{
  "version": 1,
  "edition": "brook",
  "acceptance": {
    "document": "ACCEPTANCE.md",
    "meaning": "Passing verify covers executed gates only; first-release acceptance and external evidence are recorded in ACCEPTANCE.md."
  },
  "commands": {
    "setup": {
      "argv": ["pnpm", "run", "setup"],
      "effects": "Install the frozen lockfile, provision or reuse the named remote D1, apply migrations, initialize or verify the owner, generate ignored deployment configuration, build the Worker, publish it, and check health. Add --prepare-only after the command separator to stop after remote preparation without deploying."
    },
    "deploy": {
      "argv": ["pnpm", "run", "deploy"],
      "effects": "Repeat Brook's complete setup and publish sequence, including production artifact audit, remote migrations, owner-preserving bootstrap, temporary private secrets, Worker upload, and /health verification."
    },
    "verify": {
      "argv": ["pnpm", "run", "verify"],
      "effects": "Run composition and manifest validation, deployment tests, typecheck, implementation tests, the production build, and the local browser journey; these checks do not prove hosted provider effects or complete contract acceptance."
    }
  },
  "requiredEnvironment": [
    "CLOUDFLARE_ACCOUNT_ID",
    "CLOUDFLARE_API_TOKEN",
    "BROOK_WORKER_NAME",
    "BROOK_OWNER_NAME",
    "BROOK_OWNER_STATEMENT",
    "INITIAL_OPERATOR_EMAIL",
    "AUTH_FROM_EMAIL",
    "SUPPORT_FROM_EMAIL",
    "APP_SIGNING_SECRET",
    "SENDGRID_API_KEY"
  ],
  "authentication": "Remote setup requires an explicit CLOUDFLARE_ACCOUNT_ID and CLOUDFLARE_API_TOKEN with the account's Workers, D1, and required routing permissions. Runtime secrets are uploaded through a temporary private secrets file; Stripe and signed delivery credentials are optional adapters.",
  "configuration": [
    {"path": "seed.json", "description": "Declares Brook's required and optional environment inputs, provider adapters, deployment health route, and limits."},
    {"path": "scripts/deployment/plan.mjs", "description": "Validates owner deployment inputs and generates the ignored Worker and D1 configuration."},
    {"path": "src/ext/config.ts", "description": "Buyer-owned public product identity, owner-facing statement, and theme."},
    {"path": "docs/SETUP.md", "description": "Owner, Cloudflare, sender, optional intake, webhook, and Stripe setup requirements."},
    {"path": ".seed/deployment/wrangler.json", "description": "Ignored generated Worker configuration containing the selected account, Worker, D1 and runtime variables."},
    {"path": ".seed/deployment/deployment.json", "description": "Ignored deployment receipt containing the selected account, Worker, D1 and preserved owner settings."}
  ],
  "health": {
    "path": "/health",
    "meaning": "Checks D1 reachability and reports initialization plus whether mail, authentication mail, and optional commerce configuration are present. It does not prove provider delivery or refund execution."
  },
  "notes": [
    "Brook's setup command publishes by default. Use pnpm run setup -- --prepare-only when only remote database and owner preparation is intended; this is a remote operation, not local setup.",
    "CLOUDFLARE_EMAIL_ZONE_ID, STRIPE_SECRET_KEY, and SENDGRID_WEBHOOK_PUBLIC_KEY are optional and apply only to their selected adapters or routing/reporting features.",
    "The configured Stripe key must be treated as an operator-approved commerce provider; setup and deploy never perform a refund.",
    "verify reports executed local gates only and does not establish first-release acceptance, mailbox delivery, live-money acceptance, or the obligations in ACCEPTANCE.md.",
    "The operations check is read-only static local input validation. It does not inspect Cloudflare, generated caches, build output, migration state, or hosted health."
  ]
}
