Agent execution sandbox
An isolated environment where agents can run code and call internal tools without holding standing credentials to production systems.
Every product, initiative and migration the platform teams own. Filter by team, category or stage to find what you need.
Showing all 13 streamlines
An isolated environment where agents can run code and call internal tools without holding standing credentials to production systems.
A searchable index of the datasets we hold: what is in them, who owns them, how fresh they are and whether they contain personal data.
Starting points for new services that come wired up correctly: CI, logging, metrics, health checks and deployment, without copying another team's repo.
The previous CI system. Still running for pipelines that have not migrated, and switching off for good at the end of March 2027.
38 pipelines still to migrate before the March 2027 shutdown
Cluster-wide upgrade to Kubernetes 1.31. Workloads still using removed beta APIs will stop working when their cluster is upgraded.
Production clusters upgrade from 1 October — Ingress v1beta1 is removed
One endpoint for every model we use, with per-team quotas, cost attribution, audit logging and failover between providers.
Direct provider API keys stop working on 2 November
A shared way to measure whether a prompt or model change actually improved anything, before it reaches customers.
A shared cache for build artifacts so CI and local builds stop repeating work another machine has already done.
Blocks commits containing credentials before they reach a remote branch, and flags secrets already in history so they can be rotated.
Push protection is on for the 20 busiest repositories
The supported way to run CI here: autoscaling self-hosted runners with access to internal networks, artifact caching and deployment credentials.
The answer to "who owns this service and how do I page them", kept current automatically rather than by people remembering to update a wiki page.
A reproducible local environment per repository, so a new joiner can run the service on their first morning instead of their first week.
The separate search index over the internal wiki. Switched off in June 2026 once search moved into the service catalog.