Expand description
Validated, programmatic TypeBridge workspace configuration.
This public orchestration boundary deliberately stops before schema loading,
history, persistence, provider/network I/O, secret resolution, or
compiled-runtime construction. Its bounded filesystem observations are the
explicitly supplied workspace YAML and custom TLS trust material: callers
inject local source services that canonicalize and prove those inputs before
an inert, fully validated TypeBridgeConfig is returned.
Structs§
- Bundle
Projection Context - Exact target policy plus handler and resource evidence for one compiled projection.
- Bundle
Verification Context - Explicit capability, extension, scope, profile, and projection trust context.
- Config
Origin - An immutable source origin for one workspace manifest.
- Extension
Requirement - One exact local extension handler/version requirement.
- Located
Config Spec - A strict config spec permanently bound to the manifest that owns its paths.
- Migration
Directory Authority - An open, workspace-bound migration-directory authority.
- Migration
Plan Entry - One dependency-ordered entry of an offline apply plan.
- Migration
V2Directory - A confined direct V2 migration-history directory.
- Output
Directory - A confined output directory for one shipped binding target.
- Schema
Authority Output Path - A confined portable file path for the generated server schema authority.
- Schema
Bundle Error - A fail-closed bundle failure retaining nested contract or schema diagnostics.
- Schema
SetPath - A confined path to one portable schema-set manifest.
- Secret
Reference - A retained environment-variable reference, never a resolved secret value.
- Secret
Slot - A deterministic logical slot containing one symbolic secret reference.
- Type
Bridge Config - An inert validated workspace policy produced only by its builder.
- Type
Bridge Config Builder - A consuming typed builder for
TypeBridgeConfig. - Type
Bridge Config Services - Explicit services used to validate a programmatic config hermetically.
- Type
Bridge Config Spec - A strict parsed workspace spec retaining exact source, comments, and spans.
- Type
Bridge Runtime - Source-free runtime installed only from a verified compiled bundle.
- Type
Bridge Workspace - An opaque source-authority workspace with resolved schema and managed state.
- Type
Bridge Workspace Services - Explicit local services and capabilities used to construct a source workspace.
- Verified
Schema Bundle - Opaque constructor-verified compiled schema bundle.
- Verified
Workspace Lock - Canonical lock bytes verified against one supplied source workspace.
- Workspace
Config Error - A structured programmatic workspace validation failure.
- Workspace
Directory Authority - A retained, no-follow capability for one canonical workspace root.
- Workspace
Environment - One named, inert deployment environment.
- Workspace
Lock - Canonical current lock bytes produced explicitly from one source workspace.
- Workspace
Output Directory - A retained, confined directory used for generated workspace artifacts.
- Workspace
Root - An explicit absolute workspace root whose canonical spelling is service-verified.
- Workspace
Root Ca - A canonical, workspace-confined custom root CA file.
- Workspace
Service Error - A stable failure reported by an injected, local-only config service.
Enums§
- Schema
Bundle Error Code - Stable high-level failure classification for bundle construction and verification.
- Type
Bridge Workspace Error - A fail-closed source-workspace construction failure retaining nested evidence.
- Workspace
Config Error Code - Stable categories returned while validating programmatic workspace policy.
- Workspace
Lock Error - A fail-closed workspace lock failure.
- Workspace
Lock Error Code - Stable error categories for explicit workspace lock generation and verification.
- Workspace
Transport Policy - Validated transport policy for one workspace environment.
Constants§
- MAX_
BACKFILL_ INTENT_ BYTES - Maximum bytes accepted for one source backfill intent.
- MAX_
SCHEMA_ BUNDLE_ BYTES - Maximum canonical compiled bundle size: 16 MiB.
- MAX_
WORKSPACE_ LOCK_ BYTES - Maximum accepted canonical workspace lock bytes.
- SCHEMA_
BUNDLE_ FINGERPRINT_ CANONICALIZATION - Canonicalization identity for the first bundle content envelope.
- SCHEMA_
BUNDLE_ FINGERPRINT_ DOMAIN - Fingerprint domain for the exact bundle content envelope.
- TYPEBRIDGE_
BACKFILL_ INTENT_ V1 - Exact format identifier for the first closed backfill-intent YAML wire.
- TYPEBRIDGE_
SCHEMA_ BUNDLE_ V1 - The first closed compiled-schema bundle format.
- TYPEBRIDGE_
WORKSPACE_ LOCK_ V1 - The exact first canonical workspace lock format.
- TYPEBRIDGE_
WORKSPACE_ SEMANTIC_ PROFILE_ ID - The preferred server-semantic profile for newly authored V2 workspaces.
- TYPEBRIDGE_
WORKSPACE_ SEMANTIC_ PROFILE_ IDS - Frozen server-semantic profiles accepted for workspace generation.
- TYPEBRIDGE_
WORKSPACE_ V1_ FORMAT - The only accepted language-neutral workspace manifest discriminator.
Traits§
- Extension
Registry Service - A local registry for projection-only extension requirements.
- Secret
Reference Service - A validator for symbolic secret references.
- Workspace
Source Service - A narrow local source service for root and custom-CA path validation.
Functions§
- build_
verified_ schema_ bundle - Build and immediately reverify one source-free bundle from a source workspace.
- c_
symbol_ prefix_ for_ app_ label - Derive the stable C global-symbol prefix owned by a migration application.
- decode_
verified_ schema_ bundle - Decode, reconstruct, and independently verify one canonical compiled bundle.
- encode_
verified_ schema_ bundle - Return exact canonical bytes retained by an already verified bundle.
- generate_
workspace_ lock - Explicitly generate canonical current lock bytes without writing them.
- parse_
backfill_ intent - Parse and validate one source-located closed copy-attribute intent.
- verify_
workspace_ lock - Verify canonical lock bytes against a freshly constructed source workspace.