Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 7 additions & 13 deletions .github/workflows/creator-kit-candidate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,18 +28,12 @@ jobs:
fetch-depth: 0
persist-credentials: false
- uses: oven-sh/setup-bun@v2
- name: Resolve the committed source lock
id: source
- run: bun run creator-kit:check
- name: Build the deterministic archive twice
run: |
set -euo pipefail
source_commit="$(jq -r .commit creator-kit/source-lock.json)"
[[ "$source_commit" =~ ^[a-f0-9]{40}$ ]]
git merge-base --is-ancestor "$source_commit" "$GITHUB_SHA"
echo "source_commit=$source_commit" >> "$GITHUB_OUTPUT"
- name: Rebuild the exact committed candidate
env:
SOURCE_COMMIT: ${{ steps.source.outputs.source_commit }}
run: bun run creator-kit:build -- --source-commit "$SOURCE_COMMIT"
- name: Verify committed candidate matches the generator
run: git diff --exit-code -- creator-kit
- run: bun run creator-kit:check
node scripts/creator-kit/build-release-candidate.mjs --release-dir .creator-kit-tmp/first --source-commit "$GITHUB_SHA"
node scripts/creator-kit/build-release-candidate.mjs --release-dir .creator-kit-tmp/second --source-commit "$GITHUB_SHA"
cmp .creator-kit-tmp/first/spectoda-creator-kit-0.1.0-rc.3.tar .creator-kit-tmp/second/spectoda-creator-kit-0.1.0-rc.3.tar
cmp .creator-kit-tmp/first/provenance.json .creator-kit-tmp/second/provenance.json
git diff --exit-code -- creator-kit
59 changes: 0 additions & 59 deletions .github/workflows/creator-kit-generated-pr.yml

This file was deleted.

