DG + AssetCore Deployment Patterns (Conceptual)
Reference Topology
- DG MCP server runs as its own control-plane service.
- ASC read daemon runs as a separate world-state service.
- Integration layer handles ASC auth and maps principals to DG tool permissions.
Deployment Notes
- Separation of concerns: DG controls decisions; ASC controls world-state.
- Fail-closed integration: Namespace and auth checks must fail closed.
- Determinism first: Ensure ASC read responses include anchors for replay.
Planned Additions
Validated deployment recipes and hardening guidance are not yet published for OSS. Track status in F:Docs/roadmap/README.md L73-L81.
- Provide validated deployment recipes once reference deployments exist.
- Include security hardening guides (mTLS, audit log shipping, rate limits).
- Publish production-ready HA/control-plane diagrams.