[{"data":1,"prerenderedAt":1076},["ShallowReactive",2],{"navigation_docs":3,"-develop-pipeline-apps-release-lifecycle":388,"-develop-pipeline-apps-release-lifecycle-surround":1071},[4,82,147,173,202,259,298,355],{"title":5,"icon":6,"redirect":7,"path":8,"stem":9,"children":10,"page":73},"Start","i-lucide-compass","\u002Fintro\u002Fquickstart","\u002Fintro","1.intro",[11,14,18,22,74,78],{"title":12,"path":7,"stem":13},"Quickstart","1.intro\u002F0.quickstart",{"title":15,"path":16,"stem":17},"Pipeline Applications","\u002Fintro\u002Fpipeline-app-walkthrough","1.intro\u002F1.pipeline-app-walkthrough",{"title":19,"path":20,"stem":21},"How Redgold works","\u002Fintro\u002Foverview","1.intro\u002F2.overview",{"title":23,"icon":24,"visibility":25,"redirect":26,"path":27,"stem":28,"children":29,"page":73},"Comparison","i-lucide-scale","private","\u002Fintro\u002Fcomparison\u002Fpositioning","\u002Fintro\u002Fcomparison","1.intro\u002F3.comparison",[30,33,37,41,45,49,53,57,61,65,69],{"title":31,"path":26,"stem":32},"Positioning","1.intro\u002F3.comparison\u002F1.positioning",{"title":34,"path":35,"stem":36},"vs Lovable","\u002Fintro\u002Fcomparison\u002Fvs-lovable","1.intro\u002F3.comparison\u002F10.vs-lovable",{"title":38,"path":39,"stem":40},"vs Cloudflare OS","\u002Fintro\u002Fcomparison\u002Fvs-cloudflare-os","1.intro\u002F3.comparison\u002F11.vs-cloudflare-os",{"title":42,"path":43,"stem":44},"vs a backend-as-a-service","\u002Fintro\u002Fcomparison\u002Fvs-baas","1.intro\u002F3.comparison\u002F2.vs-baas",{"title":46,"path":47,"stem":48},"vs serverless compute","\u002Fintro\u002Fcomparison\u002Fvs-serverless-compute","1.intro\u002F3.comparison\u002F3.vs-serverless-compute",{"title":50,"path":51,"stem":52},"vs a do-it-yourself data stack","\u002Fintro\u002Fcomparison\u002Fvs-diy-data-stack","1.intro\u002F3.comparison\u002F4.vs-diy-data-stack",{"title":54,"path":55,"stem":56},"vs Rama","\u002Fintro\u002Fcomparison\u002Fvs-rama","1.intro\u002F3.comparison\u002F5.vs-rama",{"title":58,"path":59,"stem":60},"vs Apache Spark","\u002Fintro\u002Fcomparison\u002Fvs-spark","1.intro\u002F3.comparison\u002F6.vs-spark",{"title":62,"path":63,"stem":64},"vs Apache DataFusion","\u002Fintro\u002Fcomparison\u002Fvs-datafusion","1.intro\u002F3.comparison\u002F7.vs-datafusion",{"title":66,"path":67,"stem":68},"vs Heroku","\u002Fintro\u002Fcomparison\u002Fvs-heroku","1.intro\u002F3.comparison\u002F8.vs-heroku",{"title":70,"path":71,"stem":72},"vs AI model providers","\u002Fintro\u002Fcomparison\u002Fvs-ai-providers","1.intro\u002F3.comparison\u002F9.vs-ai-providers",false,{"title":75,"path":76,"stem":77},"Common tasks","\u002Fintro\u002Fstarting-points","1.intro\u002F4.starting-points",{"title":79,"path":80,"stem":81},"FAQ","\u002Fintro\u002Ffaq","1.intro\u002F5.faq",{"title":83,"icon":84,"redirect":85,"path":86,"stem":87,"children":88,"page":73},"Examples","i-lucide-chef-hat","\u002Fcookbook\u002Foverview","\u002Fcookbook","10.cookbook",[89,91,95,99,103,107,111,115,119,123,127,131,135,139,143],{"title":83,"path":85,"stem":90},"10.cookbook\u002F1.overview",{"title":92,"path":93,"stem":94},"One-shot task in CI","\u002Fcookbook\u002Fone-shot-ci","10.cookbook\u002F10.one-shot-ci",{"title":96,"path":97,"stem":98},"Rate-limit retries","\u002Fcookbook\u002Fretry-rate-limits","10.cookbook\u002F11.retry-rate-limits",{"title":100,"path":101,"stem":102},"Connect GitHub review automation","\u002Fcookbook\u002Fconnect-github-app","10.cookbook\u002F12.connect-github-app",{"title":104,"path":105,"stem":106},"Delegate a task to another agent","\u002Fcookbook\u002Fdelegate-agent-task","10.cookbook\u002F13.delegate-agent-task",{"title":108,"path":109,"stem":110},"Validate a pipeline application change","\u002Fcookbook\u002Fvalidate-pipeline-app","10.cookbook\u002F14.validate-pipeline-app",{"title":112,"path":113,"stem":114},"Verify a managed application deployment","\u002Fcookbook\u002Fverify-managed-deploy","10.cookbook\u002F15.verify-managed-deploy",{"title":116,"path":117,"stem":118},"First API call","\u002Fcookbook\u002Ffirst-api-call","10.cookbook\u002F2.first-api-call",{"title":120,"path":121,"stem":122},"Python client","\u002Fcookbook\u002Fmodel-api-python","10.cookbook\u002F3.model-api-python",{"title":124,"path":125,"stem":126},"Anthropic Messages","\u002Fcookbook\u002Fanthropic-messages","10.cookbook\u002F4.anthropic-messages",{"title":128,"path":129,"stem":130},"Check credits","\u002Fcookbook\u002Fcheck-credits","10.cookbook\u002F5.check-credits",{"title":132,"path":133,"stem":134},"Query data via