Architect: use it

Envelopes and scaling rules

Bounds you approve once on one environment, so the board scales and restarts inside them without asking you again, and the scaling rules in your repository that ask it to.

An envelope is bounds you approve once on one environment, production included: “2 to 10 instances”, “up to 60 a month”, “3 restarts a day”. Inside them, the board scales and restarts without asking you again, and tells you after. Anything outside them is a plan that waits for you, with its push.

Envelopes start empty. Until you set one, every scale and restart waits for you.

#Set one

On the repository’s settings page, under Infrastructure, each environment shows its envelope or “No envelope: every scale and restart waits for you.” Press Add an envelope, or Change on one you have:

Set envelope asks first. Revoke puts every scale and restart back in front of you. Each is an envelope entry in the audit trail.

An envelope lives on the board, one per environment, never in the repository, so a pull request can’t widen it. Setting, changing, and revoking one is yours alone. An observe-only environment has none.

#Who acts inside it

Nothing scales just because an envelope exists. Two things can ask:

Either way the board builds the plan itself and decides:

The askWhat happens
Inside the bounds, the cost bound, and the restart capApproved by the envelope and applied with no press, through the same apply workflow. A quiet note in the inbox: “Scaled widgets-api to 6 instances, inside its envelope.”
Outside the bounds, past the cost bound, or the restart cap used upA plan that waits for you, with a push
A frozen or observe-only environment, or a change the resource can’t makeRefused

#Scaling rules

Scaling rules are in .github/breakaway-infra/scaling.json on the default branch, checked by infra check. Each rule listens to the environment’s signals and turns a matching one into one ask through the envelope:

{
  "version": 1,
  "rules": [
    {
      "name": "render backlog",
      "environments": ["production"],
      "resourceKinds": ["container"],
      "kinds": ["health"],
      "level": "warning",
      "act": "scale",
      "step": 2
    },
    {
      "name": "render down",
      "environments": ["production"],
      "resource": "widgets-render",
      "kinds": ["health"],
      "level": "critical",
      "act": "restart"
    }
  ]
}

The envelope, its restart cap, a freeze, and observe only decide, never the rule. The same rule and signal ask at most once a day, and only the signal’s fields and value are read: its text never reaches the ask. A file that doesn’t check asks for nothing, and the board shows its line and field. Each ask, or its refusal, shows on the repository’s scaling rules, and its audit entry names the rule.

#Hear about it