| Authentication, authorization, ForwardAuth target | ADR-020 |
| Tenant model, site isolation, cross-site sharing | ADR-020 |
Forwarded X-Auth-* headers contract | ADR-020 |
| Keycloak realm, clients, roles, groups | ADR-020 |
| Public-route allowlist | ADR-020 |
| Environment topology (local / preview / prod / local-prod) | ADR-021 |
| Preview environments per PR | ADR-021 |
| Secrets management, OVHcloud Secret Manager → Dokploy UI | ADR-022 |
| Secret rotation procedure | ADR-022 |
| API gateway, Traefik | ADR-005 |
| Runtime hosting, Dokploy, single VPS | ADR-019 |
| FastAPI as backend stack, Alembic migrations | ADR-012 |
| Schema registry (Apicurio) | ADR-001 |
| Data quality (Great Expectations, GX+OpenMetadata strategy) | ADR-002, ADR-023 |
| Iceberg compaction strategy | ADR-003 |
| Iceberg catalog (Lakekeeper) | ADR-004 |
| Field-activity event log | ADR-006 |
| Service mesh / Kubernetes deferral | ADR-007 (superseded by ADR-019) |
| Derived asset invalidation | ADR-008 |
| Observability stack | ADR-009 |
| Schema inference and registration (Path A/B) | ADR-010 |
| Documentation platform | ADR-011 |
| Local object storage (MinIO) | ADR-015 |
Iceberg partition strategy, site_code partitioning | ADR-016 |
| Table format selection (Iceberg vs Hudi/Delta) | ADR-017 |
| Cross-source harmonization, BADM tiers | ADR-018 |
| ICOS export pipeline | ADR-014 |
| Site map editor (Leaflet, PostGIS, spatial schema) | ADR-013 |
| Treatment, Trial, TrialSeries, ExperimentalLocation (experimental design model) | ADR-013 |
| Device, Sensor, Channel (measurement infrastructure model) | ADR-013 |
| Observation data model | ADR-025 |
| Lineage tooling (Marquez vs OpenMetadata, dual HTTP POST) | ADR-024 |
| AI/LLM service architecture, external LLM dependency, onboarding/event-classification assistance | ADR-026 |
| Vector search, Qdrant, retrieval-augmented AI features | ADR-027 |
Flux footprint met data provider (CDS vs Open-Meteo), MetProvider abstraction | ADR-028 |