52 changes: 17 additions & 35 deletions .github/workflows/creator-kit-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,51 +47,33 @@ jobs:
CREATOR_KIT_VERSION: ${{ inputs.version }}
run: |
set -euo pipefail
node --input-type=module -e 'const version = process.env.CREATOR_KIT_VERSION ?? ""; if (!/^[0-9]+[.][0-9]+[.][0-9]+(-[0-9A-Za-z.-]+)?$/.test(version)) process.exit(1);'
- name: Resolve the committed source lock
id: source
run: |
set -euo pipefail
source_commit="$(jq -r .commit creator-kit/source-lock.json)"
[[ "$source_commit" =~ ^[a-f0-9]{40}$ ]]
git merge-base --is-ancestor "$source_commit" "$GITHUB_SHA"
echo "source_commit=$source_commit" >> "$GITHUB_OUTPUT"
- name: Build the exact candidate
env:
CREATOR_KIT_VERSION: ${{ inputs.version }}
SOURCE_COMMIT: ${{ steps.source.outputs.source_commit }}
run: bun run creator-kit:build -- --version "$CREATOR_KIT_VERSION" --source-commit "$SOURCE_COMMIT"
- name: Verify committed candidate matches the reviewed generator
run: git diff --exit-code -- creator-kit
test "$CREATOR_KIT_VERSION" = "0.1.0-rc.3"
test "$(jq -r .version creator-kit/bundle.json)" = "$CREATOR_KIT_VERSION"
- run: bun run creator-kit:check
- name: Require an explicit publishable license posture
- name: Require the approved prerelease license and channel posture
run: |
set -euo pipefail
jq -e '.publicationAllowed == true' creator-kit/licenses.json
jq -e '.publicationAllowed == true and .realDocumentationExportAllowed == true and .entries == ["CC-BY-4.0", "MIT"]' creator-kit/licenses.json
jq -e '.state == "unpublished" and .version == null and .digest == null and .releaseUrl == null' creator-kit/stable-channel.json
- name: Create release assets locally
env:
CREATOR_KIT_VERSION: ${{ inputs.version }}
SOURCE_COMMIT: ${{ steps.source.outputs.source_commit }}
run: node scripts/creator-kit/build-release-candidate.mjs --output creator-kit --release-dir .creator-kit-tmp/release --version "$CREATOR_KIT_VERSION" --source-commit "$SOURCE_COMMIT"
SOURCE_COMMIT: ${{ inputs.source_sha }}
run: node scripts/creator-kit/build-release-candidate.mjs --bundle creator-kit --release-dir .creator-kit-tmp/release --version "$CREATOR_KIT_VERSION" --source-commit "$SOURCE_COMMIT"
- name: Verify release asset build preserved the reviewed candidate
run: git diff --exit-code -- creator-kit
- name: Create the approved stable-channel descriptor locally
env:
CREATOR_KIT_VERSION: ${{ inputs.version }}
run: |
set -euo pipefail
digest="$(jq -r .bundleDigest .creator-kit-tmp/release/provenance.json)"
node scripts/creator-kit/promote-stable-channel.mjs \
--bundle creator-kit \
--version "$CREATOR_KIT_VERSION" \
--digest "$digest" \
--release-url "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/Spectoda/examples/releases/tag/creator-kit-v${CREATOR_KIT_VERSION}" \
--output .creator-kit-tmp/release/stable-channel.json \
--confirm PUBLISH_CREATOR_KIT_RELEASE
- name: Publish the explicitly approved GitHub Release
- name: Publish the explicitly approved GitHub prerelease
env:
GH_TOKEN: ${{ github.token }}
CREATOR_KIT_VERSION: ${{ inputs.version }}
run: |
set -euo pipefail
gh release create "creator-kit-v${CREATOR_KIT_VERSION}" .creator-kit-tmp/release/* --title "Spectoda Creator Kit ${CREATOR_KIT_VERSION}" --generate-notes
if gh release view "creator-kit-v${CREATOR_KIT_VERSION}" >/dev/null 2>&1; then
echo "Release creator-kit-v${CREATOR_KIT_VERSION} already exists" >&2
exit 1
fi
gh release create "creator-kit-v${CREATOR_KIT_VERSION}" .creator-kit-tmp/release/* \
--target "$GITHUB_SHA" \
--title "Spectoda Creator Kit ${CREATOR_KIT_VERSION}" \
--notes-file creator-kit/RELEASE_NOTES.md \
--prerelease
27 changes: 14 additions & 13 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,19 +33,20 @@ scriptů, projektových patternů a integračních snippetů.

## Creator Kit boundary

- `creator-kit/` is a generated, read-only distribution candidate, not an
authoring surface.
- The candidate is synthetic-fixture-only until Documentation records an
authorized redistribution license. Never copy private Documentation bodies,
customer context or partner-local knowledge here.
- Keep exact-version pins, the fixed synthetic fixture lock in source
frontmatter, the generated source-lock commit equal to the exact reviewed
Git head, checksums, license posture and the
`unpublished` stable-channel descriptor intact. Updates require partner
approval and a normal review PR.
- The candidate workflows may validate or prepare a release, but agents must
not trigger a generated public-content PR, GitHub Release or partner
Organization mutation without fresh explicit instruction.
- `creator-kit/` is a generated, read-only public snapshot, not an authoring
surface. Documentation remains authoritative; the public copy is immutable
and flows in one direction only.
- The reviewed `0.1.0-rc.3` snapshot contains seven CC BY 4.0 Documentation
derivatives, the complete hash-locked FW 0.12.11 config contract/schema and
one MIT-licensed Event Player example. Spectoda names, logos and trademarks
are outside those license grants.
- Keep exact source commits, the Documentation bundle digest, firmware
provenance, example hashes, checksums and the `unpublished` stable-channel
descriptor intact. Updates require partner approval and a normal review PR.
- Public CI validates the committed snapshot and deterministically packages it;
it does not require access to private Documentation. Agents must not trigger
another GitHub Release or partner Organization mutation without fresh
explicit instruction.
- Do not add a generic Lazurio installer to this repository; hand that contract
to HumanAndMachines/Lazurio through its own governed planning flow.

