Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
45 changes: 45 additions & 0 deletions .github/workflows/creator-kit-candidate.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
name: Creator Kit candidate

on:
pull_request:
paths:
- "creator-kit-fixtures/**"
- "creator-kit-negative-fixtures/**"
- "creator-kit-templates/**"
- "scripts/creator-kit/**"
- "creator-kit/**"
- "data/v2/examples/player-show-complete-cue-tracks/**"
- "package.json"
- ".github/workflows/creator-kit-*.yml"

permissions:
contents: read

concurrency:
group: creator-kit-candidate-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
validate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
persist-credentials: false
- uses: oven-sh/setup-bun@v2
- name: Resolve the committed source lock
id: source
run: |
set -euo pipefail
source_commit="$(jq -r .commit creator-kit/source-lock.json)"
[[ "$source_commit" =~ ^[a-f0-9]{40}$ ]]
git merge-base --is-ancestor "$source_commit" "$GITHUB_SHA"
echo "source_commit=$source_commit" >> "$GITHUB_OUTPUT"
- name: Rebuild the exact committed candidate
env:
SOURCE_COMMIT: ${{ steps.source.outputs.source_commit }}
run: bun run creator-kit:build -- --source-commit "$SOURCE_COMMIT"
- name: Verify committed candidate matches the generator
run: git diff --exit-code -- creator-kit
- run: bun run creator-kit:check
59 changes: 59 additions & 0 deletions .github/workflows/creator-kit-generated-pr.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
name: Creator Kit generated review PR

on:
workflow_dispatch:
inputs:
confirmation:
description: "Type GENERATE_CREATOR_KIT_REVIEW_PR to create a normal review PR"
required: true
type: string
source_sha:
description: "Exact Examples commit to regenerate from"
required: true
type: string

permissions:
contents: read

jobs:
generate:
if: ${{ inputs.confirmation == 'GENERATE_CREATOR_KIT_REVIEW_PR' && inputs.source_sha == github.sha }}
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.sha }}
fetch-depth: 0
persist-credentials: false
- uses: oven-sh/setup-bun@v2
- name: Verify exact source head
env:
SOURCE_SHA: ${{ inputs.source_sha }}
run: |
set -euo pipefail
[[ "$SOURCE_SHA" =~ ^[a-f0-9]{40}$ ]]
test "$SOURCE_SHA" = "$GITHUB_SHA"
test "$(git rev-parse HEAD)" = "$SOURCE_SHA"
- name: Build from the exact source head
env:
SOURCE_SHA: ${{ inputs.source_sha }}
run: bun run creator-kit:build -- --source-commit "$SOURCE_SHA"
- run: bun run creator-kit:check
- name: Open normal generated review PR
env:
GH_TOKEN: ${{ github.token }}
SOURCE_SHA: ${{ inputs.source_sha }}
run: |
set -euo pipefail
branch="automation/creator-kit-${{ github.run_id }}"
git switch -c "$branch"
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add creator-kit
git commit -m "chore: regenerate Creator Kit candidate"
git remote set-url origin "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git"
git push --set-upstream origin "$branch"
gh pr create --title "chore: regenerate Creator Kit candidate" --body "Generated from exact source head ${SOURCE_SHA}. Human review is required; this workflow does not publish a Release." --base main --head "$branch"
97 changes: 97 additions & 0 deletions .github/workflows/creator-kit-release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,97 @@
name: Creator Kit release

on:
workflow_dispatch:
inputs:
confirmation:
description: "Type PUBLISH_CREATOR_KIT_RELEASE after human review and license approval"
required: true
type: string
version:
description: "Exact semver release version"
required: true
type: string
source_sha:
description: "Exact reviewed Examples commit"
required: true
type: string