MCP","\u002Fcookbook\u002Fmcp-query-data","10.cookbook\u002F6.mcp-query-data",{"title":136,"path":137,"stem":138},"Drive an agent via MCP","\u002Fcookbook\u002Fmcp-drive-agent","10.cookbook\u002F7.mcp-drive-agent",{"title":140,"path":141,"stem":142},"Install the client","\u002Fcookbook\u002Finstall-client","10.cookbook\u002F8.install-client",{"title":144,"path":145,"stem":146},"Use another API host","\u002Fcookbook\u002Fpoint-client-at-host","10.cookbook\u002F9.point-client-at-host",{"title":148,"icon":149,"redirect":150,"path":151,"stem":152,"children":153,"page":73},"Agent operations","i-lucide-network","\u002Ffleet\u002Foverview","\u002Ffleet","11.fleet",[154,157,161,165,169],{"title":155,"path":150,"stem":156},"Running agent work","11.fleet\u002F0.overview",{"title":158,"path":159,"stem":160},"Workstreams and issues","\u002Ffleet\u002Fworkstreams-and-issues","11.fleet\u002F1.workstreams-and-issues",{"title":162,"path":163,"stem":164},"Agent lifecycle","\u002Ffleet\u002Fagent-lifecycle","11.fleet\u002F2.agent-lifecycle",{"title":166,"path":167,"stem":168},"Supervision and recovery","\u002Ffleet\u002Fsupervision","11.fleet\u002F3.supervision",{"title":170,"path":171,"stem":172},"An application workstream from request to delivery","\u002Ffleet\u002Fapplication-workstream","11.fleet\u002F4.application-workstream",{"title":174,"icon":175,"redirect":176,"path":177,"stem":178,"children":179,"page":73},"Architecture","i-lucide-layers","\u002Finfrastructure\u002Foverview","\u002Finfrastructure","3.infrastructure",[180,182,186,190,194,198],{"title":174,"path":176,"stem":181},"3.infrastructure\u002F0.overview",{"title":183,"path":184,"stem":185},"A request through the platform","\u002Finfrastructure\u002Frequest-path","3.infrastructure\u002F11.request-path",{"title":187,"path":188,"stem":189},"Agent work and durable state","\u002Finfrastructure\u002Fagent-work","3.infrastructure\u002F12.agent-work",{"title":191,"path":192,"stem":193},"Data and pipelines","\u002Finfrastructure\u002Fdata","3.infrastructure\u002F3.data",{"title":195,"path":196,"stem":197},"AI and agents","\u002Finfrastructure\u002Fai","3.infrastructure\u002F4.ai",{"title":199,"path":200,"stem":201},"Managed deployment","\u002Finfrastructure\u002Fdeployment","3.infrastructure\u002F7.deployment",{"title":203,"icon":204,"redirect":205,"path":206,"stem":207,"children":208,"page":73},"API","i-lucide-book-marked","\u002Freference\u002Fauthentication","\u002Freference","4.reference",[209,212,216,220,224,228,232,236,240,244,248],{"title":210,"path":205,"stem":211},"Authentication","4.reference\u002F1.authentication",{"title":213,"path":214,"stem":215},"Security disclosure policy","\u002Freference\u002Fsecurity-disclosure","4.reference\u002F11.security-disclosure",{"title":217,"path":218,"stem":219},"Model API","\u002Freference\u002Fllm-api","4.reference\u002F2.llm-api",{"title":221,"path":222,"stem":223},"MCP server","\u002Freference\u002Fmcp","4.reference\u002F2.mcp",{"title":225,"path":226,"stem":227},"Data platform preview","\u002Freference\u002Fdata-platform-preview","4.reference\u002F3.data-platform-preview",{"title":229,"path":230,"stem":231},"Terminal client","\u002Freference\u002Fcli","4.reference\u002F6.cli",{"title":233,"path":234,"stem":235},"Pipeline manifest preview","\u002Freference\u002Fpipeline-preview","4.reference\u002F7.pipeline-preview",{"title":237,"path":238,"stem":239},"Limits and retries","\u002Freference\u002Flimits","4.reference\u002F8.limits",{"title":241,"path":242,"stem":243},"API contract details","\u002Freference\u002Fapi-contracts","4.reference\u002F9.api-contracts",{"title":245,"path":246,"stem":247},"Errors","\u002Freference\u002Ferrors","4.reference\u002F9.errors",{"title":249,"icon":250,"visibility":251,"path":252,"stem":253,"children":254,"page":73},"Public API","i-lucide-route","public","\u002Freference\u002Froutes","4.reference\u002Froutes",[255],{"title":256,"path":257,"stem":258},"V1 routes","\u002Freference\u002Froutes\u002Fv1","4.reference\u002Froutes\u002Fv1",{"title":260,"icon":261,"visibility":25,"redirect":262,"path":263,"stem":264,"children":265,"page":73},"Develop","i-lucide-code","\u002Fdevelop\u002Fpipeline-apps\u002Foverview","\u002Fdevelop","5.develop",[266,270,286,290,294],{"title":267,"path":268,"stem":269},"Author a batch transform","\u002Fdevelop\u002Fauthor-a-batch-transform","5.develop\u002F10.author-a-batch-transform",{"title":271,"visibility":251,"redirect":262,"path":272,"stem":273,"children":274,"page":73},"Pipeline