平台与运行仓库
oceanway-core 实施计划
OceanWay 共享领域、运行编排、Operations、计量与账务核心仓库的分阶段实施计划
仓库:Oceanway-AI/oceanway-core。当前已验收基线:Organization-backed Run Admission、credits Reservation 与事务内 Outbox Append。
目标结果与当前基线
Core 是 Identity、Tenant、Authorization、Developer Access、Wallet、Billing、Asset、Execution、Metering、Agent、MCP、Model Control、Operations 与 Audit 的模块化运行时。当前受控基线可以创建 Run/Reservation,但没有正式 Outbox Dispatcher、Gateway 执行、模型输出、Metering、Settlement、Asset 或 Public Admission。
Core 保持一个仓库,但模块继续拥有独立 Command、Service、Repository、表、事件和权限。模块合仓不等于跨模块直接改表。
B1 的实时任务、依赖和评审统一进入 GitHub Milestone B1 · Outbox & Operations Read Model。本页只维护稳定边界和退出门禁,不复制 Issue 的实时状态。
模块 Owner
| 模块 | 拥有的事实 | 明确不拥有 |
|---|---|---|
| Identity/Tenant/Auth | Principal、Organization、Membership、Workspace、Project、Policy | 产品 Session UI、Workforce IdP |
| Developer Access | App、Environment、Service Account、Credential Version、Binding | Raw Secret 接收、公开文档 |
| Model Control | Offering、Surface Publication、Execution Target、Routing Policy | Provider Channel/Supply |
| Execution | Run、Step、Attempt、Manifest、Closure、Output Fact | Provider Task、规范计量、Ledger |
| Metering | Eligibility、MeterEvent、ProviderCostFact、Settlement Input | Gateway 原始 Payload、Ledger 终局 |
| Billing | Billing Account、Reservation、Ledger、Finalization、经济 Case Source Fact | Operations Case 工作流 |
| Asset | Asset、Version、Blob Registration、Lineage、引用保护 | 产品私有业务聚合 |
| Operations/Audit | Dispatcher、Receipt、Read Model、Query、Case Workflow、Audit | 领域事实改写、Admin UI |
仓库里程碑
CORE-1 已完成:受控 Run Admission
- 固定 Contracts
0.2.0; - API Edge Workload JWT 与 Credential Snapshot;
- Organization-backed Tenant/Project/Model/Billing 校验;
- 不可变 Run Input/Manifest、credits Reservation、幂等与事务 Outbox;
- 真实 PostgreSQL 并发、约束与回滚测试。
该基线不开放公网,也不执行模型。
CORE-2 当前:Outbox 与 Operations
- 配对产生 Run/Wallet v2 与精确 Append-time Delivery Set;
- Dispatcher Claim/Lease/Fencing、Attempt、Receipt、Quarantine 与
published_at受控更新; - Event/Accepted Observation 幂等 Projector、Versioned Read Model 与 Shadow Rebuild;
- Workforce Grant Exchange、Private Query、完整性 Snapshot/Guard 与两阶段 Audit;
- API Edge Observation Intake 和 Admin Run Explorer 所需 BFF Contract。
详细阶段继续以既有 Operations 实施计划为规范;本页负责把它纳入十四仓总控。
CORE-3:Execution、Metering 与 Billing
- Execution 创建 Attempt Manifest、消费 Gateway 结果并以不可逆 Closure 冻结完整 Attempt Set;
- Metering 独占 Eligibility、MeterEvent、ProviderCostFact 与 Settlement Input;
- Billing 通过 Purpose-bound Validation Bundle 在本地事务终局 Ledger/Reservation;
- 成功终局后的更正只追加 Transition/Exposure;
- 两类正式 Reconciliation Case 使用 Billing-authoritative Source/Resolution Fact;其他冲突保留 Owner-local Blocked Work。
CORE-4:Text Canary 与 Asset
- 固定一个 Organization、credits、Offering、Execution Target 与 Text Gateway 路径;
- 从 Admission 到 Attempt、Evidence、Metering、Billing 和 Output 全链路收敛;
- 成功 Output 登记 Asset Version/Lineage,失败或未知不创建伪 Asset;
- 为 Console
/ai与 Studio 提供最小 Product/Customer BFF Contract。
CORE-5:共享生态扩展
- Personal Space、企业治理、预算和订阅;
- Media Gateway、Drama、Commerce 与 FDE 私有交付;
- Agent Revision/Deployment、MCP Connection/Grant 和 Canvas Runtime;
- Public API 查询、取消、Webhook 与多模型能力。
数据与事务门禁
- 同一业务命令只有一个 Owner Repository 和幂等结果;失败不得留下部分事实。
- 跨模块原子行为使用明确事务协调;跨仓只通过版本化 Service/Event Contract。
- 在线 PostgreSQL 查询必须定向、有界并使用参数化 Repository;Operations 全量快照只用于显式重建/证明。
- Event、Manifest、Ledger、Asset Version、Receipt、Conflict Fact 与 Audit 等不可变对象不能原地修补。
- Personal Space 不能映射成 Organization 兼容;必须等待 tenant-aware 新版本和完整授权/账务门禁。
仓库验收
- 所有模块边界有依赖负向测试,禁止产品/Gateway 私有类型进入 Core 领域。
- 真实 PostgreSQL 覆盖唯一性、锁、CAS、事务回滚、租约失效、重放、乱序与并发。
- 每个跨仓 Read/Validate 都验证 Workload Audience、Purpose、Scope、完整四元组和摘要。
- 故障注入覆盖 Commit 后响应丢失、Consumer Ack 前后崩溃、未知 Provider 提交和 Billing 终局回滚。
- 每个批次登记固定 Commit、CI、Migration、Image Digest、SBOM、跨进程证据和回滚演练。