Skip to content

feat(io): select ontology artifacts settings and data components for portable export #785

Description

@DecisionNerd

Problem

Whole-project export is too coarse for common sharing and promotion workflows. Users need to package only an ontology, selected data components, derived artifacts, or selected non-secret settings without manually copying files, accidentally leaking unrelated state, or producing an unusable dependency set.

Objective

Add a deterministic, previewable component-selection and dependency-closure contract for portable project v2.

Requirements

  • Define typed built-in profiles for complete project, ontology-only, data-components, artifacts, settings, and custom selections.
  • Select by stable semantic identity and component kind, never by runtime-local catalog ID or unchecked host path.
  • Resolve mandatory dependencies deterministically and explain every auto-included component. Support a strict mode that fails rather than adding undeclared closure.
  • Treat the semantic manifest, package metadata, and explicit required closure as overhead, not as a violation of only; forbid unrelated payload kinds.
  • Ontology-only export uses the existing explicit ontology-document authority, preserves authored migration ordering where included, excludes session-only loads, and never adopts or clears authority.
  • Settings selection includes only closed-schema, portable, non-secret values or secret references. Secret values, credentials, local absolute paths, live runtime state, and provider state always fail or are explicitly redacted with a receipt.
  • Preview returns exact included/excluded stable identities, reasons, estimated counts/bytes where knowable, required capabilities, redactions, and a deterministic selection fingerprint before writing.
  • Unsupported combinations, missing dependencies, ambiguous identities, incompatible package classes, and selectors that would silently widen fail with stable typed errors.
  • Feed the same selection plan into expanded export, bundle export, verification, OCI publication, and bindings.

Acceptance criteria

  • Each built-in profile and custom selection produces a deterministic plan and selection fingerprint from the same pinned generation.
  • Ontology-only fixtures prove no graph data, artifacts, secrets, unrelated settings, runtime-local IDs, or session-only ontology state are present.
  • Data/artifact/settings selections contain only requested components plus explicitly reported required closure.
  • Preview and final package receipts agree exactly; concurrent source change fails rather than changing the selection silently.
  • Secret-bearing or non-portable settings cannot enter a package.
  • Unsupported fine-grained data selection is rejected and directed to feat(io): export deterministic graph data subsets with referential closure #786 rather than broadened.

BDD completion scenarios

Scenario: Share only an ontology

Given a project with an adopted ontology and unrelated data/artifacts/settings
When the ontology-only profile is previewed and exported
Then the receipt names only the ontology and bounded required metadata
And the verifier proves the unrelated payload classes are absent.

Scenario: Required closure is visible

Given a selected artifact that requires a schema and ontology version
When the plan is resolved
Then those dependencies are either explicitly included with reasons or strict mode fails
And the exporter never guesses or silently widens the package.

Scenario: Settings stay safe

Given settings containing portable values, secret references, a secret value, and an absolute host path
When settings export is planned
Then portable values and allowed references may be selected
And secret values and non-portable paths fail or are explicitly excluded before any package is written.

Observability and security

Record aggregate selected/excluded/redacted counts and stable reason codes. Do not log values, selectors containing private content, secrets, absolute paths, or unbounded inventories.

Testing and documentation

Add profile and dependency-graph unit tests, privacy leakage fixtures, ontology-authority regression tests, settings schema/security tests, preview/export race tests, and parity fixtures. Document recipes for ontology, data component, artifact, settings, and custom sharing.

Non-goals

Arbitrary row/subgraph extraction, graph merge, secret transport, implicit ontology adoption, or provider/IaC state export.

Related issues

Portable-v2 epic: #740. Format/verifier/export prerequisites: #783, #784, and #741. Fine-grained graph/data selection: #786.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    coreCore source code changesenhancementNew feature or requesttestingTest coverage and testing infrastructure

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions