{
  "version": 1,
  "edition": "lily",
  "acceptance": {
    "document": "ACCEPTANCE.md",
    "meaning": "Passing verify covers executed gates only; first-release acceptance and external evidence are recorded in ACCEPTANCE.md."
  },
  "commands": {
    "setup": {
      "argv": [
        "pnpm",
        "run",
        "setup"
      ],
      "effects": "Provision or reuse the remote D1, R2, and Queue resources, apply no migrations, write ignored deployment resource IDs, and render the ignored remote Wrangler configuration. Use --dry-run after the command separator for a read-only plan."
    },
    "deploy": {
      "argv": [
        "pnpm",
        "run",
        "deploy"
      ],
      "effects": "Run remote setup, build the Worker, apply remote D1 migrations, upload the emitted Worker with private manifest secrets, and wait for the configured APP_ORIGIN /health response. Ordered migrations include the selected owner SQL after core; migration failure stops the update."
    },
    "verify": {
      "argv": [
        "pnpm",
        "run",
        "verify"
      ],
      "effects": "Run composition, configuration, source/runtime, migration, build, artifact, and browser checks against local isolated state; this may exit nonzero when the contract reporter still has uncovered clauses. Includes isolated owner-migration ordering, rerun and rollback checks."
    },
    "export": {
      "argv": [
        "pnpm",
        "run",
        "export"
      ],
      "effects": "Create private D1/R2 archive from explicitly offline installation; see DATA-PORTABILITY.md for archive path and required config arguments."
    },
    "import": {
      "argv": [
        "pnpm",
        "run",
        "import"
      ],
      "effects": "Restore verified private archive into freshly migrated empty offline D1/R2 target and verify equivalent archive; no external provider mutations."
    }
  },
  "requiredEnvironment": [
    "APP_ORIGIN",
    "INITIAL_OWNER_EMAIL",
    "SESSION_SECRET",
    "SUPPORT_EMAIL",
    "MAIL_API_KEY"
  ],
  "authentication": "Remote setup accepts an existing Wrangler OAuth login or CLOUDFLARE_API_TOKEN; set CLOUDFLARE_ACCOUNT_ID when the identity can access multiple Cloudflare accounts. Provider values are supplied through the environment and uploaded through a temporary private secrets file.",
  "configuration": [
    {
      "path": "seed.json",
      "description": "Declares Lily deployment inputs, optional adapters, resource assumptions, and conditional environment requirements."
    },
    {
      "path": "deploy/wrangler.template.toml",
      "description": "Template for the generated Worker, D1, R2, Queue, cron, and public configuration bindings."
    },
    {
      "path": "src/ext/config.ts",
      "description": "Buyer-owned public organization identity and theme configuration."
    },
    {
      "path": ".seed/deployment/production.json",
      "description": "Ignored setup receipt containing the selected environment's provisioned resource names and IDs; generated by setup and never committed."
    }
  ],
  "health": {
    "path": "/health",
    "meaning": "Checks D1, R2 list, Queue acceptance and runtime configuration within a900ms dependency deadline;503 for missing, failing or late dependencies. Queue acceptance is not consumer execution or provider mail delivery."
  },
  "notes": [
    "The default remote environment is production; set LILY_DEPLOY_ENV to a lowercase environment slug when using another deployment namespace.",
    "TICKET_MAIL_* values are required only when the optional ticket-mail channel is enabled; optional commerce, AI, and external-sync values are buyer-selected adapter inputs.",
    "verify reports executed local gates only. It does not establish full first-release acceptance, provider delivery, hosted readiness, or the obligations recorded in ACCEPTANCE.md.",
    "The operations check is read-only static local input validation. It does not inspect Cloudflare, generated caches, built artifacts, migration state, or hosted health."
  ]
}