Apps","\u002Fdevelop\u002Fpipeline-apps","5.develop\u002F11.pipeline-apps",[275,278,282],{"title":276,"path":262,"stem":277},"Pipeline apps","5.develop\u002F11.pipeline-apps\u002F1.overview",{"title":279,"path":280,"stem":281},"Collaborative board walkthrough","\u002Fdevelop\u002Fpipeline-apps\u002Fcollaborative-board","5.develop\u002F11.pipeline-apps\u002F2.collaborative-board",{"title":283,"path":284,"stem":285},"Release and security lifecycle","\u002Fdevelop\u002Fpipeline-apps\u002Frelease-lifecycle","5.develop\u002F11.pipeline-apps\u002F3.release-lifecycle",{"title":287,"path":288,"stem":289},"Build a vertical","\u002Fdevelop\u002Fbuild-a-vertical","5.develop\u002F5.build-a-vertical",{"title":291,"path":292,"stem":293},"Managed application artifacts","\u002Fdevelop\u002Fscaffold-a-narrow-app","5.develop\u002F7.scaffold-a-narrow-app",{"title":295,"path":296,"stem":297},"Import your data","\u002Fdevelop\u002Fimport-your-data","5.develop\u002F8.import-your-data",{"title":299,"icon":300,"redirect":301,"path":302,"stem":303,"children":304,"page":73},"Guides","i-lucide-layout-grid","\u002Fapplications\u002Fai-agents\u002Foverview","\u002Fapplications","7.applications",[305,309,329,341],{"title":306,"path":307,"stem":308},"Application maturity catalog","\u002Fapplications\u002Fcatalog","7.applications\u002F0.catalog",{"title":310,"visibility":251,"path":311,"stem":312,"children":313,"page":73},"AI Agents","\u002Fapplications\u002Fai-agents","7.applications\u002F1.ai-agents",[314,317,321,325],{"title":315,"path":301,"stem":316},"Coding agents","7.applications\u002F1.ai-agents\u002F01.overview",{"title":318,"path":319,"stem":320},"GitHub App automation","\u002Fapplications\u002Fai-agents\u002Fgithub-app-automation","7.applications\u002F1.ai-agents\u002F04.github-app-automation",{"title":322,"path":323,"stem":324},"agent-cli assistance","\u002Fapplications\u002Fai-agents\u002Fagent-cli-assistance","7.applications\u002F1.ai-agents\u002F05.agent-cli-assistance",{"title":326,"path":327,"stem":328},"Agent REST control","\u002Fapplications\u002Fai-agents\u002Frest-agent-control","7.applications\u002F1.ai-agents\u002F06.rest-agent-control",{"title":330,"visibility":251,"path":331,"stem":332,"children":333,"page":73},"Tickets","\u002Fapplications\u002Ftickets","7.applications\u002F2.tickets",[334,337],{"title":330,"path":335,"stem":336},"\u002Fapplications\u002Ftickets\u002Foverview","7.applications\u002F2.tickets\u002F01.overview",{"title":338,"path":339,"stem":340},"API walkthrough","\u002Fapplications\u002Ftickets\u002Fapi-walkthrough","7.applications\u002F2.tickets\u002F02.api-walkthrough",{"title":342,"icon":343,"visibility":251,"path":344,"stem":345,"children":346,"page":73},"Case studies","i-lucide-book-open-check","\u002Fapplications\u002Fcase-studies","7.applications\u002F6.case-studies",[347,351],{"title":348,"path":349,"stem":350},"Case study: owner-scoped tickets","\u002Fapplications\u002Fcase-studies\u002Ftickets","7.applications\u002F6.case-studies\u002F01.tickets",{"title":352,"path":353,"stem":354},"Case study: repository review and correction","\u002Fapplications\u002Fcase-studies\u002Frepository-review","7.applications\u002F6.case-studies\u002F02.repository-review",{"title":356,"icon":357,"redirect":358,"path":359,"stem":360,"children":361,"page":73},"Resources","i-lucide-library","\u002Fresources\u002Fglossary","\u002Fresources","9.resources",[362,365,369,373,377,380,384],{"title":363,"path":358,"stem":364},"Glossary","9.resources\u002F1.glossary",{"title":366,"path":367,"stem":368},"Terms of Service","\u002Fresources\u002Fterms","9.resources\u002F2.terms",{"title":370,"path":371,"stem":372},"Privacy Policy","\u002Fresources\u002Fprivacy","9.resources\u002F3.privacy",{"title":374,"path":375,"stem":376},"Acceptable Use Policy","\u002Fresources\u002Facceptable-use","9.resources\u002F4.acceptable-use",{"title":79,"path":378,"stem":379},"\u002Fresources\u002Ffaq","9.resources\u002F5.faq",{"title":381,"path":382,"stem":383},"Documentation feedback","\u002Fresources\u002Fdocs-feedback","9.resources\u002F6.docs-feedback",{"title":385,"path":386,"stem":387},"Refund and Cancellation Policy","\u002Fresources\u002Frefund-cancellation","9.resources\u002F7.refund-cancellation",{"id":389,"title":283,"access":251,"audience":390,"body":391,"description":1062,"extension":1063,"last_verified":1064,"links":1065,"maturity":1066,"meta":1067,"navigation":1068,"path":284,"seo":1069,"stem":285,"__hash__":1070},"docs\u002F5.develop\u002F11.pipeline-apps\u002F3.release-lifecycle.md","developer",{"type":392,"value":393,"toc":1045},"minimark",[394,398,402,407,498,501,505,512,522,544,558,562,579,582,585,619,622,626,708,713,727,731,744,747,754,758,761,764,768,771,777,780,784,787,807,810,814,817,820,824,827,909,912,916,919,922,933,936,947,950,954,957,974,977,981,984,1026,1029,1041],[395,396,397],"caution",{},"The