Live health
Loading…
DRQ: data residency quarantine
DRQ keeps Comms.ID's protected data and processing in Australia on Cloudflare. It holds a stock of empty R2 buckets, D1 databases and Durable Objects. It verifies where each one is, and it lets an application take one. The take is recorded in the residency ledger, and the reply is the receipt.
Moved from comms-id/platform at 14d29ca9 (comms-id/platform#516). Worker names, the Durable Object
namespace, ledger history, stock and assignments are unchanged.
Take an item
pnpm install
pnpm quarantine --help
pnpm quarantine take --kind r2 --request-id my-app-assets-001 --team my-team --stack my-app --binding ASSETS
The reply holds item (the resource and its assignment) and event (the take's ledger event: the receipt).
Reuse the same request ID to recover an interrupted take; never take again with a new ID.
Guides
| Need | Guide |
|---|---|
| R2 or D1 storage | docs/quarantine-consumer.md |
| Durable Object (in-object application) | docs/quarantine-applications.md, docs/au-pool.md |
| Worker Cache API | docs/quarantine-cache.md |
| Which Cloudflare services are allowed | docs/quarantine-services.md |
| Nightly pool check and ledger export | docs/quarantine-checks.md |
| Measurements and AWS probes | docs/quarantine-measurements.md, docs/quarantine-aws-coverage.md |
| Historical receipts | docs/audit-records.md |
Consuming DRQ code
Platform installs this repository as one pnpm git dependency, pinned to a commit:
"@comms-id/data-residency": "git+https://github.com/comms-id/drq.git#<commit>"
effect and alchemy are peer dependencies. The plan hook is
@comms-id/data-residency/infra/localisation-policy.ts; the runtime guards are
@comms-id/data-residency/cloudflare/workers.
Before a DRQ change merges
Run the consumer check from your DRQ worktree and paste its receipt (stdout) into the PR body:
pnpm check:consumers
It packs this tree the way platform installs the pinned dependency, installs it into a fresh export of platform's origin/main (no consumer checkout is changed), and runs platform's type checks, infra tests and the tests of every app that depends on DRQ. DRQ_CONSUMER_PLATFORM selects another platform checkout. monocomms takes no DRQ code yet.
Decisions and evidence
DRQ's decisions and evidence stay in comms-id/platform: ADR-0028, ADR-0033, ADR-0042, ADR-0043, ADR-0045
and ADR-0048 in docs/03-decisions/adrs/, and docs/evidence/localisation/.