CDF config, shared core
The part of .cdf/config.yaml that every Cognitive Delivery implementation must understand identically. Product-specific sections are deliberately NOT here: a product carries its own alongside these, which is why additionalProperties is true at the root.
- Schema
config-core.schema.json, served as JSON at its$id: https://cognitive-delivery.github.io/contract/1.x/config-core.schema.json- Dialect
http://json-schema.org/draft-07/schema#- Root
- object, open (additional properties are carried)
- Stability
- none stated at the root; every declared property carries its own
- Properties
- 18 declared: 18 under the root, 0 in definitions
Properties
Every declared property under the root, in the schema's own order. [] is an array's items, .* the shape of every unnamed member, #name a definition. Objects carry additional properties unless a row says otherwise.
| Path | Type | Required | Description | Constraints | Stability |
|---|---|---|---|---|---|
adoption_tier | integer | How much governance this workspace has adopted. Read by the Index, so it must mean the same thing everywhere. | one of 1, 2, 3, 4max 9007199254740991 | stable | |
governance | object | stable | |||
governance.source | string | stable | |||
governance.refresh_mode | string | one of "on-open", "manual", "scheduled" | stable | ||
governance.profile | string | stable | |||
review_policy | object | Who must review, and whether the author may. Security-relevant: an implementation that ignored reviewer_cannot_be_implementer would let work approve itself. | stable | ||
review_policy.cross_model_review_required | boolean | stable | |||
review_policy.reviewer_cannot_be_implementer | boolean | stable | |||
review_policy.required_reviewers | integer | min 0 max 9007199254740991 | stable | ||
provenance | object | stable | |||
provenance.required_fields | array | stable | |||
provenance.required_fields[] | string | ||||
cdi | object | stable | |||
cdi.enabled | boolean | stable | |||
cdi.aggregation_endpoint | string | null | Null means local only. Null is the default and is a value, not an omission. | stable | ||
break_glass | object | The exceptional override. Security-relevant: an implementation that widened this beyond one spec and one non-final gate would break the policy the framework states. | stable | ||
break_glass.mode | string | one of "self-service-logged", "two-person", "disabled" | stable | ||
break_glass.timeout_minutes | integer | min 0 max 9007199254740991 | stable | ||
sealed | array | Dotted paths of fields an upper layer has fixed. SEALING IS PART OF THE CONTRACT, and any implementation that ignores it fails conformance. A sealed field may not be relaxed by a downstream layer: a lower layer may match the sealed value or make it stricter, never looser. Ignoring this would let a workspace quietly undo a control its organisation set. | stable | ||
sealed[] | string | A dotted path of lower-case segments (review_policy.reviewer_cannot_be_implementer). The runner also checks that a sealed path in a fixture resolves to a key the file carries. | pattern ^[a-z][a-z0-9_]*(\.[a-z][a-z0-9_]*)*$ |