developer-preview lifecycle implements strict local lowering, canonical\nhashing, publisher attestation verification, immutable registry storage,\nsigned verification receipts, tenant installation, capability consent,\nupgrade\u002Frollback diffs, revocation projection, verified remote loading,\nowner\u002Fgrantee sharing, and operator-reviewed public catalog entries. Public\nself-service publication remains planned.",[399,400,401],"p",{},"Portable applications add a software supply chain to the platform. A release\ncan contain executable transforms, pages, actions, dependencies, and requests\nfor data or device access. Reproducible hashes and explicit capability grants\ntherefore belong in the base contract rather than in catalog policy added later.",[403,404,406],"h2",{"id":405},"application-identities-and-roles","Application identities and roles",[408,409,410,426],"table",{},[411,412,413],"thead",{},[414,415,416,420,423],"tr",{},[417,418,419],"th",{},"Identity or artifact",[417,421,422],{},"Lifetime",[417,424,425],{},"Mutable state",[427,428,429,446,459,472,485],"tbody",{},[414,430,431,440,443],{},[432,433,434,435,439],"td",{},"Logical app (",[436,437,438],"code",{},"app_id",")",[432,441,442],{},"Long-lived product identity",[432,444,445],{},"Display and repository metadata live in authoring\u002Fcatalog records",[414,447,448,453,456],{},[432,449,450],{},[436,451,452],{},"PipelineAppManifest",[432,454,455],{},"Mutable authoring input",[432,457,458],{},"Readable unresolved members, configuration, and tags",[414,460,461,466,469],{},[432,462,463],{},[436,464,465],{},"AppRelease",[432,467,468],{},"Immutable artifact graph",[432,470,471],{},"None; a content change creates a new release hash",[414,473,474,479,482],{},[432,475,476],{},[436,477,478],{},"AppInstallation",[432,480,481],{},"One tenant's realization of a release",[432,483,484],{},"Current pin, accepted grants, local configuration, upgrade and rollback history",[414,486,487,492,495],{},[432,488,489],{},[436,490,491],{},"AppCatalogEntry",[432,493,494],{},"Public or tenant-private discovery record",[432,496,497],{},"Summary, latest-release pointer, categories, preview assets, and visibility policy",[399,499,500],{},"Keeping these roles separate allows several installations to pin different\nreleases while preserving one logical app and publisher lineage. Catalog\nvisibility grants neither installation authority nor dataset access.",[403,502,504],{"id":503},"current-pipeline-signing-boundary","Current pipeline signing boundary",[399,506,507,508,511],{},"A current ",[436,509,510],{},"PipelineSpec"," content hash is BLAKE3 over the canonical CBOR encoding\nof:",[513,514,520],"pre",{"className":515,"code":517,"language":518,"meta":519},[516],"language-text","nodes + output_node_ids + spec_name + cli\n","text","",[436,521,517],{"__ignoreMap":519},[399,523,524,525,528,529,532,533,536,537,540,541,543],{},"The author signature verifies that hash. The optional ",[436,526,527],{},"cli"," value contains the\npublished command name, aliases, and help text; changing that surface creates a\nnew content revision. ",[436,530,531],{},"version_tag",", description, tags, ",[436,534,535],{},"latest",", and timestamps\nare excluded. Changing those metadata fields does not create a new content\nrevision. The stable revision key is ",[436,538,539],{},"spec_name + spec_hash","; ",[436,542,535],{}," is a\nmutable registry pointer.",[399,545,546,547,550,551,554,555,557],{},"Function source and compiled artifacts have their own content hashes. When a\npipeline carries ",[436,548,549],{},"pin_ast_hash"," or ",[436,552,553],{},"pin_artifact_hash",", resolution must use that\nexact source or binary. A human ",[436,556,531],{}," remains useful for display and\nrelease notes, while the hash is the reproducibility boundary.",[403,559,561],{"id":560},"application-signing-contract","Application signing contract",[399,563,564,567,568,571,572,571,575,578],{},[436,565,566],{},"AppRelease.content_hash"," is computed over canonical package bytes with\n",[436,569,570],{},"content_hash",", ",[436,573,574],{},"author_hash",[436,576,577],{},"author_signature",", and the publisher identity\nfields in provenance cleared. It is a publisher-independent digest of the\npackage graph. A separate publisher