Expand Down
27 changes: 14 additions & 13 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,19 +57,20 @@ replacement.

## Creator Kit release boundary

`creator-kit/` is a generated, reviewable read-only distribution artifact. Its
source fixture and builder are intentionally synthetic-only until the
Documentation owner records a redistribution license. The private
`documentation` module remains the authority for Markdown/MDX and the
`agentExport` selection contract.

The candidate includes a versioned bundle schema, manifest, source lock,
license posture, compatibility contract, indexes, checksums and an
`unpublished` stable-channel descriptor. `scripts/creator-kit/validate.mjs`
checks public safety, links, hashes, size and the human-release gate. The
release candidate script produces a deterministic tar and provenance file but
does not publish a release, transfer public content or mutate a partner
Organization.
`creator-kit/` is a generated, reviewable read-only public snapshot. The
private `documentation` module remains authoritative for Markdown/MDX and the
`agentExport` selection contract. A licensed export crosses into this public
repository only as an immutable, checksum-locked, one-way derivative; Examples
does not become an authoring backchannel for Documentation.

The `0.1.0-rc.3` snapshot includes seven CC BY 4.0 documents, two hash-locked
FW 0.12.11 config assets and one MIT example. It carries the exact
Documentation snapshot digest, Documentation/Firmware/Examples source commits,
license posture, compatibility contract, indexes and checksums.
`scripts/creator-kit/validate.mjs` checks public safety, links, hashes,
provenance, size and the unpublished stable boundary. Public CI packages the
already committed snapshot into a deterministic tar; only the protected
workflow may publish that tar as a GitHub prerelease.

The only v1 transport contract is GitHub Releases plus the stable descriptor.
No embeddings, hosted dynamic RAG, central MCP gateway, writable
Expand Down
15 changes: 15 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,21 @@

Date-based versions use `YYYYMMDD`.

## 20260809

### Added

- Published the immutable Creator Kit `0.1.0-rc.3` source snapshot with seven
CC BY 4.0 Controller Config/Creator Kit documents, the complete FW 0.12.11
config contract plus JSON Schema, and one MIT Event Player example.

### Changed

- Release automation now publishes an explicit GitHub prerelease while the
stable-channel descriptor remains unpublished.
- Public CI verifies Documentation, Firmware and Examples provenance plus all
bundle/archive checksums without requiring access to private Documentation.

## 20260808

### Changed
Expand Down
31 changes: 16 additions & 15 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -55,20 +55,19 @@ Each example should include:
Do not commit secrets, client credentials, private network keys, or
customer-specific data that is not meant to be public.

## Spectoda Creator Kit candidate
## Spectoda Creator Kit public prerelease

`creator-kit/` is the reviewed distribution surface for the English Spectoda
Creator Kit. The current tree is a synthetic-fixture-only release candidate;
real Documentation bodies are not transferred until an authorized
redistribution license is recorded. Documentation remains the private
authoring source of truth.
`creator-kit/` is the immutable source snapshot for the public English
Spectoda Creator Kit `0.1.0-rc.3` prerelease. It contains the complete selected
FW 0.12.11 Controller Config documentation and machine-readable config
contract/schema under CC BY 4.0, plus one MIT-licensed Event Player example.
Documentation remains the private authoring source of truth; this repository
holds only the reviewed one-way public derivative.

The candidate is read-only and uses exact-version pins, a fixed synthetic
fixture lock in frontmatter plus a generated source-lock commit equal to the
exact Examples Git head, manifests,
indexes, checksums, a stable-channel descriptor and a protected human release
gate. Partner-local knowledge must live outside the bundle. Native Lazurio
installation is intentionally not implemented here.
The prerelease is read-only and uses exact source commits, firmware provenance,
manifests, indexes, checksums and a protected release gate. The stable-channel
descriptor remains `unpublished`; partner-local knowledge stays outside the
bundle. Native Lazurio installation is intentionally not implemented here.

