Continuity controls
Make the pipeline recoverable without the engineer's private run command.
Pipelines become dependent when interval logic, retry exceptions, state locations, backfill flags, correction scripts, consumer caveats, and recovery order live in shell history or one person's memory. The client record should let another qualified engineer trace, operate, repair, reconcile, and retire the path.
- Client-held pipeline registry
- Purpose, owners, sources, consumers, records, schemas, time and delivery semantics, schedules, triggers, jobs, state, checkpoints, quality rules, lineage, service objectives, access, dependencies, releases, incidents, backfills, corrections, changes, and retirement state remain findable and versioned.
- Reproducible run chain
- Approved code, dependencies, environments, configurations, secrets references, source and contract versions, logical intervals, run identities, input and output manifests, state, tests, lineage, quality evidence, deployment artifacts, and reconciliations can reproduce or explain a selected run without undocumented edits.
- Least-privilege data path
- Individual source, transport, compute, state, storage, scheduler, lineage, telemetry, deployment, replay, quarantine, consumer, administration, and incident access is approved for the role, reviewable, and removed through an owned transition path.
- Demonstrated handoff
- A receiving engineer can obtain approved access, trace one record and interval, deploy a reviewed change, diagnose a failed stage, restore state, run a bounded backfill, prevent duplicate effects, reconcile the consumer, and retire a superseded pipeline before responsibility changes.