attestation binds signer identity to that\ndigest. The local compiler implements canonicalization and deterministic\nhashing, then emits an unsigned candidate. Managed publication verifies the\npublisher attestation and referenced registry evidence before it stores the\nimmutable release.",[399,580,581],{},"The shared release validator separates structural validity from publication\nevidence. Local callers can supply the authored manifest whose hash is carried\nby the release and prove the normalized resolved graph still matches it. The\ncryptographic\u002Fregistry evidence fields are opaque and cannot be asserted by a\ncaller. The release-bound verifier strictly rejects unknown schema fields and\ntags, binds authored source bytes and their hash to the exact normalized\nmanifest and release digest, verifies the publisher attestation, and issues an\nopaque signed receipt. Local unsigned candidates remain inspectable and\nineligible until they pass that managed boundary.",[399,583,584],{},"The canonical release is intended to cover:",[586,587,588,592,595,598,601,604,607,610,613,616],"ul",{},[589,590,591],"li",{},"application identity and release format version;",[589,593,594],{},"exact schema descriptor references;",[589,596,597],{},"exact pipeline revisions;",[589,599,600],{},"exact transform and asset artifacts;",[589,602,603],{},"surface trees, bindings, actions, and navigation;",[589,605,606],{},"dataset declarations and migration policy;",[589,608,609],{},"capability requests;",[589,611,612],{},"exact dependency releases;",[589,614,615],{},"collaboration, offline, and compatibility policy;",[589,617,618],{},"provenance and fork parent.",[399,620,621],{},"The release signature authenticates that full graph. Each referenced artifact\nalso retains its own hash and signature, so an inspector can verify both the\npackage and its components.",[403,623,625],{"id":624},"lifecycle","Lifecycle",[513,627,631],{"className":628,"code":629,"language":630,"meta":519,"style":519},"language-mermaid shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","flowchart LR\n    Draft --> Validate\n    Validate --> Sign\n    Sign --> Publish\n    Publish --> Install\n    Install --> Run\n    Run --> Upgrade\n    Upgrade --> Run\n    Run --> Rollback\n    Rollback --> Run\n    Publish --> Fork\n    Publish --> Revoke\n","mermaid",[436,632,633,642,648,654,660,666,672,678,684,690,696,702],{"__ignoreMap":519},[634,635,638],"span",{"class":636,"line":637},"line",1,[634,639,641],{"class":640},"sTEyZ","flowchart LR\n",[634,643,645],{"class":636,"line":644},2,[634,646,647],{"class":640},"    Draft --> Validate\n",[634,649,651],{"class":636,"line":650},3,[634,652,653],{"class":640},"    Validate --> Sign\n",[634,655,657],{"class":636,"line":656},4,[634,658,659],{"class":640},"    Sign --> Publish\n",[634,661,663],{"class":636,"line":662},5,[634,664,665],{"class":640},"    Publish --> Install\n",[634,667,669],{"class":636,"line":668},6,[634,670,671],{"class":640},"    Install --> Run\n",[634,673,675],{"class":636,"line":674},7,[634,676,677],{"class":640},"    Run --> Upgrade\n",[634,679,681],{"class":636,"line":680},8,[634,682,683],{"class":640},"    Upgrade --> Run\n",[634,685,687],{"class":636,"line":686},9,[634,688,689],{"class":640},"    Run --> Rollback\n",[634,691,693],{"class":636,"line":692},10,[634,694,695],{"class":640},"    Rollback --> Run\n",[634,697,699],{"class":636,"line":698},11,[634,700,701],{"class":640},"    Publish --> Fork\n",[634,703,705],{"class":636,"line":704},12,[634,706,707],{"class":640},"    Publish --> Revoke\n",[709,710,712],"h3",{"id":711},"draft","Draft",[399,714,715,716,571,719,722,723,726],{},"The author works with readable schema, pipeline, surface, and release files.\nReferences may use local paths or qualified names. ",[436,717,718],{},"rac app validate",[436,720,721],{},"build",",\nand ",[436,724,725],{},"inspect"," exercise the local draft lifecycle. Drafts cannot be installed\noutside their development workspace.",[709,728,730],{"id":729},"validate","Validate",[399,732,733,734,736,737,740,741,743],{},"Local validation rejects unknown TOML fields, malformed pipeline graphs,\nincompatible entity merge policies, unsupported v1 surface\u002Faction shapes,\ndangling references, undeclared effect capabilities, direct self-dependencies,\nand incompatible resolved dependency versions. Building\nalso resolves referenced pipeline sources to exact ",[436,735,510],{}," hashes.