Zero concepts
Five nouns explain the entire product. Understand these five and you understand Zero.
Organization → Project → Environment → Services, Domains,
Variables, Secrets,
Deployments, Versions
| Concept | What it is | What boundary it sets |
|---|---|---|
| Organization | The customer's tenant | Access, metering, audit, and data isolation |
| Project | The application | Public address, version history, configuration |
| Environment | The deployment target (Production and others) | Real isolation between environments |
| Service | A unit that runs inside the project | The process, its type, and its resources |
| Deployment | A deployment | The state, the evidence, and the history of that attempt |
Two decisions that save years
An environment is a boundary, not a label. If an environment were a label, isolation would be a convention. In Zero, each environment has its own space, its own quota, and its own blast radius: a problem in one environment does not cross into another. The same holds between projects: over the internal network, nothing reaches anything without an explicit permission — see Networking between projects.
Nothing is overwritten. Every deployment creates a new version. Restoring a previous version undoes nothing — it reactivates something that is still whole. That is what lets the product promise that the version that worked comes back as it was, not as a rebuild of it.
The pages in this section
Why the project is the application, and what an environment actually separates.
Open →ServicesThe four service types and when to use each.
Open →How a deployment worksBuild, artifact, version, and active version — and why all four are separate.
Open →What the platform acceptsWhy there is a catalog, and what happens when something falls outside it.
Open →The principles that hold everywhere
These are not aspirations: each one has a mechanism behind it.
- You declare product concepts, never infrastructure objects.
- Whatever is not in the catalog is refused with an explanation and an alternative, never with a raw infrastructure error.
- The scope of your access comes from the authenticated session, never from a request body.
- A secret is protected on write, not on read.
- The artifact is immutable. Promoting reuses exactly the same artifact.
- A deployed version is never overwritten. Restoring is a first-class operation.
- No long operation is synchronous.
- Versions are pinned, with origin and date. No "latest".
- A backup with no restore test is not a backup.
- Nothing is declared ready because it compiled.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.