feat: collect infrastructure dependency inventories
Module Package Release / publish-packages (push) Successful in 13s

This commit is contained in:
2026-08-24 15:00:08 +02:00
parent 08c3e47b6d
commit 9cb2080938
8 changed files with 378 additions and 38 deletions
+13
View File
@@ -200,6 +200,19 @@ Feature providers remain responsible for their own semantics:
Ops projects the same Core-validated receipt. It must not maintain a second
parser with different validation or secret-handling rules.
Core also defines the inverse, read-only dependency-inventory contract used
before the installer changes one of those infrastructure capabilities. An
enabled module registers
`infrastructure.dependency_inventory.<module_id>` and returns bounded, stable
references to its persisted configuration or data, a lifecycle state, scope,
numeric metrics, and a required operator action. Providers must not return
secrets or use this read to migrate state. The Core collector validates provider
identity and capability coverage, orders records deterministically, and marks
the complete inventory failed when any provider raises or violates the
contract. Ops is the authorized projection boundary; the installer remains the
consumer and must match installation id, freshness, completion and impacted
capability coverage before apply.
The admin wizard backend starts with these routes:
- `GET /api/v1/admin/configuration-packages/catalog`