\nResolved dataset sources and sinks must be covered by matching read\u002Fwrite\ncapabilities. An ",[436,738,739],{},"http_fetch"," stage requires a matching network capability, and\nan authenticated fetch also requires a secret capability matching the referenced\nsecret name. The same resolution check runs in ",[436,742,718],{},".\nPublication validation additionally rejects unknown schema fields and tags;\nbinds authored source bytes to the exact normalized manifest, resolved package\ngraph, and release digest; and verifies the transitive dependency graph,\ndescriptor and artifact registry evidence, runtime compatibility, route\nownership, publisher keys, and migrations through a release-bound receipt.",[399,745,746],{},"A local scaffold report may omit checks that need a registry. A publishable\nverdict is separate and fail-closed: a skipped required gate produces an\nincomplete release rather than a publishable one.",[399,748,749,750,753],{},"Runtime v1 also validates parameterized pipeline actions as a signed,\nfour-field filter binding: input key, destination column, comparison operator,\nand scalar kind. Partial bindings are invalid. ",[436,751,752],{},"invoke_function"," actions are\nrejected at publication until the client host has an authenticated invocation\ntransport and an ABI-compatible input\u002Foutput encoder.",[709,755,757],{"id":756},"sign-and-publish","Sign and publish",[399,759,760],{},"The publisher attests to the publisher-independent package digest, binding its\nsigner identity to those exact contents. Publication stores immutable release\nmetadata, the attestation, content references, and the verifier's signed\nreceipt in the managed registry. An owner can create a private catalog\nprojection for trusted account or tenant grantees, or submit the exact current\nrelease for public review. Public discovery requires an operator approval\nrecorded in the append-only app catalog review log.",[399,762,763],{},"Native function references are resolved against the dedicated DTS code\nregistry. Pipeline execution and future runtime materialization require the\nexact function name, source-AST hash, artifact hash, ABI, symbol, target, and verification\nevidence. The registry keeps the function-to-artifact association append-only,\nso rebuilding the same AST cannot make an older signed release unresolvable.",[709,765,767],{"id":766},"install","Install",[399,769,770],{},"Installation validates the release and dependency closure, records accepted\ngrants, registers its verified entity descriptors, and pins the exact release\nfor a tenant. The registry signs the complete mutable installation projection,\nincluding its state, grants, projected revocation metadata, and monotonically\nincreasing revision. Remote clients verify that attestation and the immutable\npublication receipt before persisting or activating the bundle. Discovery\npermission and installation permission are distinct.",[399,772,773,774,776],{},"The Apps UI lists owner, grantee, and approved-public catalog scopes. A private\nshare grants read\u002Fdiscovery permission over the stable ",[436,775,438],{},"; it does not\ncopy the publisher's installation or widen access to the publisher's datasets.\nInstallation into the active workspace still requires tenant owner\u002Fadmin\nauthority and explicit acceptance of every required capability. Trusted\ncontacts become eligible share targets only after their email matches an\nactive, authenticated workspace member.",[399,778,779],{},"The attestation issuance time is a second monotonic replay barrier within a\nsingle installation revision. The registry allocates it from persisted state\nwhile locking the installation, root release, and sorted transitive dependency\nclosure. Clients reject older issuance times, require an equal issuance time to\ncarry the same bundle hash, and retain a verified root revocation or\ndependency-driven suspension as terminal for that sequence and release.",[709,781,783],{"id":782},"upgrade-and-rollback","Upgrade and rollback",[399,785,786],{},"An upgrade diff groups changes by:",[586,788,789,792,795,798,801,804],{},[589,790,791],{},"schemas and migrations;",[589,793,794],{},"pipeline and transform revisions;",[589,796,797],{},"pages, bindings, and actions;",[589,799,800],{},"dependencies and assets;",[589,802,803],{},"newly requested or broadened capabilities;",[589,805,806],{},"compatibility with stored data and the client runtime.",[399,808,809],{},"The installation pin moves only after validation and approval. Rollback points\nto a previously accepted compatible release. Append-only data and operation\nhistory remain