Run the local gates from the repository root:

Expand All @@ -77,6 +76,8 @@ bun run creator-kit:build
bun run creator-kit:check
```

`creator-kit:build` creates only a local release candidate archive under the
ignored `.creator-kit-tmp/`; it does not call GitHub Releases or publish a
generated PR.
`creator-kit:build` creates only a local deterministic archive under the
ignored `.creator-kit-tmp/`; it does not call GitHub Releases. The public
release is available at the matching
[`creator-kit-v0.1.0-rc.3`](https://github.com/Spectoda/examples/releases/tag/creator-kit-v0.1.0-rc.3)
prerelease after the protected publication workflow completes.
4 changes: 2 additions & 2 deletions TODO.tasks.json
Original file line number Diff line number Diff line change
Expand Up @@ -356,9 +356,9 @@
"agents"
],
"dev_code": "DEV-6455",
"summary": "Generate a synthetic-fixture-only English Creator Kit candidate with exact source locks, manifests, indexes, checksums, compatibility, stable-channel and provenance contracts. Keep release, generated PR, partner mutation and Lazurio installation behind explicit human gates.",
"summary": "Publish the approved Creator Kit 0.1.0-rc.3 prerelease with seven CC BY 4.0 Documentation derivatives, the complete FW 0.12.11 config contract/schema and one MIT example. Keep the stable channel unpublished and partner mutation or Lazurio installation outside this release.",
"risk_notes": [
"No real Documentation body may enter this public repo until the authorized redistribution license is recorded.",
"Only the exact licensed Documentation snapshot and allowlisted FW 0.12.11 assets may enter this public repository.",
"The stable channel is intentionally unpublished and native Lazurio distribution is a separate dependency.",
"Canonicalized from task-2026-08-07-6455-examples-candidate on 2026-08-09; no current Mission Control plan, workspace ledger or worktree reference remains."
],
Expand Down
6 changes: 3 additions & 3 deletions creator-kit-evaluations/questions.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,11 @@
}
},
{
"id": "bundle-scope",
"prompt": "What is the synthetic creator workflow fixture?",
"id": "controller-config-source",
"prompt": "Where can I find the complete FW 0.12.11 Controller Config keywords?",
"expected": {
"abstain": false,
"citation": "documents/en/synthetic-creator.md"
"citation": "documents/en/pro-vyrobce-a-tvurce/controller-config/fw-01211-keywords.md"
}
},
{
Expand Down
6 changes: 3 additions & 3 deletions creator-kit-evaluations/responses/claude.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,9 @@
"abstained": false
},
{
"id": "bundle-scope",
"answer": "The fixture is a small creator workflow with no private Network state.",
"citations": ["documents/en/synthetic-creator.md"],
"id": "controller-config-source",
"answer": "The complete FW 0.12.11 keyword reference is included in the pinned Controller Config documentation.",
"citations": ["documents/en/pro-vyrobce-a-tvurce/controller-config/fw-01211-keywords.md"],
"abstained": false
},
{
Expand Down
6 changes: 3 additions & 3 deletions creator-kit-evaluations/responses/codex.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,9 @@
"abstained": false
},
{
"id": "bundle-scope",
"answer": "The bundle describes a small public-safe creator workflow.",
"citations": ["documents/en/synthetic-creator.md"],
"id": "controller-config-source",
"answer": "Use the pinned FW 0.12.11 keyword reference and the machine-readable contract bundled with it.",
"citations": ["documents/en/pro-vyrobce-a-tvurce/controller-config/fw-01211-keywords.md"],
"abstained": false
},
{
Expand Down
Loading
Loading