status: PROPOSED REFERENCE DECISION · 4 reversal or invalidation conditions

ADR-K07-003

Deterministic OT isolation

Use independent trust zones, explicit one-way or narrowly mediated flows, deny-by-default control paths, and non-digital or independently controlled safety functions where consequence analysis requires them.

Status: PROPOSED REFERENCE DECISION · 4 reversal or invalidation conditions

ADR-K07-004

Management-plane separation and recovery

Separate management networks and identities, require hardware-rooted attestation where available, restrict update authority, and maintain an independently recoverable management baseline.

Status: PROPOSED REFERENCE DECISION · 4 reversal or invalidation conditions

ADR-K07-005

Trusted time, sequence, and event ordering

Use multiple time sources, bounded drift, authenticated distribution where supported, local monotonic sequence, and explicit degraded-time operation.

Status: PROPOSED REFERENCE DECISION · 4 reversal or invalidation conditions

ADR-K07-006

Workload, device, and service identity

Bind every workload, device, model service and actuator to a scoped cryptographic identity, policy decision, key lifecycle, and revocation path.

Status: PROPOSED REFERENCE DECISION · 4 reversal or invalidation conditions

ADR-K07-007

Model and data provenance gate

Require model, code, prompt-policy, tool, evaluation and data-lineage manifests; gate promotion on signed or checksummed evidence and rollback readiness.

Status: PROPOSED REFERENCE DECISION · 4 reversal or invalidation conditions

ADR-K07-008

Multi-sensor physical evidence and disagreement

Require independent modalities, confidence and time quality, disagreement handling, safe delay measures, and authority-separated actuation.

Status: PROPOSED REFERENCE DECISION · 4 reversal or invalidation conditions

ADR-K07-009

Communications-loss autonomy envelope

Define local minimum mission, pre-authorized containment actions, degraded-time and degraded-sensor rules, expiration, return-to-safe-state, and evidence synchronization after reconnection.

Status: PROPOSED REFERENCE DECISION · 4 reversal or invalidation conditions

ADR-K07-010

Restoration known-good chain

Maintain immutable or protected manifests, clean-room recovery, independent key and artifact verification, sequenced restoration, and post-restoration monitoring before readiness is restored.

Status: PROPOSED REFERENCE DECISION · 4 reversal or invalidation conditions

Decision discipline

Each record preserves context, proposed decision, alternatives, consequences, source relationships, and conditions that defeat or reverse the choice. A reference ADR does not decide a named facility without authorized site facts and accountable approval.