{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-sft-010","code":"wm-sft-010-runtime-compute-environment","url":"https://ver.cy/models/wm-sft-010-runtime-compute-environment/","name":"Runtime / Compute Environment","alternateNames":[],"kind":"world-model","status":"published","version":"1.0.0","language":"en","classifiers":{"family":"World Models","category":"Information and virtual systems","entryKind":"entity","plane":"","domain":["INF.SFT.RUN"],"industry":["Cross-industry"],"navPath":"NAV.INF.SFT.RUN","tags":["runtime","compute","environment","inf.sft.run"],"facets":{}},"whatItIs":"A runtime or compute environment is the set of infrastructure resources and platform layers on which software executes, such as a cluster, a virtual machine pool, a container platform or a serverless runtime, together with the workloads occupying it over time. It records topology, configuration under control and which workloads ran where and when; the software itself and its deployments are separate subjects.","purpose":"Describe a managed runtime environment, its resources, dependent occupants and configuration evidence across time without duplicating software, deployment or physical-asset masters.","scope":{"in":["Environment identity, classification, accountability and resource topology","Capacity and execution capability assertions with evidence and uncertainty","Dependent occupant bindings and observed lifecycle or health facts","Configuration designations, baselines, drift and maintenance evidence","Isolation, action-authority references, provenance, projections and record continuity"],"out":["Software and application masters, product lifecycle, source code and release ownership","Deployment orchestration, change approval execution and workload scheduling or execution","Managed-service tenant mastership, impact propagation, general audit and enforcement engines","Physical asset identity, custody, procurement and disposal","Secret payloads, workload business data, billing, energy accounting and complete platform security certification"],"boundaries":[{"neighbor":"WM-SFT-002","distinction":"Reference logical software and application identity, ownership and product lifecycle; occupant records never become independent software masters."},{"neighbor":"WM-SFT-009","distinction":"Reference deployment occurrences for creation or change evidence; deployment plan, approval, execution and outcome remain deployment-owned."},{"neighbor":"WM-XCT-039","distinction":"Reference tenant mastership and bounded impact projections; this model records runtime topology assertions, not managed-service graph evaluation or cross-tenant impact propagation."},{"neighbor":"WM-OBJ-001","distinction":"Reference underlying physical item when applicable; runtime resource identity and CI designation do not duplicate physical identity, custody, ownership or asset lifecycle."},{"neighbor":"WM-SFT-018","distinction":"Incoming hosting links can identify this runtime context; endpoint identity, contract and endpoint lifecycle remain external."},{"neighbor":"WM-SFT-015","distinction":"Incoming execution links identify where an execution occurred; task execution state, scheduling and execution effects remain external."}]},"distinguishingFeatures":["It is where software runs, while the software product, release and deployment are records of what runs.","Occupancy is temporal: the same resource hosts different workloads over time.","Configuration items are designated and baselined, so drift can be detected.","Distinct from physical computing hardware, which may underlie many environments."],"structure":{"bundles":[{"id":"SFT010-B1","name":"Environment and resources","description":"What the environment is made of.","layers":[{"id":"SFT010-B1-L1","name":"Topology","description":"Resources, their relations and their location.","findings":[{"id":"SFT010-F01","name":"Environment identity","description":"The environment, its purpose and owner.","questions":[{"text":"Which environment is meant, and is it production, staging or development?","id":"SFT010-Q01"},{"text":"Who owns and operates it?","id":"SFT010-Q02"}]},{"id":"SFT010-F02","name":"Resource topology","description":"Compute, storage and network resources and how they connect.","questions":[{"text":"Which resources make up the environment, and in which regions or sites?","id":"SFT010-Q03"},{"text":"Which resources are shared with other environments?","id":"SFT010-Q04"}]}]}]},{"id":"SFT010-B2","name":"Occupancy over time","description":"What runs in the environment.","layers":[{"id":"SFT010-B2-L1","name":"Runtime occupants","description":"Workloads placed on resources over time.","findings":[{"id":"SFT010-F03","name":"Occupant record","description":"Which workload ran on which resource and when.","questions":[{"text":"Which workloads ran on this resource during the period?","id":"SFT010-Q05"},{"text":"Which deployment placed each workload there?","id":"SFT010-Q06"}]}]}]},{"id":"SFT010-B3","name":"Configuration control","description":"How the environment is governed.","layers":[{"id":"SFT010-B3-L1","name":"Controlled configuration","description":"Designated configuration items and their baselines.","findings":[{"id":"SFT010-F04","name":"Baseline and drift","description":"The approved configuration and deviations from it.","questions":[{"text":"Which configuration items are under control, and what is their