Validated, programmatic TypeBridge workspace configuration.
This unpublished orchestration boundary deliberately stops before YAML
parsing, schema loading, history, persistence, provider/network I/O, secret
resolution, or compiled-runtime construction. The one bounded filesystem
observation is explicit custom TLS trust material: callers inject a local
source service that canonicalizes and proves the configured CA file before
an inert, fully validated [TypeBridgeConfig] is returned.