← Back to catalogue
Published

Runtime / Compute Environment

vr.wm-sft-010 · wm-sft-010-runtime-compute-environment

Describe a managed runtime environment, its resources, dependent occupants and configuration evidence across time without duplicating software, deployment or physical-asset masters.

World Models Information and virtual systems INF.SFT.RUN

Bundle → Layer → Finding → Questions Filled

3 bundles · 3 layers · 5 findings · 10 questions

Environment and resources What the environment is made of.

Topology

Resources, their relations and their location.

Environment identity

The environment, its purpose and owner.

  1. Which environment is meant, and is it production, staging or development?
  2. Who owns and operates it?

Resource topology

Compute, storage and network resources and how they connect.

  1. Which resources make up the environment, and in which regions or sites?
  2. Which resources are shared with other environments?
Occupancy over time What runs in the environment.

Runtime occupants

Workloads placed on resources over time.

Occupant record

Which workload ran on which resource and when.

  1. Which workloads ran on this resource during the period?
  2. Which deployment placed each workload there?
Configuration control How the environment is governed.

Controlled configuration

Designated configuration items and their baselines.

Baseline and drift

The approved configuration and deviations from it.

  1. Which configuration items are under control, and what is their approved baseline?
  2. Has the actual configuration drifted from the baseline?

Patch and support state

Patch levels and end-of-support status.

  1. Which operating system and runtime versions are in use, and are they patched?
  2. Do any components reach end of support soon?

Classifiers Filled

Family
World Models
Category
Information and virtual systems
Entry kind
entity
Navigation path
NAV.INF.SFT.RUN
Domain
INF.SFT.RUN
Industry
Cross-industry
Tags
runtimecomputeenvironmentinf.sft.run

What it is Filled

A runtime or compute environment is the set of infrastructure resources and platform layers on which software executes, such as a cluster, a virtual machine pool, a container platform or a serverless runtime, together with the workloads occupying it over time. It records topology, configuration under control and which workloads ran where and when; the software itself and its deployments are separate subjects.

In scope

  • Environment identity, classification, accountability and resource topology
  • Capacity and execution capability assertions with evidence and uncertainty
  • Dependent occupant bindings and observed lifecycle or health facts
  • Configuration designations, baselines, drift and maintenance evidence
  • Isolation, action-authority references, provenance, projections and record continuity

Out of scope

  • Software and application masters, product lifecycle, source code and release ownership
  • Deployment orchestration, change approval execution and workload scheduling or execution
  • Managed-service tenant mastership, impact propagation, general audit and enforcement engines
  • Physical asset identity, custody, procurement and disposal
  • Secret payloads, workload business data, billing, energy accounting and complete platform security certification

Why it exists Filled

Describe a managed runtime environment, its resources, dependent occupants and configuration evidence across time without duplicating software, deployment or physical-asset masters.

Distinguishing features Filled

  • It is where software runs, while the software product, release and deployment are records of what runs.
  • Occupancy is temporal: the same resource hosts different workloads over time.
  • Configuration items are designated and baselined, so drift can be detected.
  • Distinct from physical computing hardware, which may underlie many environments.

What robots and AI may and may not do Filled

Must not

  • Change production configuration outside the change process.
  • Expose credentials, secrets or internal topology to unauthorized parties.
  • Delete or reprovision resources that host running workloads without approval.
  • Disable logging or security controls.

Only with a human decision

  • Changes to production environments and their baselines.
  • Decommissioning an environment.
  • Granting administrative access.

May

  • Inventory resources and occupants from monitoring and configuration data.
  • Report configuration drift and unpatched components.
  • Answer which workloads ran where at a given time.
  • Propose capacity or configuration changes for approval.

Moral aspects Filled

  • Environments host personal and business data whose protection depends on their configuration.
  • Outages hit users of every service hosted in the environment.
  • Energy use of compute has environmental cost.

Who is affected

  • Users of hosted services
  • Operators and engineers
  • Data subjects whose data is processed

Owners Filled

Steward

The platform or infrastructure team that operates the environment and controls its configuration.

Roles

Environment steward
Resolve scoped master identities, granularity and record quality.
Runtime operator
Supply controller evidence and resource observations under delegated authority.
Configuration approver
Provide approved baseline and exception references; local records cannot grant this authority.
Evidence reviewer
Challenge stale observations, ambiguity, mapping loss and unsupported conformance.
Records custodian
Apply disclosure, retention, erasure and tombstone rules to local evidence.

Master systems

  • Configuration management database
  • Infrastructure-as-code repository
  • Cloud resource inventory

Links to other meta-models Filled

references

  • WM-SFT-002 - Reference logical software and application identity, ownership and product lifecycle; occupant records never become independent software masters. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt.
  • WM-SFT-009 - Reference deployment occurrences for creation or change evidence; deployment plan, approval, execution and outcome remain deployment-owned. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt.
  • WM-XCT-039 - Reference tenant mastership and bounded impact projections; this model records runtime topology assertions, not managed-service graph evaluation or cross-tenant impact propagation. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt.
  • WM-OBJ-001 - Reference underlying physical item when applicable; runtime resource identity and CI designation do not duplicate physical identity, custody, ownership or asset lifecycle. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt.
  • WM-SFT-018 - Incoming hosting links can identify this runtime context; endpoint identity, contract and endpoint lifecycle remain external. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt.
  • WM-SFT-015 - Incoming execution links identify where an execution occurred; task execution state, scheduling and execution effects remain external. Bind actual target version and instance authority before operational use; candidate ledger direction is preserved in the frozen prompt.

aligned

  • https://github.com/opencontainers/runtime-spec/blob/v1.2.0/runtime.md - Container-profile state and ID alignment only; no universal lifecycle or conformance claim.
  • https://opentelemetry.io/docs/specs/otel/resource/sdk/ - Telemetry resource projection only; schema URLs and conflict/loss reports are required.
  • https://www.w3.org/TR/prov-o/ - Attribution and revision vocabulary alignment; no truth or authority inference.

neighbor

  • WM-SFT-002 - Reference logical software and application identity, ownership and product lifecycle; occupant records never become independent software masters.
  • WM-SFT-009 - Reference deployment occurrences for creation or change evidence; deployment plan, approval, execution and outcome remain deployment-owned.
  • WM-XCT-039 - Reference tenant mastership and bounded impact projections; this model records runtime topology assertions, not managed-service graph evaluation or cross-tenant impact propagation.
  • WM-OBJ-001 - Reference underlying physical item when applicable; runtime resource identity and CI designation do not duplicate physical identity, custody, ownership or asset lifecycle.
  • WM-SFT-018 - Incoming hosting links can identify this runtime context; endpoint identity, contract and endpoint lifecycle remain external.
  • WM-SFT-015 - Incoming execution links identify where an execution occurred; task execution state, scheduling and execution effects remain external.

parent

  • WM-SFT-002

What else AI and robots need to interact with it Filled

Identity and identifiers required Filled

  • An environment is identified by its name and identifier in the configuration management database or the provider's resource identifiers.
  • Resources carry provider resource identifiers, host names and network addresses.

Direct properties not applicable Not applicable

Not applicable

A runtime environment is an information or software construct; its measurable attributes are configuration and operational data, not physical properties.

Recognition optional Filled

  • An environment is recognised by its resource inventory, network boundaries and labels.
  • Often confused with a deployment, with the physical data centre or with one of many clusters of the same name.

Capabilities and actions required Filled

  • Resources can be provisioned, scaled, patched, reconfigured and decommissioned.
  • Workloads can be scheduled onto resources and moved between them.

Hazards and failure modes required Filled

  • Outages from failed changes or capacity exhaustion.
  • Security breaches through misconfiguration or unpatched components.
  • Untracked drift that makes recovery and audit impossible.

Standards and interfaces required Filled

  • Open Container Initiative runtime and image specifications.
  • OpenTelemetry for resource and workload telemetry.
  • Infrastructure-as-code definitions as the declared configuration.

Context of use required Filled

  • Operated on premises, in public or private clouds and at the edge.
  • Governed by IT service management and security controls such as ISO/IEC 27001.

Sources Filled

  1. The NIST Definition of Cloud Computing - National Institute of Standards and Technology
  2. Open Container Initiative Runtime Specification - Runtime and Lifecycle - Open Container Initiative
  3. Nodes - Kubernetes project
  4. Resource SDK - OpenTelemetry project
  5. Pod Lifecycle - Kubernetes project
  6. Resource Management for Pods and Containers - Kubernetes project
  7. Guide for Security-Focused Configuration Management of Information Systems - National Institute of Standards and Technology
  8. PROV-O: The PROV Ontology - World Wide Web Consortium
  9. RFC 3339: Date and Time on the Internet: Timestamps - Internet Engineering Task Force
  10. Multi-tenancy - Kubernetes project
  11. NIST SP 800-145 The NIST Definition of Cloud Computing (NIST)
  12. Open Container Initiative Runtime Specification (Open Container Initiative)
  13. ISO/IEC 20000-1 Service management system requirements (ISO/IEC)

Open questions

  • Run the coordinator source checker outside the sandbox, pin applicable source versions and record source-to-claim and license dispositions without treating HTTP success as semantic verification.
  • Develop nested instance profiles and fixtures covering reused IDs, overlapping occupancy, unknown bounds, stale telemetry, conflicting baselines, shared resources, tenant isolation and lawful erasure.
  • Research specialist compute platforms and test loss-aware mappings against actual deployed versions and pinned neighbor models.
  • Restore independent external review before any canonical or publishable-draft promotion.
  • Nested executable instance schemas, interval overlap rules and unit-aware acceptance fixtures are not implemented.
  • Virtual-machine, serverless, accelerators, edge and embedded profiles need deeper primary research and integration tests.
  • Runtime disaster recovery, billing and energy accounting are external concerns; only recovery evidence references are represented.
  • Direct source HTTP status and body hashes are unmeasured locally; rolling source versions and deployed-platform applicability require coordinator review.
  • Independent external review is absent under the owner-authorized waiver.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-sft-010-runtime-compute-environment/spec.yaml, ver-cy/world-models/card-supplements/wm-sft-010-runtime-compute-environment.json