approved baseline?","id":"SFT010-Q07"},{"text":"Has the actual configuration drifted from the baseline?","id":"SFT010-Q08"}]},{"id":"SFT010-F05","name":"Patch and support state","description":"Patch levels and end-of-support status.","questions":[{"text":"Which operating system and runtime versions are in use, and are they patched?","id":"SFT010-Q09"},{"text":"Do any components reach end of support soon?","id":"SFT010-Q10"}]}]}]}]},"agentConduct":{"may":["Inventory resources and occupants from monitoring and configuration data.","Report configuration drift and unpatched components.","Answer which workloads ran where at a given time.","Propose capacity or configuration changes for approval."],"mustNot":["Change production configuration outside the change process.","Expose credentials, secrets or internal topology to unauthorized parties.","Delete or reprovision resources that host running workloads without approval.","Disable logging or security controls."],"requiresHuman":["Changes to production environments and their baselines.","Decommissioning an environment.","Granting administrative access."]},"ethics":{"considerations":["Environments host personal and business data whose protection depends on their configuration.","Outages hit users of every service hosted in the environment.","Energy use of compute has environmental cost."],"affectedParties":["Users of hosted services","Operators and engineers","Data subjects whose data is processed"]},"owners":{"steward":"The platform or infrastructure team that operates the environment and controls its configuration.","roles":[{"name":"Environment steward","responsibilities":["Resolve scoped master identities, granularity and record quality."]},{"name":"Runtime operator","responsibilities":["Supply controller evidence and resource observations under delegated authority."]},{"name":"Configuration approver","responsibilities":["Provide approved baseline and exception references; local records cannot grant this authority."]},{"name":"Evidence reviewer","responsibilities":["Challenge stale observations, ambiguity, mapping loss and unsupported conformance."]},{"name":"Records custodian","responsibilities":["Apply disclosure, retention, erasure and tombstone rules to local evidence."]}],"masterSystems":["Configuration management database","Infrastructure-as-code repository","Cloud resource inventory"]},"relations":[{"target":"WM-SFT-002","type":"references","note":"Reference logical software and application identity, ownership and product lifecycle; occupant records never become independent software masters. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt."},{"target":"WM-SFT-009","type":"references","note":"Reference deployment occurrences for creation or change evidence; deployment plan, approval, execution and outcome remain deployment-owned. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt."},{"target":"WM-XCT-039","type":"references","note":"Reference tenant mastership and bounded impact projections; this model records runtime topology assertions, not managed-service graph evaluation or cross-tenant impact propagation. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt."},{"target":"WM-OBJ-001","type":"references","note":"Reference underlying physical item when applicable; runtime resource identity and CI designation do not duplicate physical identity, custody, ownership or asset lifecycle. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt."},{"target":"WM-SFT-018","type":"references","note":"Incoming hosting links can identify this runtime context; endpoint identity, contract and endpoint lifecycle remain external. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt."},{"target":"WM-SFT-015","type":"references","note":"Incoming execution links identify where an execution occurred; task execution state, scheduling and execution effects remain external. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt."},{"target":"https://github.com/opencontainers/runtime-spec/blob/v1.2.0/runtime.md","type":"aligned","note":"Container-profile state and ID alignment only; no universal lifecycle or conformance claim."},{"target":"https://opentelemetry.io/docs/specs/otel/resource/sdk/","type":"aligned","note":"Telemetry resource projection only; schema URLs and conflict/loss reports are required."},{"target":"https://www.w3.org/TR/prov-o/","type":"aligned","note":"Attribution and revision vocabulary alignment; no truth or authority inference."},{"target":"WM-SFT-002","type":"neighbor","note":"Reference logical software and application identity, ownership and product lifecycle; occupant records never become independent software masters."},{"target":"WM-SFT-009","type":"neighbor","note":"Reference deployment occurrences for creation or change evidence; deployment plan, approval, execution and outcome remain deployment-owned."},{"target":"WM-XCT-039","type":"neighbor","note":"Reference tenant mastership and bounded impact projections; this model records runtime topology assertions, not managed-service graph evaluation or cross-tenant impact propagation."},{"target":"WM-OBJ-001","type":"neighbor","note":"Reference underlying physical item when applicable; runtime resource identity and CI designation do not duplicate physical identity, custody, ownership or asset lifecycle."},{"target":"WM-SFT-018","type":"neighbor","note":"Incoming hosting links can identify this runtime context; endpoint identity, contract and endpoint lifecycle remain external."