intact.",[709,811,813],{"id":812},"fork-and-revoke","Fork and revoke",[399,815,816],{},"A fork receives a new project and publisher identity with provenance pointing\nto the source release. Data is copied or granted through a separate explicit\noperation.",[399,818,819],{},"Revocation blocks new installation and dependency resolution. Existing\ninstallations follow policy: warn, quarantine, disable, or roll back to a known\nrelease. The decision and reason remain auditable.",[403,821,823],{"id":822},"capabilities","Capabilities",[399,825,826],{},"Capabilities are names and scoped parameters, never embedded credentials.",[408,828,829,841],{},[411,830,831],{},[414,832,833,836,838],{},[417,834,835],{},"Class",[417,837,83],{},[417,839,840],{},"Enforcement point",[427,842,843,854,865,876,887,898],{},[414,844,845,848,851],{},[432,846,847],{},"Dataset",[432,849,850],{},"Read\u002Fwrite a named app dataset",[432,852,853],{},"Engine authorization and installation grants",[414,855,856,859,862],{},[432,857,858],{},"Network",[432,860,861],{},"Connect to an allowlisted service or domain",[432,863,864],{},"Server egress or client host policy",[414,866,867,870,873],{},[432,868,869],{},"Secret",[432,871,872],{},"Resolve a named server-side secret",[432,874,875],{},"Server secret resolver; values never enter the release",[414,877,878,881,884],{},[432,879,880],{},"Device",[432,882,883],{},"Camera, microphone, notifications, location, files",[432,885,886],{},"Browser\u002FCapacitor host plus OS permission",[414,888,889,892,895],{},[432,890,891],{},"Background",[432,893,894],{},"Schedule, push subscription, background sync",[432,896,897],{},"Server scheduler or native host",[414,899,900,903,906],{},[432,901,902],{},"Cross-app",[432,904,905],{},"Invoke or read an explicitly exported contract",[432,907,908],{},"Installation dependency and grant closure",[399,910,911],{},"Dependencies contribute their own capability requirements. Installation shows\nthe transitive closure and records which release requested each grant. An\nupgrade that broadens that closure requires renewed approval.",[403,913,915],{"id":914},"server-and-client-execution-boundaries","Server and client execution boundaries",[399,917,918],{},"The server remains authoritative for identity, authorization, secrets,\nprivileged network access, large dataset scans, and durable writes.\nDeterministic client expressions may run over rows already available to the\ninstalled application. Optimistic client operations become authoritative only\nafter server acceptance.",[399,920,921],{},"WASM has three separate maturity boundaries:",[586,923,924,927,930],{},[589,925,926],{},"A feature-gated server request-handler host is implemented with local unary,\nstreaming, and WebSocket fixtures. Production routing does not currently\nselect it.",[589,928,929],{},"The deployed dataflow executor provides a default-on, capability-limited\nWasmtime UDF tier with fuel, memory, and wall-time bounds and no WASI. Its\nother callable tiers are built-in operations, trusted native batch\ntransforms, and Firecracker isolation for opted-in untrusted native\u002FPython\nworkloads. The backend is implemented; the first WASM route remains staged\nfor publication.",[589,931,932],{},"The portable Rust\u002FWASM runtime verifies strict installed bundles, binds\ndurable canonical-CBOR state to the installation\u002Ftenant\u002Fuser\u002Fsite identity,\nqueues and replays CBOR entity operations through Capacitor Preferences,\npreserves state across a verified release rebind, hydrates exact entities in\nbatches, and sends causal metadata to the descriptor-bound server merge path.\nCustom client transforms and arbitrary descriptor-generated subscriptions\nremain planned.",[399,934,935],{},"The authenticated service response supplies the registry verifier key. The\nruntime pins that key with the durable bundle and refuses replacement or\nsequence rollback. Offline use therefore inherits the trust of the previous\nauthenticated exchange. Persisting the key beside the bundle cannot defend\nagainst an attacker who can replace the complete local storage record; a native\nhardware-backed trust anchor would be a separate host integration.",[399,937,938,939,942,943,946],{},"Registry signing-key rotation retains receipt continuity. Atomically replace\nthe existing ",[436,940,941],{},"DATA_ENGINE_SIGNING_KEY_FILE"," contents with one 64-hex seed per\nline: the new current seed first, followed by every retained prior seed. The\noptional ",[436,944,945],{},"DATA_ENGINE_SIGNING_KEYRING_FILE"," can hold additional retired seeds.\nKeep an old seed available while any installed release receipt names its public\nkey; installation refresh and lifecycle updates fail closed when that exact key\nis unavailable.",[399,948,949],{},"These paths may share artifact and ABI primitives. Their deployment status and\ncapability sets remain explicit.",[403,951,953],{"id":952},"data-sharing","Data sharing",[399,955,956],{},"Application sharing and dataset sharing solve different problems:",[586,958,959,962,965,968,971],{},[589,960,961],{},"catalog visibility lets a principal discover release metadata;",[589,963,964],{},"installation permission lets a workspace pin and run a release;",[589,966,967],{},"dataset grants let principals read selected application data;",[589,969,970],{},"write authority remains a separate scoped grant and server policy;",[589,972,973],{},"public data visibility does not imply public application publication, and a\npublic application does not imply public user data.",[399,975,976],{},"The existing append-only dataset-share record, grant id, catalog review verdict,\nand soft revocation provide the starting primitives for shared app data.\nApplication discovery and installation grants are implemented separately from\ndataset access, so sharing an app never grants its data implicitly.",[403,978,980],{"id":979},"publication-gates","Publication gates",[399,982,983],{},"A release is eligible for managed publication only when:",[985,986,987,990,993,996,999,1002,1005,1008,1011,1014,1017,1020,1023],"ol",{},[589,988,989],{},"its wire bytes contain no unknown schema fields or tags and reproduce the\nclaimed package digest;",[589,991,992],{},"its authored source bytes or source hash bind to the exact normalized\nmanifest and resolved release graph;",[589,994,995],{},"every artifact is available under its declared hash;",[589,997,998],{},"every pipeline parses, lowers, and resolves exactly;",[589,1000,1001],{},"every schema reference and binding type-checks;",[589,1003,1004],{},"every requested capability is declared and reviewable;",[589,1006,1007],{},"dependencies are exact, acyclic, and compatible;",[589,1009,1010],{},"migrations are additive or carry an approved explicit procedure;",[589,1012,1013],{},"the golden application conformance suite passes for the affected contract;",[589,1015,1016],{},"the release has a supported client\u002Fruntime compatibility range;",[589,1018,1019],{},"the catalog audience and revocation policy are set;",[589,1021,1022],{},"the publisher attestation verifies against the package digest and signer\nidentity;",[589,1024,1025],{},"the verifier returns the opaque receipt bound to all of this evidence.",[399,1027,1028],{},"A local unsigned build cannot produce that receipt by itself. The managed\npublication path issues it after the registry-backed checks pass; public\nself-service publication remains future work.",[399,1030,1031,1032,1036,1037,1040],{},"The first public proof is the\n",[1033,1034,1035],"a",{"href":280},"collaborative board",". Return to the\n",[1033,1038,1039],{"href":262},"Pipeline Apps mental model"," for the artifact\noverview.",[1042,1043,1044],"style",{},"html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":519,"searchDepth":644,"depth":644,"links":1046},[1047,1048,1049,1050,1058,1059,1060,1061],{"id":405,"depth":644,"text":406},{"id":503,"depth":644,"text":504},{"id":560,"depth":644,"text":561},{"id":624,"depth":644,"text":625,"children":1051},[1052,1053,1054,1055,1056,1057],{"id":711,"depth":650,"text":712},{"id":729,"depth":650,"text":730},{"id":756,"depth":650,"text":757},{"id":766,"depth":650,"text":767},{"id":782,"depth":650,"text":783},{"id":812,"depth":650,"text":813},{"id":822,"depth":644,"text":823},{"id":914,"depth":644,"text":915},{"id":952,"depth":644,"text":953},{"id":979,"depth":644,"text":980},"How portable pipeline apps are hashed, signed, validated, installed, permissioned, upgraded, shared, forked, and revoked.","md","2026-08-14",null,"preview",{"toc":1068,"visibility":251},true,{"title":283,"description":1062},"r54OKJltPePYjWcD5cd_PJWcyplUDy3EQNLU8trriJM",[1072,1074],{"title":279,"path":280,"stem":281,"description":1073,"children":-1},"A developer-preview portable pipeline app spanning release distribution, rendering, durable replay, and causal entity merge.",{"title":287,"path":288,"stem":289,"description":1075,"children":-1},"How to build an application vertical on the platform, in order — Rust schema, ingestion, transforms, service surface, UI, then deployment.",1789873213247]