--- since: 1.2.1 --- # Coding and Architecture Rules ## Keep Views Thin Views should orchestrate, not implement domain workflows. ## Services Own Business Logic Shared business rules belong in services. ## Avoid Direct State Mutation Use explicit workflows for lifecycle transitions. ## Prefer Explicit Configuration Do not silently infer production settings. ## Keep Calculators Pure Financial calculations should be deterministic and side-effect free. ## Protect Cross-Domain Boundaries Use stable interfaces rather than reaching into another domain's private implementation. ## Security Never commit: ```text passwords API keys JWT secrets encryption keys private certificates database credentials ``` ## Resource Awareness The production VM is intentionally small. Avoid unnecessary background workers, duplicate processes and memory-heavy infrastructure.