},{"target":"WM-SFT-015","type":"neighbor","note":"Incoming execution links identify where an execution occurred; task execution state, scheduling and execution effects remain external."},{"target":"WM-SFT-002","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["An environment is identified by its name and identifier in the configuration management database or the provider's resource identifiers.","Resources carry provider resource identifiers, host names and network addresses."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["An environment is recognised by its resource inventory, network boundaries and labels.","Often confused with a deployment, with the physical data centre or with one of many clusters of the same name."]},"capabilities":{"applicability":"required","items":["Resources can be provisioned, scaled, patched, reconfigured and decommissioned.","Workloads can be scheduled onto resources and moved between them."]},"hazards":{"applicability":"required","items":["Outages from failed changes or capacity exhaustion.","Security breaches through misconfiguration or unpatched components.","Untracked drift that makes recovery and audit impossible."]},"interfaces":{"applicability":"required","items":["Open Container Initiative runtime and image specifications.","OpenTelemetry for resource and workload telemetry.","Infrastructure-as-code definitions as the declared configuration."]},"context":{"applicability":"required","items":["Operated on premises, in public or private clouds and at the edge.","Governed by IT service management and security controls such as ISO/IEC 27001."]}},"sources":[{"title":"The NIST Definition of Cloud Computing","url":"https://csrc.nist.gov/pubs/sp/800/145/final","note":"National Institute of Standards and Technology"},{"title":"Open Container Initiative Runtime Specification - Runtime and Lifecycle","url":"https://github.com/opencontainers/runtime-spec/blob/v1.2.0/runtime.md","note":"Open Container Initiative"},{"title":"Nodes","url":"https://kubernetes.io/docs/concepts/architecture/nodes/","note":"Kubernetes project"},{"title":"Resource SDK","url":"https://opentelemetry.io/docs/specs/otel/resource/sdk/","note":"OpenTelemetry project"},{"title":"Pod Lifecycle","url":"https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/","note":"Kubernetes project"},{"title":"Resource Management for Pods and Containers","url":"https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/","note":"Kubernetes project"},{"title":"Guide for Security-Focused Configuration Management of Information Systems","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-128.pdf","note":"National Institute of Standards and Technology"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium"},{"title":"RFC 3339: Date and Time on the Internet: Timestamps","url":"https://www.rfc-editor.org/rfc/rfc3339","note":"Internet Engineering Task Force"},{"title":"Multi-tenancy","url":"https://kubernetes.io/docs/concepts/security/multi-tenancy/","note":"Kubernetes project"},{"title":"NIST SP 800-145 The NIST Definition of Cloud Computing (NIST)"},{"title":"Open Container Initiative Runtime Specification (Open Container Initiative)"},{"title":"ISO/IEC 20000-1 Service management system requirements (ISO/IEC)"}],"openQuestions":["Run the coordinator source checker outside the sandbox, pin applicable source versions and record source-to-claim and license dispositions without treating HTTP success as semantic verification.","Develop nested instance profiles and fixtures covering reused IDs, overlapping occupancy, unknown bounds, stale telemetry, conflicting baselines, shared resources, tenant isolation and lawful erasure.","Research specialist compute platforms and test loss-aware mappings against actual deployed versions and pinned neighbor models.","Restore independent external review before any canonical or publishable-draft promotion.","Nested executable instance schemas, interval overlap rules and unit-aware acceptance fixtures are not implemented.","Virtual-machine, serverless, accelerators, edge and embedded profiles need deeper primary research and integration tests.","Runtime disaster recovery, billing and energy accounting are external concerns; only recovery evidence references are represented.","Direct source HTTP status and body hashes are unmeasured locally; rolling source versions and deployed-platform applicability require coordinator review.","Independent external review is absent under the owner-authorized waiver."],"resources":{"spec":"/models/wm-sft-010-runtime-compute-environment/spec.yaml","agents":"/models/wm-sft-010-runtime-compute-environment/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-sft-010"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-sft-010-runtime-compute-environment/spec.yaml","ver-cy/world-models/card-supplements/wm-sft-010-runtime-compute-environment.json"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-10-06T12:29:33Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"A runtime environment is an information or software construct; its measurable attributes are configuration and operational data, not physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-06, unreviewed). Written from the card's existing content and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}