Secure Paved Road Pattern: Architecture Visual Type and Design Constraints

The Secure Paved Road pattern routes to the Architecture visual type and enforces strict complexity constraints including limits of 3 trust zones, 8 components, 10 total paths, and exactly 1 privileged gate.

The secure paved road pattern is a semantic pattern defined in the cathrynlavery/diagram-design repository for visualizing system security boundaries, deployment paths, and trust relationships. According to the source code in semantic-patterns.md, this pattern specifically maps to the Architecture visual type to ensure clear representation of ingress routes, protected zones, and privileged access points within infrastructure topology diagrams.

Visual Type Mapping

The Secure Paved Road pattern explicitly routes to the Architecture visual type. As defined in skills/diagram-design/references/semantic-patterns.md (lines 76-89), this mapping ensures the diagram follows standardized conventions for system overviews, integration maps, and infrastructure topology visualization.

Architecture Layout Conventions

When implementing the secure paved road pattern, the Architecture visual type requires specific layout standards defined in skills/diagram-design/references/type-architecture.md (lines 5-14). These include:

  • Zone-based organization: Distinct rectangular regions representing trust boundaries
  • Orthogonal connectors: Right-angled path lines between components
  • Standardized styling: Consistent fill colors, stroke weights, and typography for zones and components

Complexity Budget and Constraints

The pattern enforces a strict complexity budget to prevent diagram overload and maintain clarity. According to lines 80-84 in semantic-patterns.md, the following hard limits apply:

Constraint Limit Purpose
Trust zones ≤ 3 zones Keeps boundary visualization manageable
Components ≤ 8 distinct components Prevents overcrowding in system overview
Paths ≤ 10 total routes Limits cognitive load for route analysis
Forbidden paths ≤ 2 blocked routes Highlights critical security boundaries without clutter
Privileged gate Exactly 1 gate Ensures single point of elevated privilege identification

If a diagram exceeds these limits, the specification requires splitting detail into a separate catalog figure rather than compromising the primary view.

Anti-Patterns to Avoid

Lines 84-86 of semantic-patterns.md define specific anti-patterns that violate the secure paved road pattern integrity:

  • Generic security boxes: Never use vague "security" containers without explicit route connections showing data flow
  • Crossing forbidden arrows: Avoid drawing blocked routes that visually cross into protected zones, as this creates ambiguity about boundary enforcement
  • Unlabeled secrets: Always label identities, secrets, and credentials; omission creates operational risk
  • Rejoining bypass paths: Never allow a blocked or bypass path to reconnect with the approved route, as this implies a vulnerability in the paved road logic

Implementation Example

Below is a minimal HTML/SVG implementation following the Architecture visual type conventions for the Secure Paved Road pattern. This example satisfies all complexity constraints while demonstrating trust zones, permitted paths, forbidden routes, and the required privileged gate.

<!-- assets/example-secure-paved-road.html -->
<!DOCTYPE html>
<html>
<head>
  <meta charset="UTF-8">
  <title>Secure Paved Road Example</title>
  <link rel="stylesheet" href="style.css">
</head>
<body>
  <svg width="800" height="400">
    <!-- Trust zone rectangles -->
    <rect x="50"  y="50" width="300" height="300" rx="8"
          fill="rgba(45,49,66,0.02)" stroke="rgba(45,49,66,0.10)"/>
    <text x="200" y="45" font-size="9" fill="#2d313a">Public Zone</text>

    <rect x="450" y="50" width="300" height="300" rx="8"
          fill="rgba(45,49,66,0.02)" stroke="rgba(45,49,66,0.10)"/>
    <text x="600" y="45" font-size="9" fill="#2d313a">Private Zone</text>

    <!-- Components -->
    <rect id="ingress" x="120" y="120" width="120" height="60" fill="#e0e5f2"/>
    <text x="180" y="150" text-anchor="middle" font-size="8">Ingress</text>

    <rect id="gateway" x="560" y="120" width="120" height="60" fill="#e0e5f2"/>
    <text x="620" y="150" text-anchor="middle" font-size="8">Gateway</text>

    <rect id="service" x="560" y="250" width="120" height="60" fill="#e0e5f2"/>
    <text x="620" y="280" text-anchor="middle" font-size="8">Service</text>

    <!-- Permitted path (solid) -->
    <path d="M240,150 H560" stroke="#2d313a" marker-end="url(#arrow)"/>

    <!-- Forbidden path (dashed, stops before zone) -->
    <path d="M240,200 H560" stroke="#c03c3c" stroke-dasharray="4,3"
          marker-end="url(#stop)"/>

    <!-- Privileged gate (different style) -->
    <path d="M560,180 V250" stroke="#006400" marker-end="url(#arrow)"/>
    <text x="560" y="220" font-size="7" fill="#006400" text-anchor="middle">
      Privileged Gate
    </text>

    <!-- Arrow markers (defs omitted for brevity) -->
  </svg>
</body>
</html>

This implementation demonstrates:

  • 2 trust zones (Public and Private) within the ≤3 limit
  • 3 components (Ingress, Gateway, Service) within the ≤8 limit
  • One permitted path (solid line) and one forbidden path (dashed red line) within the ≤2 forbidden path limit
  • Exactly one privileged gate (green vertical arrow) as required

Preview this example by opening the file in a browser or via the built-in gallery at skills/diagram-design/assets/index.html.

Summary

  • The secure paved road pattern maps exclusively to the Architecture visual type for system infrastructure visualization
  • Strict complexity budget allows maximum 3 trust zones, 8 components, and 10 total paths
  • Exactly one privileged gate must be present, requiring explicit elevated privilege labeling
  • Maximum 2 forbidden paths permitted, using distinct visual styling (dashed lines, stop markers)
  • Specific anti-patterns prohibit generic security boxes, unlabeled secrets, and rejoining bypass routes

Frequently Asked Questions

What visual type does the secure paved road pattern route to?

The secure paved road pattern routes to the Architecture visual type. According to semantic-patterns.md (lines 76-89), this mapping ensures the diagram follows standardized conventions for zones, connectors, and infrastructure topology visualization.

How many trust zones can a secure paved road diagram contain?

A secure paved road diagram may contain at most 3 trust zones. This constraint, defined in the complexity budget (lines 80-84), ensures that boundary visualization remains clear and manageable without overwhelming the viewer with excessive security perimeters.

What is the privileged gate constraint in the secure paved road pattern?

The pattern requires exactly one privileged gate that demands elevated privilege. This constraint ensures the diagram explicitly identifies the single critical access point requiring special authorization, preventing ambiguity about where privileged escalation occurs in the system architecture.

What happens if a diagram exceeds the secure paved road complexity limits?

If a diagram exceeds the limits of 3 trust zones, 8 components, or 10 total paths, the specification requires splitting the detail into a separate catalog figure rather than cramming information into the primary diagram. This maintains the clarity and readability mandated by the complexity budget defined in the source files.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →