Problem
Whole-project export is too coarse for common sharing and promotion workflows. Users need to package only an ontology, selected data components, derived artifacts, or selected non-secret settings without manually copying files, accidentally leaking unrelated state, or producing an unusable dependency set.
Objective
Add a deterministic, previewable component-selection and dependency-closure contract for portable project v2.
Requirements
- Define typed built-in profiles for complete project, ontology-only, data-components, artifacts, settings, and custom selections.
- Select by stable semantic identity and component kind, never by runtime-local catalog ID or unchecked host path.
- Resolve mandatory dependencies deterministically and explain every auto-included component. Support a strict mode that fails rather than adding undeclared closure.
- Treat the semantic manifest, package metadata, and explicit required closure as overhead, not as a violation of
only; forbid unrelated payload kinds.
- Ontology-only export uses the existing explicit ontology-document authority, preserves authored migration ordering where included, excludes session-only loads, and never adopts or clears authority.
- Settings selection includes only closed-schema, portable, non-secret values or secret references. Secret values, credentials, local absolute paths, live runtime state, and provider state always fail or are explicitly redacted with a receipt.
- Preview returns exact included/excluded stable identities, reasons, estimated counts/bytes where knowable, required capabilities, redactions, and a deterministic selection fingerprint before writing.
- Unsupported combinations, missing dependencies, ambiguous identities, incompatible package classes, and selectors that would silently widen fail with stable typed errors.
- Feed the same selection plan into expanded export, bundle export, verification, OCI publication, and bindings.
Acceptance criteria
BDD completion scenarios
Scenario: Share only an ontology
Given a project with an adopted ontology and unrelated data/artifacts/settings
When the ontology-only profile is previewed and exported
Then the receipt names only the ontology and bounded required metadata
And the verifier proves the unrelated payload classes are absent.
Scenario: Required closure is visible
Given a selected artifact that requires a schema and ontology version
When the plan is resolved
Then those dependencies are either explicitly included with reasons or strict mode fails
And the exporter never guesses or silently widens the package.
Scenario: Settings stay safe
Given settings containing portable values, secret references, a secret value, and an absolute host path
When settings export is planned
Then portable values and allowed references may be selected
And secret values and non-portable paths fail or are explicitly excluded before any package is written.
Observability and security
Record aggregate selected/excluded/redacted counts and stable reason codes. Do not log values, selectors containing private content, secrets, absolute paths, or unbounded inventories.
Testing and documentation
Add profile and dependency-graph unit tests, privacy leakage fixtures, ontology-authority regression tests, settings schema/security tests, preview/export race tests, and parity fixtures. Document recipes for ontology, data component, artifact, settings, and custom sharing.
Non-goals
Arbitrary row/subgraph extraction, graph merge, secret transport, implicit ontology adoption, or provider/IaC state export.
Related issues
Portable-v2 epic: #740. Format/verifier/export prerequisites: #783, #784, and #741. Fine-grained graph/data selection: #786.
Problem
Whole-project export is too coarse for common sharing and promotion workflows. Users need to package only an ontology, selected data components, derived artifacts, or selected non-secret settings without manually copying files, accidentally leaking unrelated state, or producing an unusable dependency set.
Objective
Add a deterministic, previewable component-selection and dependency-closure contract for portable project v2.
Requirements
only; forbid unrelated payload kinds.Acceptance criteria
BDD completion scenarios
Scenario: Share only an ontology
Given a project with an adopted ontology and unrelated data/artifacts/settings
When the ontology-only profile is previewed and exported
Then the receipt names only the ontology and bounded required metadata
And the verifier proves the unrelated payload classes are absent.
Scenario: Required closure is visible
Given a selected artifact that requires a schema and ontology version
When the plan is resolved
Then those dependencies are either explicitly included with reasons or strict mode fails
And the exporter never guesses or silently widens the package.
Scenario: Settings stay safe
Given settings containing portable values, secret references, a secret value, and an absolute host path
When settings export is planned
Then portable values and allowed references may be selected
And secret values and non-portable paths fail or are explicitly excluded before any package is written.
Observability and security
Record aggregate selected/excluded/redacted counts and stable reason codes. Do not log values, selectors containing private content, secrets, absolute paths, or unbounded inventories.
Testing and documentation
Add profile and dependency-graph unit tests, privacy leakage fixtures, ontology-authority regression tests, settings schema/security tests, preview/export race tests, and parity fixtures. Document recipes for ontology, data component, artifact, settings, and custom sharing.
Non-goals
Arbitrary row/subgraph extraction, graph merge, secret transport, implicit ontology adoption, or provider/IaC state export.
Related issues
Portable-v2 epic: #740. Format/verifier/export prerequisites: #783, #784, and #741. Fine-grained graph/data selection: #786.