# Router Valkey Microservice Rollout Matrix (All WebServices)

Scope

Legend:

Service Migration Matrix

Service HostCompose ServiceCurrent ReverseProxy Path PrefixesWaveAcceptance OwnerMigration DispositionRollback Switch
advisoryai.stella-ops.localadvisory-ai-web/advisoryai, /api/v1/advisory, /api/v1/advisory-ai, /api/v1/advisory-ai/adapters, /v1/advisory-ai, /v1/advisory-ai/adaptersADeveloper + Test Automation (Wave A)Migrate API prefixes to Microservice; keep root compatibility path until cutover acceptance.Route type revert in router-gateway-local.json + ADVISORYAI_ROUTER_ENABLED=false (standardized in RMW-03).
airgap-controller.stella-ops.local(retired 2026-09-11)/airgapController–N/A (retired)Host retired at SPRINT_20260722_025 OK-5 and frozen to src/__Obsoleted/AirGap/StellaOps.AirGap.Controller/; nothing to migrate. The surviving /system/airgap/* surface is Policy Engine’s and rides that host’s row.N/A.
airgap-time.stella-ops.local(retired 2026-09-11)/airgapTime–N/A (retired)Host retired at SPRINT_20260722_025 OK-5 and frozen to src/__Obsoleted/AirGap/StellaOps.AirGap.Time/; nothing to migrate. Time-anchor verification survives as a domain-neutral library, not a route.N/A.
attestor.stella-ops.localattestor/api/v1/attestations, /api/v1/attestor, /api/v1/witnesses, /attestorBDeveloper + Test Automation (Wave B)Migrate API prefixes first; keep root compatibility route until evidence-plane acceptance sign-off.Route type revert + ATTESTOR_ROUTER_ENABLED=false (RMW-03).
authority.stella-ops.localauthority/.well-known, /api/v1/authority, /api/v1/trust, /authority, /connect, /console, /jwksBDeveloper + Test Automation (Wave B)Migrate Authority API and OIDC identity routes to Microservice; use in-service OIDC bridge endpoints (/connect/*, /well-known/openid-configuration) for protocol compatibility.Route type revert + AUTHORITY_ROUTER_ENABLED=false (RMW-03).
binaryindex (source retired)predecessor host frozenHub-owned binary/symbol routes-VulnerabilitiesSee current ownership; no legacy aliasesStanding-estate window separately authorized.
cartographer.stella-ops.local(merged into graph-api)/cartographer–N/A (retired)Cartographer merged into graph-api; hostname is a network alias on graph-api container.N/A.
concelier.stella-ops.localconcelier/api/v1/concelier, /concelierDDeveloper + Test Automation (Wave D)Migrate API prefix first, then root compatibility route.Route type revert + CONCELIER_ROUTER_ENABLED=false (RMW-03).
doctor.stella-ops.localdoctor-web/api/doctor, /doctorDDeveloper + Test Automation (Wave D)Migrate API prefix first; keep root compatibility path until UI/runtime consumers are validated.Route type revert + DOCTOR_ROUTER_ENABLED=false (RMW-03).
doctor-scheduler.stella-ops.local(obsoleted)/api/v1/doctor/scheduler–N/A (frozen 2026-08-09)Host frozen to src/__Obsoleted/ under SPRINT_20260722_009 DOC-5; never deployed on the current stack. Scheduling is served by JobEngine at /api/v1/scheduler/doctor*, which the gateway already routes to scheduler.stella-ops.local.N/A.
evidencelocker.stella-ops.localevidence-locker-web/api/v1/evidence, /api/v1/proofs, /api/v1/verdicts, /api/verdicts, /evidencelocker, /v1/evidence-packsBDeveloper + Test Automation (Wave B)Migrate API/v1 and v1 endpoints first; keep root compatibility path until evidence workflows pass QA.Route type revert + EVIDENCELOCKER_ROUTER_ENABLED=false (RMW-03).
excititor.stella-ops.localexcititor-web/excititorDDeveloper + Test Automation (Wave D)Add API-form microservice mapping if needed; migrate root compatibility route in Wave D.Route type revert + EXCITITOR_ROUTER_ENABLED=false (RMW-03).
offlinekit.stella-ops.local (was exportcenter.stella-ops.local)offlinekit-web (succeeded export-web 2026-09-13)/api/offlinekit/v1 — already migratedBDeveloper + Test Automation (Wave B)DONE at SPRINT_20260722_025 OK-6/OK-10. The route group is a single regex prefix on the successor host; the legacy /api/v1/export, /exportcenter and bare /v1/audit-bundles compatibility paths were deleted, not kept (§2.11 pre-release: no legacy aliases). Live probe 2026-09-14: /api/offlinekit/v1/exports/profiles → 401, /v1/exports → 404.Route type revert is no longer available — the predecessor host is stopped and frozen. Rollback is the window’s documented stack revert.
