{
  "version": 1,
  "edition": "orbit",
  "acceptance": {
    "document": "ACCEPTANCE.md",
    "meaning": "Passing verify covers executed gates only; first-release acceptance and external evidence are recorded in ACCEPTANCE.md."
  },
  "commands": {
    "setup": {
      "argv": [
        "pnpm",
        "run",
        "setup"
      ],
      "effects": "Read the explicit deployment config, provision or reuse the named remote D1, write ignored resource configuration, and apply remote migrations. Owner bootstrap and Worker publication remain separate deploy steps."
    },
    "deploy": {
      "argv": [
        "pnpm",
        "run",
        "deploy"
      ],
      "effects": "Validate the owner file and selected provider inputs, provision or reuse the named D1, bootstrap the owner, apply migrations, build, upload private configuration, publish the Worker and minute timer, and wait for /health."
    },
    "verify": {
      "argv": [
        "pnpm",
        "run",
        "verify"
      ],
      "effects": "Run boundary and manifest checks, real D1 core tests, build/typecheck, composition and deployment checks, isolated browser journeys, emitted-Worker proof, declared-capacity measurements, and result-bearing contract/baseline reporting."
    }
  },
  "requiredEnvironment": [
    "SENDGRID_API_KEY",
    "MAIL_FROM",
    "OWNER_FILE"
  ],
  "authentication": "Remote setup uses the explicit .seed/deployment/config.json accountId and an authenticated Wrangler identity. Deploy requires an absolute owner JSON path supplied with --owner-file or OWNER_FILE, plus SENDGRID_API_KEY and MAIL_FROM; private mail secrets are uploaded through a temporary file. Customer outreach additionally requires MAIL_REPLY_TO and SENDGRID_UNSUBSCRIBE_GROUP_ID; signed relay and reply keys are separate from native operator sessions. Optional AI inputs and source encryption are declared in seed.json.",
  "configuration": [
    {
      "path": "seed.json",
      "description": "Declares Orbit's conditional auth and mail adapter inputs, deployment route, and resource assumptions."
    },
    {
      "path": ".seed/deployment/config.json",
      "description": "Owner-created ignored deployment identity containing workerName, environment, accountId, and origin; required by setup."
    },
    {
      "path": "deploy/wrangler.template.toml",
      "description": "Template for local and generated Worker and D1 configuration."
    },
    {
      "path": "SETUP.md",
      "description": "Owner JSON shape, local setup, Cloudflare deployment, sender configuration, and repeat-deploy rules."
    },
    {
      "path": "src/ext/config.ts",
      "description": "Buyer-owned public identity plate name, description, and image/credit settings."
    }
  ],
  "health": {
    "path": "/health",
    "meaning": "Checks the Orbit D1 workspace_settings table and returns service/database status. It does not verify SendGrid acceptance, mailbox delivery, AI, queue, cron, or complete workflow readiness."
  },
  "notes": [
    "Every deploy requires an absolute owner file: use -- --owner-file /absolute/path/to/owner.json or set OWNER_FILE to that path. The owner file is never committed.",
    "AUTH_ORIGIN is generated from the ignored deployment config origin. SENDGRID_API_KEY and MAIL_FROM are conditional in seed.json and become required when native mail authentication or approved outbound mail is configured; the operations config adapter validates the selected inputs.",
    "The Worker implements minute-timer evaluation, scheduled dispatch, delivery reconciliation and notifications. Signed sources, SendGrid relay events and signed inbound replies have separately authenticated endpoints. No R2 or Queue is required.",
    "verify reports executed local gates only and does not establish first-release acceptance, provider delivery, or hosted readiness; see ACCEPTANCE.md.",
    "The operations check is read-only static local input validation. It does not inspect Cloudflare, generated caches, build output, migration state, or hosted health."
  ]
}
