{
  "version": 1,
  "edition": "ferry",
  "acceptance": {
    "document": "ACCEPTANCE.md",
    "meaning": "Passing verify covers executed gates only; first-release acceptance and external evidence are recorded in ACCEPTANCE.md."
  },
  "commands": {
    "setup": {
      "argv": [
        "pnpm",
        "run",
        "setup"
      ],
      "effects": "Resolve the authenticated Cloudflare account, provision or reuse the named D1, write ignored deployment settings and generated Wrangler configuration, and leave the deployment ready for deploy."
    },
    "deploy": {
      "argv": [
        "pnpm",
        "run",
        "deploy"
      ],
      "effects": "Run setup, audit the production configuration, build the Worker, apply remote migrations, initialize or preserve the owner and business, upload private secrets, publish the Worker, and wait for /health."
    },
    "verify": {
      "argv": [
        "pnpm",
        "run",
        "verify"
      ],
      "effects": "Run typecheck, lint, validation, bootstrap and composition checks, component tests, and the build; browser verification is a separate test:browser command."
    },
    "onboard": {
      "argv": [
        "node",
        "scripts/install.mjs"
      ],
      "effects": "Open a loopback Ferry setup browser without application dependencies; approval installs frozen dependencies and starts an empty local D1 workspace through ordinary pnpm dev. No remote resources or mail are created."
    }
  },
  "requiredEnvironment": [
    "FERRY_WORKER_NAME",
    "FERRY_OWNER_EMAIL",
    "FERRY_OWNER_NAME",
    "FERRY_BUSINESS_NAME",
    "APP_URL",
    "EMAIL_FROM",
    "AUTH_SESSION_SECRET",
    "SENDGRID_API_KEY"
  ],
  "authentication": "Remote setup resolves a single authenticated Wrangler OAuth account or CLOUDFLARE_API_TOKEN; set CLOUDFLARE_ACCOUNT_ID when multiple accounts are available. AUTH_SESSION_SECRET and SENDGRID_API_KEY are uploaded through a temporary private secrets file; FERRY_LOCAL_AUTH and FERRY_LOCAL_DEMO are local-only and rejected for deployment.",
  "configuration": [
    {
      "path": "seed.json",
      "description": "Declares Ferry environment inputs, provider adapters, deployment route, and resource assumptions."
    },
    {
      "path": "scripts/lib/configuration.mjs",
      "description": "Validates deployment settings and generates the production Worker, D1, assets, and schedule configuration."
    },
    {
      "path": "src/ext/config.ts",
      "description": "Buyer-owned public organization identity, owner name, landing copy, credit, and theme."
    },
    {
      "path": ".seed/deployment/ferry.json",
      "description": "Ignored setup receipt containing the selected account, Worker, D1, origin, and preserved deployment settings."
    }
  ],
  "health": {
    "path": "/health",
    "meaning": "Returns the Ferry runtime service status after the Worker can reach its HTTP handler; it does not inspect D1, mail delivery, scheduled work, or deal health."
  },
  "notes": [
    "FERRY_DATABASE_NAME, FERRY_TIME_ZONE, and FERRY_CURRENCY are optional deployment settings with defaults; FERRY_LOCAL_AUTH and FERRY_LOCAL_DEMO cannot be deployed.",
    "verify does not run the full browser journey, hosted provider checks, mailbox delivery, or complete contract acceptance. See ACCEPTANCE.md for release obligations.",
    "The follow-up send control remains disabled in the current bounded implementation; provider acceptance evidence does not imply a complete outreach workflow.",
    "The operations check is read-only static local input validation. It does not inspect Cloudflare, generated caches, build output, migration state, or hosted health."
  ]
}