findings.stella-ops.localfindings-ledger-web/api/v1/findings, /findingsLedgerDDeveloper + Test Automation (Wave D)Migrate API prefix first, then root compatibility path.Route type revert + FINDINGS_ROUTER_ENABLED=false (RMW-03).
(gateway.stella-ops.local — removed, consolidated into router-gateway)————Legacy gateway container eliminated; all traffic served by router-gateway (slot 0).N/A
integrations.stella-ops.localintegrations-web/api/v1/integrations, /integrationsADeveloper + Test Automation (Wave A)Migrate API prefix first, then root compatibility path.Route type revert + INTEGRATIONS_ROUTER_ENABLED=false (RMW-03).
issuerdirectory.stella-ops.localissuer-directory/issuerdirectoryBDeveloper + Test Automation (Wave B)Migrate route in trust-plane wave with issuer/auth verification checks.Route type revert + ISSUERDIRECTORY_ROUTER_ENABLED=false (RMW-03).
notify.stella-ops.local (+ notifier.stella-ops.local alias)notify-web/api/v1/notify, /notify, /api/v1/notifier, /notifierDDeveloper + Test Automation (Wave D)Merged: notifier-web folded into notify-web.Route type revert + NOTIFY_ROUTER_ENABLED=false (RMW-03).
opsmemory.stella-ops.localopsmemory-web/api/v1/opsmemory, /opsmemoryADeveloper + Test Automation (Wave A)Migrate API prefix first, then root compatibility path.Route type revert + OPSMEMORY_ROUTER_ENABLED=false (RMW-03).
jobengine.stella-ops.localorchestrator/api/approvals, /api/jobengine, /api/release-orchestrator, /api/releases, /api/v1/jobengine, /api/v1/release-orchestrator, /api/v1/workflows, /orchestrator, /v1/runsCDeveloper + Test Automation (Wave C)Migrate all API/v1 and v1 routes first; keep root compatibility path until control-plane acceptance.Route type revert + ORCHESTRATOR_ROUTER_ENABLED=false (RMW-03).
packsregistry.stella-ops.localpacksregistry-web/packsregistryADeveloper + Test Automation (Wave A)Add API-form endpoint mapping if required, then migrate root compatibility route.Route type revert + PACKSREGISTRY_ROUTER_ENABLED=false (RMW-03).
platform.stella-ops.localplatform/api, /api/admin, /api/analytics, /api/v1/authority/quotas, /api/v1/gateway/rate-limits, /api/v1/platform, /envsettings.json, /platformCDeveloper + Test Automation (Wave C)Migrate API prefixes to Microservice; keep /platform and /envsettings.json reverse proxy for static/bootstrap behavior.Route type revert + PLATFORM_ROUTER_ENABLED=false (RMW-03).
policy-engine.stella-ops.localpolicy-engine/api/risk, /api/risk-budget, /api/v1/determinization, /policyEngineCDeveloper + Test Automation (Wave C)Migrate API prefixes first; keep root compatibility path until control-plane verification completes.Route type revert + POLICY_ENGINE_ROUTER_ENABLED=false (RMW-03).
policy-gateway.stella-ops.localpolicyMerged into policy-engine above--Gateway merged into policy-engine. All routes now served by policy-engine.-
reachgraph.stella-ops.localreachgraph-webnone - not router-publishedDDeveloper + Test Automation (Wave D)SPRINT_20260904_003 ROA-7: this host no longer registers with the Router at all (Router__Enabled: "false", hard-coded, no variable). graph-api composes the same StellaOps.ReachGraph.Application controllers and owns the /v1/reachgraphs, /v1/cve-mappings and /v1/reachability prefixes; publishing both made the answering host vary per request. The direct reachgraph.stella-ops.local alias is unaffected and stays until GRA-10 deletes the deployable.No lever: there is nothing to roll back to. Re-enabling it restores the two-owner collision and fails RouterRoutePrefixOwnershipConformanceTests.
remediation.stella-ops.local— (not in compose snapshot)— (no ReverseProxy route in 2026-02-21 snapshot)CDeveloper + Test Automation (Wave C)StellaOps.Remediation.WebService exists, but router/compose mapping is missing. Add explicit remediation API route inventory and then migrate to Microservice route type in control-plane wave.Missing rollback key; add REMEDIATION_ROUTER_ENABLED once route is added.
registry-token.stella-ops.localregistry-token/registryTokenserviceADeveloper + Test Automation (Wave A)Migrate compatibility route with token flow validation in Wave A.Route type revert + REGISTRY_TOKEN_ROUTER_ENABLED=false (RMW-03).
replay.stella-ops.localreplay-web/replayADeveloper + Test Automation (Wave A)Migrate compatibility route in Wave A; add API-form alias if needed.Route type revert + REPLAY_ROUTER_ENABLED=false (RMW-03).
riskengine.stella-ops.localriskengine-web/riskengineCDeveloper + Test Automation (Wave C)Migrate compatibility route in control-plane wave; add API alias if required.Route type revert + RISKENGINE_ROUTER_ENABLED=false (RMW-03).
sbomservice.stella-ops.localsbomservice/api/change-traces, /api/compare, /api/sbomservice, /api/v1/lineage, /api/v1/sbom, /api/v1/sources, /sbomserviceDDeveloper + Test Automation (Wave D)Migrate API prefixes first; keep root compatibility path until graph/feed wave acceptance.Route type revert + SBOMSERVICE_ROUTER_ENABLED=false (RMW-03).
scanner.stella-ops.localscanner-web/api/fix-verification, /api/v1/scanner, /api/v1/secrets, /api/v1/triage, /api/v1/vulnerabilities, /api/v1/watchlist, /scannerDDeveloper + Test Automation (Wave D)Migrate API prefixes first; keep root compatibility path until scanner behavioral checks pass.Route type revert + SCANNER_ROUTER_ENABLED=false (RMW-03).
scheduler.stella-ops.localscheduler-web/api/scheduler, /schedulerCDeveloper + Test Automation (Wave C)Migrate API prefix first, then root compatibility path.Route type revert + SCHEDULER_ROUTER_ENABLED=false (RMW-03).
signals.stella-ops.localsignals/api/v1/signals, /signalsDDeveloper + Test Automation (Wave D)Migrate API prefix first, then root compatibility path.Route type revert + SIGNALS_ROUTER_ENABLED=false (RMW-03).
signer.stella-ops.localsigner/signerBDeveloper + Test Automation (Wave B)Migrate compatibility route in trust/evidence wave with signing validation.Route type revert + SIGNER_ROUTER_ENABLED=false (RMW-03).
smremote.stella-ops.localsmremote/smremoteADeveloper + Test Automation (Wave A)Migrate compatibility route in Wave A; add API alias if required.Route type revert + SMREMOTE_ROUTER_ENABLED=false (RMW-03).
symbols (source retired)predecessor host frozenHub-owned binary/symbol routes-VulnerabilitiesSee current ownership; no legacy aliasesStanding-estate window separately authorized.
taskrunner.stella-ops.localtaskrunner-web/taskrunnerCDeveloper + Test Automation (Wave C)Migrate compatibility route in control-plane wave; add API alias if required.Route type revert + TASKRUNNER_ROUTER_ENABLED=false (RMW-03).
timelineindexer.stella-ops.localtimeline-indexer-web/timelineindexerPILOTDeveloper (pilot accepted)Timeline API is already microservice (/api/v1/timeline); keep root compatibility route reverse proxy until later cleanup.Route type revert + TIMELINE_ROUTER_ENABLED=false (already supported).
unknowns.stella-ops.localunknowns-web/unknownsADeveloper + Test Automation (Wave A)Migrate compatibility route in Wave A; add API alias if required.Route type revert + UNKNOWNS_ROUTER_ENABLED=false (RMW-03).
vexhub.stella-ops.localvexhub-web/api/v1/vex, /api/vex, /vexhubDDeveloper + Test Automation (Wave D)Migrate API prefixes first, then root compatibility path.Route type revert + VEXHUB_ROUTER_ENABLED=false (RMW-03).
vexlens.stella-ops.localvexlens-web/api/v1/vexlens, /vexlensDDeveloper + Test Automation (Wave D)Migrate API prefix first, then root compatibility path.Route type revert + VEXLENS_ROUTER_ENABLED=false (RMW-03).
vulnexplorer.stella-ops.localapi/api/vuln-explorer, /vulnexplorerDDeveloper + Test Automation (Wave D)Migrate API prefix first; keep root compatibility path until vuln explorer routing is validated.Route type revert + VULNEXPLORER_ROUTER_ENABLED=false (RMW-03).

Wave Acceptance Mapping

WaveAcceptance Owner
ADeveloper + Test Automation (Wave A)
BDeveloper + Test Automation (Wave B)
CDeveloper + Test Automation (Wave C)
DDeveloper + Test Automation (Wave D)
PILOTDeveloper (pilot accepted)

Notes