Architecture Decision Records
This section contains all Architecture Decision Records (ADRs) for the EthioConnect platform. ADRs document significant architectural choices, their context, and their consequences.
Index
| ADR | Title | Status |
|---|---|---|
| 0001 | Multi-Region Deployment Strategy | Accepted |
| 0011 | Tenant Admin Self-Service | Accepted |
| 0012 | Kubernetes Deployment Strategy | Accepted |
| 0013 | Helm Chart Structure | Accepted |
| 0014 | Client SDK Architecture | Accepted |
| 0015 | Cloud Infrastructure Strategy | Accepted |
| 0016 | GitOps Deployment Model | Accepted |
| 0017 | Mobile SDK Architecture | Accepted |
| 0018 | Documentation Site (Docusaurus) | Accepted |
| 0019 | EthioConnect Branding and Dart/Flutter Documentation | Accepted |
| 0020 | Self-Serve Onboarding and Unified Web Origin | Accepted |
| 0021 | Split the Tenant Dashboard and the Platform-Operator Console into Two Apps | Accepted |
| 0022 | Native Dart SDK (commbaas) | Accepted |
| 0024 | Signup Notifications via Transactional Outbox and Email Channel | Accepted |
| 0025 | Tenant Suspension: Event-Driven Enforcement and Notification | Accepted |
| 0026 | Payment Control: Prepaid/Postpaid Subscriptions and Hour-Balance Enforcement | Accepted (§3/§4 amended by 0028) |
| 0028 | Prepaid Hours: Soft Exhaustion Gate, Distinct from Suspension | Accepted |
| 0032 | Scheduler Service Boundary and the Shared Webhook Delivery Package | Accepted |
| 0033 | Postgres Claim-Queue Scheduling with SKIP LOCKED and a Unique-Occurrence Index | Accepted |
| 0034 | Scheduler Execution Semantics: At-Least-Once Delivery, Exactly-Once Run Materialisation, Idempotency Key | Accepted |
| 0035 | Cron Semantics: 1-Minute Granularity, IANA Timezones, DST Rules, tzdata Pinning | Accepted |
| 0036 | Misfire and Catch-Up Policy; Suspension Windows Are Never Backfilled | Accepted |
| 0037 | Deterministic Jitter and the scheduled_for / fire_after Split | Accepted |
| 0038 | schedule-events Topic: Partitioning, Retention, and the Outbox vs Best-Effort Split | Accepted |
| 0039 | Scheduler Quotas and Limits Under the Entitlement Model | Accepted |
| 0040 | Scheduler Outbound Egress, SSRF Posture, and Secret Handling | Accepted (security-review ship gate) |
| 0041 | Scheduler Single-Region Planning and DR on Regional Failover | Accepted |
| 0042 | Customer Site on Firebase Hosting at ethioconnect.net | Accepted |
Format
Each ADR follows the structure:
- Title — Short descriptive name prefixed with the ADR number.
- Status —
Proposed,Accepted,Deprecated, orSuperseded. - Context — The forces at play and the problem being addressed.
- Decision — What was decided and why.
- Consequences — Trade-offs, risks, and follow-up work.