permissions:
contents: read

jobs:
release:
if: ${{ inputs.confirmation == 'PUBLISH_CREATOR_KIT_RELEASE' && inputs.source_sha == github.sha && github.ref == 'refs/heads/main' }}
runs-on: ubuntu-latest
environment:
name: creator-kit-release
permissions:
contents: write
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.sha }}
fetch-depth: 0
persist-credentials: false
- uses: oven-sh/setup-bun@v2
- name: Verify reviewed exact head
env:
SOURCE_SHA: ${{ inputs.source_sha }}
run: |
set -euo pipefail
[[ "$SOURCE_SHA" =~ ^[a-f0-9]{40}$ ]]
test "$SOURCE_SHA" = "$GITHUB_SHA"
test "$(git rev-parse HEAD)" = "$SOURCE_SHA"
- name: Validate release inputs
env:
CREATOR_KIT_VERSION: ${{ inputs.version }}
run: |
set -euo pipefail
node --input-type=module -e 'const version = process.env.CREATOR_KIT_VERSION ?? ""; if (!/^[0-9]+[.][0-9]+[.][0-9]+(-[0-9A-Za-z.-]+)?$/.test(version)) process.exit(1);'
- name: Resolve the committed source lock
id: source
run: |
set -euo pipefail
source_commit="$(jq -r .commit creator-kit/source-lock.json)"
[[ "$source_commit" =~ ^[a-f0-9]{40}$ ]]
git merge-base --is-ancestor "$source_commit" "$GITHUB_SHA"
echo "source_commit=$source_commit" >> "$GITHUB_OUTPUT"
- name: Build the exact candidate
env:
CREATOR_KIT_VERSION: ${{ inputs.version }}
SOURCE_COMMIT: ${{ steps.source.outputs.source_commit }}
run: bun run creator-kit:build -- --version "$CREATOR_KIT_VERSION" --source-commit "$SOURCE_COMMIT"
- name: Verify committed candidate matches the reviewed generator
run: git diff --exit-code -- creator-kit
- run: bun run creator-kit:check
- name: Require an explicit publishable license posture
run: |
set -euo pipefail
jq -e '.publicationAllowed == true' creator-kit/licenses.json
- name: Create release assets locally
env:
CREATOR_KIT_VERSION: ${{ inputs.version }}
SOURCE_COMMIT: ${{ steps.source.outputs.source_commit }}
run: node scripts/creator-kit/build-release-candidate.mjs --output creator-kit --release-dir .creator-kit-tmp/release --version "$CREATOR_KIT_VERSION" --source-commit "$SOURCE_COMMIT"
- name: Verify release asset build preserved the reviewed candidate
run: git diff --exit-code -- creator-kit
- name: Create the approved stable-channel descriptor locally
env:
CREATOR_KIT_VERSION: ${{ inputs.version }}
run: |
set -euo pipefail
digest="$(jq -r .bundleDigest .creator-kit-tmp/release/provenance.json)"
node scripts/creator-kit/promote-stable-channel.mjs \
--bundle creator-kit \
--version "$CREATOR_KIT_VERSION" \
--digest "$digest" \
--release-url "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/Spectoda/examples/releases/tag/creator-kit-v${CREATOR_KIT_VERSION}" \
--output .creator-kit-tmp/release/stable-channel.json \
--confirm PUBLISH_CREATOR_KIT_RELEASE
- name: Publish the explicitly approved GitHub Release
env:
GH_TOKEN: ${{ github.token }}
CREATOR_KIT_VERSION: ${{ inputs.version }}
run: |
set -euo pipefail
gh release create "creator-kit-v${CREATOR_KIT_VERSION}" .creator-kit-tmp/release/* --title "Spectoda Creator Kit ${CREATOR_KIT_VERSION}" --generate-notes
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1 +1,2 @@
.DS_Store
.creator-kit-tmp/
18 changes: 18 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,24 @@ scriptů, projektových patternů a integračních snippetů.
gotchas. Například analog 0-3.3 V na ESP32 se čte přes `type: "ADC"`, ne přes
zatím neimplementované `GPI` + `variant: "ANALOG"`.

## Creator Kit boundary

- `creator-kit/` is a generated, read-only distribution candidate, not an
authoring surface.
- The candidate is synthetic-fixture-only until Documentation records an
authorized redistribution license. Never copy private Documentation bodies,
customer context or partner-local knowledge here.
- Keep exact-version pins, the fixed synthetic fixture lock in source
frontmatter, the generated source-lock commit equal to the exact reviewed
Git head, checksums, license posture and the
`unpublished` stable-channel descriptor intact. Updates require partner
approval and a normal review PR.
- The candidate workflows may validate or prepare a release, but agents must
not trigger a generated public-content PR, GitHub Release or partner
Organization mutation without fresh explicit instruction.
- Do not add a generic Lazurio installer to this repository; hand that contract
to HumanAndMachines/Lazurio through its own governed planning flow.

## Hranice

- `modules/examples/` není source of truth pro zákaznickou dokumentaci. Hotové
Expand Down
19 changes: 19 additions & 0 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -55,3 +55,22 @@ runtime fetch, no Firebase) and renders a browsable, copyable catalog.
This repository can reference those sources, but should not become their
replacement.

## Creator Kit release boundary

`creator-kit/` is a generated, reviewable read-only distribution artifact. Its
source fixture and builder are intentionally synthetic-only until the
Documentation owner records a redistribution license. The private
`documentation` module remains the authority for Markdown/MDX and the
`agentExport` selection contract.

The candidate includes a versioned bundle schema, manifest, source lock,
license posture, compatibility contract, indexes, checksums and an
`unpublished` stable-channel descriptor. `scripts/creator-kit/validate.mjs`
checks public safety, links, hashes, size and the human-release gate. The
release candidate script produces a deterministic tar and provenance file but
does not publish a release, transfer public content or mutate a partner
Organization.

