# Integration Platform Institutionalisation Programme

## Architectural invariant

The middleware connects and translates; FEI decides; the Ledger records; regulated providers execute; the Platform presents.

The Gateway cannot create accounting truth, approve a commitment, determine financial eligibility or replace a regulated executor.

## Phase 1 - Edge Trust

- API Gateway validates partner X.509 certificates against a versioned truststore.
- The execute-api endpoint is disabled and the application origin is private.
- A Lambda request authoriser checks certificate status and expiry in a strongly consistent edge registry.
- API Gateway overwrites all certificate-identity headers with authoriser context.
- The backend validates the signed edge assertion and independently maps the certificate thumbprint to exactly one partner.
- OAuth client-credential tokens are bound to the verified certificate using the `cnf` claim.
- Secrets enter tasks through Secrets Manager references and ECS workload identity.

Exit evidence: the trusted-edge and certificate-binding contract tests pass; direct-origin access is absent from the network topology.

## Phase 2 - Regional Resilience

- ECS/Fargate spans three Availability Zones behind a private Application Load Balancer.
- Aurora runs a writer and reader across a three-subnet database group with automatic failover and 35-day backups.
- ECS deployment rollback, health checks and target-tracking autoscaling are enabled.
- Each private subnet has an AZ-local NAT path to avoid a shared egress failure.
- S3 evidence storage, MSK Serverless and CloudWatch logs are regional managed services.

Exit evidence: AWS Fault Injection Service removes a task and isolates one AZ without breaching the partner API SLO; an Aurora failover exercise is recorded.

## Phase 3 - Durable Integration

- The authoritative registry, consent, policy and delivery state remain in Aurora.
- A transactional outbox publishes canonical envelopes to MSK through an IAM-authenticated local bridge.
- Topics are separated by provider, payment, account, identity, partner command, webhook, reconciliation and audit domains.
- Partition keys express business ordering; no global ordering is claimed.
- Producers and consumers are idempotent, retries are bounded and poison messages move to a governed dead-letter path.
- Replay remains dual-controlled and consequential provider actions require fencing.
- Signed canonical schemas define compatibility, ownership, sensitivity, retention, consumers and deprecation.

Exit evidence: broker interruption, duplicate delivery, reordering, poison-message and replay tests complete without duplicate consequential action.

## Phase 4 - Operational Trust

- OTLP traces carry correlation identifiers across the edge, policy layer, application, adapters and downstream delivery.
- Formal SLOs cover webhook acknowledgement, event publication, outbound delivery, partner API availability and reconciliation ingestion.
- Audit-chain ranges are reduced into Merkle roots, signed and written to an S3 Object Lock compliance bucket.
- Adapter activation requires all functional, resilience, security and reconciliation scenarios to pass.
- Critical assurance failures block publication unless a complete, approved and time-limited exception exists.

Exit evidence: a material integration is traceable end to end and its signed evidence checkpoint verifies after retrieval from immutable storage.

## Phase 5 - Ecosystem Scale

- The developer portal presents documentation, schemas, samples, webhook operations, quotas, certification and support.
- Sandbox and production are distinct environments with separately issued credentials.
- Partner progression is Applied, Due diligence, Sandbox approved, Development, Conformance testing, Security certification, Operational approval, Production credentials issued, Active.
- Regional recovery starts active-passive for mutable and consequential processing. Stateless documentation and authentication may be regionally distributed.

Exit evidence: a new partner completes onboarding without bespoke database or deployment intervention, and the annual recovery exercise meets the approved RTO and RPO.

## Activation gates

Infrastructure definitions are not production approval. A change set must receive security, architecture, data-protection and operations approval. Production promotion requires:

1. a versioned CA truststore and revocation feed;
2. immutable image digests and signed provenance;
3. Secrets Manager rotation functions and successful rotation tests;
4. database migration rehearsal and rollback evidence;
5. adapter certification evidence;
6. load, failure and recovery test evidence;
7. approved DNS and reverse-proxy transition for `https://api.threasury.org`, with the former `https://bank.threasury.org/gateway/` path retained only as a compatibility redirect;
8. no legacy provider connections.
