Files
govoplan-files/docs/GENERATED_ARTIFACT_STORE.md
T

1.3 KiB

Generated Artifact Store

Files implements Core's optional files.artifact_store capability for modules that generate deterministic output without owning file storage.

The producer supplies bytes, filename, content type, destination folder, optional idempotency key, and bounded non-secret provenance. Files applies the actor's files:file:upload permission, tenant/user ownership, path rules, versioning, configured blob backend, and conflict behavior. An idempotency key is represented as source provenance so an unchanged retry does not create an unrelated file version.

The shared Files session owns finalization. Before a new managed object is written, Files commits a lease-fenced Core recovery operation containing only identifiers and digests. The caller's eventual session commit independently verifies both FileBlob metadata and stored bytes; rollback compensates only an unreferenced key. Producers must therefore complete the supplied transaction normally and must not bypass or replace Files session lifecycle handling.

The response contains only file/version identifiers, display path, media type, size, digest, and storage provenance. Producers must not put credentials, tokens, or rendered plaintext into metadata. Storing an artifact proves Files accepted it; it does not prove printing, mailing, or any other external effect.