docs: ADR 0002 — data-placement rubric (D1 / per-user DO / Analytics Engine) - #1109
Conversation
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
|
Warning Review limit reached
Next review available in: 52 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThis change adds ADR 0002 for data placement across storage systems. It documents placement criteria, concrete assignments, operational guardrails, and revisit conditions. The architecture and ADR indexes now link to the new decision record. ChangesData placement documentation
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
|
🔎 Preview deployed: https://kody-pr-1109.kody-a99.workers.dev Worker: Mocks:
|
|
@coderabbitai review |
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/contributing/decisions/0002-data-placement.md`:
- Around line 34-44: Update the data-placement ADR to add a standing per-user
isolation rule covering packages, jobs, secrets, values, memories, remote
connectors, email inboxes, and durable storage: all reads and writes must be
scoped by userId and reject cross-user access. State that only documented
operator/admin indexes and reporting aggregates may be cross-user, and link to
the existing data-storage.md contract for the full isolation model.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: cf55ee52-ab8f-4e45-b89c-8ce64fb188f1
📒 Files selected for processing (3)
docs/contributing/architecture/index.mddocs/contributing/decisions/0002-data-placement.mddocs/contributing/decisions/index.md
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
What
Records the data-placement rubric decided during the July 2026 scalability review as decision record
docs/contributing/decisions/0002-data-placement.md:APP_DB) is the scaling bottleneck (global single writer, shared 10 GB cap); the audit found awaited per-call D1 writes on hot paths (entitlement counter upserts,withAccountWriteLeasefencing, activation upserts,workflow_runsprojections, uncached plan read inassertWithinEntitlement); precedent existed in the RunLog DO move (migrations 0099/0112).userId, spans entities/tables, is cached low-write config, needs fleet-wide queries, or is a cross-user enumeration/deletion index; a per-user Durable Object when data is high-write,userId-addressed, owner-local, read on the owner's own path; Analytics Engine for append-only reporting-grade telemetry within AE's retention window; R2/KV/Vectorize homes unchanged. Plus the five forces (lookup direction, transactional boundaries, read topology, serialization, operations) and the standing rules (budget justification for new awaited hot-path D1 writes, deletion/export coverage in the same move, admin cross-user SELECT redesign in the same change, per-user isolation held in every storage home).Notes for review
docs/contributing/architecture/decisions/0001-.... The repo already has an ADR system atdocs/contributing/decisions/(template, index, numbering, temporal-check exemption intools/check-docs-temporal-language.ts), so this record lands there as 0002 instead of creating a parallel directory. The existing index already documents the naming convention.docs/contributing/architecture/index.md(Data Storage bullet) and the decisions index.npm run primitives:checkneeds no change: it validates that paths listed inprimitives.yamlresolve; new docs don't require registration and this PR reshapes no primitive.System recap — composes existing primitives (low risk, docs only)
Mode: recap · Base:
main@915db38· Head:5050df9Classification: composes — documentation-only change; the classifier matches no primitive code roots and no primitive is added or reshaped. The ADR documents placement rules for existing storage primitives.
Primitives touched
System map
The ADR records which storage primitive each kind of data belongs to; all nodes are unchanged context.
Legend: green = composes (wiring only) · amber = extended by this PR · red = new primitive · gray = context (unchanged, included only when an edge crosses it).
Conductor report
docs/contributing/decisions/0002-data-placement.md) capturing the data-placement rubric (D1 vs per-user Durable Objects vs Analytics Engine, with R2/KV/Vectorize homes), the five forces, standing rules (including per-user isolation from review feedback), and the concrete placements; linked from the decisions index and the architecture index.docs/contributing/decisions/(template, index, ADR 0001), so this landed there as 0002 instead of creatingdocs/contributing/architecture/decisions/0001-.... That directory is also the one exempted fromdocs:check-temporal, which point-in-time ADRs require.npm run primitives:checkneeded no change.npm run validategreen locally; all CI checks green.data-storage.mduntouched (only the architecture index gained a link).Summary by CodeRabbit