The only v1 transport contract is GitHub Releases plus the stable descriptor.
No embeddings, hosted dynamic RAG, central MCP gateway, writable
Documentation API or generic Lazurio installer belongs in this module.
19 changes: 19 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,25 @@ Date-based versions use `YYYYMMDD`.
NetworkStorage propagation, rewind and play. There is no generation or hot
update protocol in v1.

## 20260807

### Added

- Added a reviewable English Spectoda Creator Kit candidate with a fail-closed
synthetic-only build, manifest, source lock, checksums, compatibility,
indexes, stable-channel contract and in-bundle README/AGENTS.md.
- Added deterministic release assets/provenance, public-safety/link/secret/
license/size gates, negative behavior tests and Codex/Claude-shaped
agent-objective harness. Release and generated public-content workflows are
protected and were not triggered.

### Verification

- `bun run creator-kit:check`
- `bun run creator-kit:build`
- Candidate CI fetches full history before checking the committed source lock,
so ancestry validation remains fail-closed on a fresh GitHub Actions checkout.

## 20260702

### Added
Expand Down
26 changes: 26 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -54,3 +54,29 @@ Each example should include:

Do not commit secrets, client credentials, private network keys, or
customer-specific data that is not meant to be public.

## Spectoda Creator Kit candidate

`creator-kit/` is the reviewed distribution surface for the English Spectoda
Creator Kit. The current tree is a synthetic-fixture-only release candidate;
real Documentation bodies are not transferred until an authorized
redistribution license is recorded. Documentation remains the private
authoring source of truth.

The candidate is read-only and uses exact-version pins, a fixed synthetic
fixture lock in frontmatter plus a generated source-lock commit equal to the
exact Examples Git head, manifests,
indexes, checksums, a stable-channel descriptor and a protected human release
gate. Partner-local knowledge must live outside the bundle. Native Lazurio
installation is intentionally not implemented here.

Run the local gates from the repository root:

```bash
bun run creator-kit:build
bun run creator-kit:check
```

`creator-kit:build` creates only a local release candidate archive under the
ignored `.creator-kit-tmp/`; it does not call GitHub Releases or publish a
generated PR.
55 changes: 55 additions & 0 deletions TODO.tasks.json
Original file line number Diff line number Diff line change
Expand Up @@ -336,6 +336,61 @@
"role": "planning_source"
},
"source": "mission-control"
},
{
"id": "task-2026-08-07-6455-examples-candidate",
"title": "DEV-6455: Build the reviewed Spectoda Creator Kit distribution candidate",
"status": "review",
"priority": "high",
"priority_rank": 56,
"assignee": "agent",
"priority_decider": "matejsuchanek",
"priority_reason": "The public Examples repository is the reviewed Creator Kit distribution surface, while Documentation remains private and authoritative.",
"created_at": "2026-08-07",
"updated_at": "2026-08-07",
"tags": [
"DEV-6455",
"creator-kit",
"release-candidate",
"public-safety",
"agents"
],
"dev_code": "DEV-6455",
"summary": "Generate a synthetic-fixture-only English Creator Kit candidate with exact source locks, manifests, indexes, checksums, compatibility, stable-channel and provenance contracts. Keep release, generated PR, partner mutation and Lazurio installation behind explicit human gates.",
"risk_notes": [
"No real Documentation body may enter this public repo until the authorized redistribution license is recorded.",
"The stable channel is intentionally unpublished and native Lazurio distribution is a separate dependency."
],
"acceptance_criteria": [
"The candidate is deterministic across two builds and includes a verifiable archive, provenance, source lock and checksum manifest.",
"Public-safety, link, secret, license and size gates plus negative fixtures pass; document IDs and indexes are unique and deterministic.",
"Codex/Claude-shaped objective fixtures pass citation and abstention checks without claiming a real pilot or partner onboarding."
],
"links": [
{
"label": "Creator Kit bundle",
"path": "creator-kit"
},
{
"label": "Creator Kit release builder",
"path": "scripts/creator-kit/build-release-candidate.mjs"
},
{
"label": "Creator Kit validation",
"path": "scripts/creator-kit/validate.mjs"
},
{
"label": "Mission Control plan",
"path": "db/data/mission-control/plans/2026/08/DEV-6455-spectoda-creator-kit-agent-knowledge-release.yaml"
}
],
"planning": {
"plan_id": "mcplan-dev-6455",
"path": "db/data/mission-control/plans/2026/08/DEV-6455-spectoda-creator-kit-agent-knowledge-release.yaml",
"source": "mission-control",
"role": "execution_task"
},
"source": "mission-control"
}
]
}
Loading
Loading