What this covers
This is a managed machine, not managed code. We are responsible for the machine and everything that keeps it serving; you are responsible for the application running on it and how it behaves.
Before you start
Nothing to prepare — this article exists so there is no argument later about who was meant to do what.
How to do it
- We own the virtual machine, its operating system and its patches.
- We own the JDK: installing it, and keeping it current within the version you pinned.
- We own the machine's toolchain — the JDK, Maven and Gradle — and keep it current within the version you pinned.
- We own the TLS certificate and its renewal.
- We own the backups and the monitoring, and we are the ones woken when the machine stops serving.
- You own your application: its code, its dependencies, its migrations, its correctness, and deploying it.
- You own your JVM tuning — heap sizing, garbage collector choice, thread pools.
- You own what your application talks to, including any database it uses.
What our team checks
If you are unsure which side of the line a problem sits on, ask. Support will look, and will tell you plainly if it turns out to be in your application rather than passing it back without explanation.
Next step
If something is wrong and you cannot tell whose side it is on, open a support request with the time it happened. That is exactly the case this boundary is written for.