Expand description
Validated, programmatic TypeBridge workspace configuration.
This unpublished orchestration boundary deliberately stops before YAML
parsing, schema loading, history, persistence, provider/network I/O, secret
resolution, or compiled-runtime construction. The one bounded filesystem
observation is explicit custom TLS trust material: callers inject a local
source service that canonicalizes and proves the configured CA file before
an inert, fully validated TypeBridgeConfig is returned.
Structs§
- Bundle
Projection Context - Exact target policy and handler evidence allowed for one compiled projection.
- Bundle
Verification Context - Explicit capability, extension, scope, profile, and projection trust context.
- Config
Origin - An immutable source origin for one workspace manifest.
- Extension
Requirement - One exact local extension handler/version requirement.
- Located
Config Spec - A strict config spec permanently bound to the manifest that owns its paths.
- Migration
Directory Authority - An open, workspace-bound migration-directory authority.
- Migration
Plan Entry - One dependency-ordered entry of an offline apply plan.
- Migration
V2Directory - A confined direct V2 migration-history directory.
- Output
Directory - A confined output directory for one shipped binding target.
- Schema
Bundle Error - A fail-closed bundle failure retaining nested contract or schema diagnostics.
- Schema
SetPath - A confined path to one portable schema-set manifest.
- Secret
Reference - A retained environment-variable reference, never a resolved secret value.
- Secret
Slot - A deterministic logical slot containing one symbolic secret reference.
- Type
Bridge Config - An inert validated workspace policy produced only by its builder.
- Type
Bridge Config Builder - A consuming typed builder for
TypeBridgeConfig. - Type
Bridge Config Services - Explicit services used to validate a programmatic config hermetically.
- Type
Bridge Config Spec - A strict parsed workspace spec retaining exact source, comments, and spans.
- Type
Bridge Runtime - Source-free runtime installed only from a verified compiled bundle.
- Type
Bridge Workspace - An opaque source-authority workspace with resolved schema and managed state.
- Type
Bridge Workspace Services - Explicit local services and capabilities used to construct a source workspace.
- Verified
Schema Bundle - Opaque constructor-verified compiled schema bundle.
- Verified
Workspace Lock - Canonical lock bytes verified against one supplied source workspace.
- Workspace
Config Error - A structured programmatic workspace validation failure.
- Workspace
Directory Authority - A retained, no-follow capability for one canonical workspace root.
- Workspace
Environment - One named, inert deployment environment.
- Workspace
Lock - Canonical current lock bytes produced explicitly from one source workspace.
- Workspace
Output Directory - A retained, confined directory used for generated workspace artifacts.
- Workspace
Root - An explicit absolute workspace root whose canonical spelling is service-verified.
- Workspace
Root Ca - A canonical, workspace-confined custom root CA file.
- Workspace
Service Error - A stable failure reported by an injected, local-only config service.
Enums§
- Schema
Bundle Error Code - Stable high-level failure classification for bundle construction and verification.
- Type
Bridge Workspace Error - A fail-closed source-workspace construction failure retaining nested evidence.
- Workspace
Config Error Code - Stable categories returned while validating programmatic workspace policy.
- Workspace
Lock Error - A fail-closed workspace lock failure.
- Workspace
Lock Error Code - Stable error categories for explicit workspace lock generation and verification.
- Workspace
Transport Policy - Validated transport policy for one workspace environment.
Constants§
- MAX_
SCHEMA_ BUNDLE_ BYTES - Maximum canonical compiled bundle size: 16 MiB.
- MAX_
WORKSPACE_ LOCK_ BYTES - Maximum accepted canonical workspace lock bytes.
- SCHEMA_
BUNDLE_ FINGERPRINT_ CANONICALIZATION - Canonicalization identity for the first bundle content envelope.
- SCHEMA_
BUNDLE_ FINGERPRINT_ DOMAIN - Fingerprint domain for the exact bundle content envelope.
- TYPEBRIDGE_
SCHEMA_ BUNDLE_ V1 - The first closed compiled-schema bundle format.
- TYPEBRIDGE_
WORKSPACE_ LOCK_ V1 - The exact first canonical workspace lock format.
- TYPEBRIDGE_
WORKSPACE_ SEMANTIC_ PROFILE_ ID - The exact server-semantic profile accepted by the first V2 workspace.
- TYPEBRIDGE_
WORKSPACE_ V1_ FORMAT - The only accepted language-neutral workspace manifest discriminator.
Traits§
- Extension
Registry Service - A local registry for projection-only extension requirements.
- Secret
Reference Service - A validator for symbolic secret references.
- Workspace
Source Service - A narrow local source service for root and custom-CA path validation.
Functions§
- build_
verified_ schema_ bundle - Build and immediately reverify one source-free bundle from a source workspace.
- decode_
verified_ schema_ bundle - Decode, reconstruct, and independently verify one canonical compiled bundle.
- encode_
verified_ schema_ bundle - Return exact canonical bytes retained by an already verified bundle.
- generate_
workspace_ lock - Explicitly generate canonical current lock bytes without writing them.
- verify_
workspace_ lock - Verify canonical lock bytes against a freshly constructed source workspace.