> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bijection.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Branches with a controlled carrier

> Compare allocation policies, publish an exact reviewed decision, and reconcile a shipment without duplicate effects.

Part of [Allocate scarce stock and review scenarios](/use-cases/northstar/index).

## Complete stack

| System | Custody | Role | Owner | State | Version source | Failure contract |
| - | - | - | - | - | - | - |
| bijection | run | Objects, operations, branches, review and publication | Application owner | Operational state in PostgreSQL; file storage owned by the backend | Explicit native build manifest, CLI digest and application source digest | Accepted requests retain their identity through lost replies and process restart. |
| carrier | run | Shipment booking and reconciliation | Customer companion service | Booking records keyed by external call identity | Controlled carrier source captured with the journey | An ambiguous reply remains unknown until reconciliation. |
| postgres | run | Operational persistence | Qualification resource owner | Disposable local cluster with an exact resource record | Installed PostgreSQL executable version recorded by harness | Only the recorded cluster is stopped by cleanup. |

## Connections

* **bijection → postgres:** Transactional operational persistence. Identity: Backend database credential.
* **bijection → carrier:** Durable booking intent and status reconciliation. Identity: Run-scoped carrier capability.

## Deployment inputs

* `build` (file, required): Source-bound native build manifest.
* `cli` (file, required): Bijection CLI executable.
* `sdk` (directory, required): Built Bijection SDK matching the selected CLI and backend.

## Bounds and cleanup

One loopback backend and one disposable PostgreSQL cluster; bounded fixture; no cloud runtime.

Maximum duration: 2400 seconds. Maximum captured log: 4194304 bytes.

Estimated cost: No provider usage for this recipe. Uses the selected local machine.

Cleanup: The qualification owner stops its exact child processes, removes credentials and stops its owned PostgreSQL cluster. A run passes only after cleanup is observed.

The executable runbook is maintained at `examples/northstar/recipes/controlled-carrier/runbook.md`. A declared journey is verified only when every named check appears in a successful execution report and cleanup has been observed.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.