# @ankhorage/infra

## 7.1.6

### Patch Changes

- e3d03be: Update Ankhorage dependencies: `@ankhorage/ankh`, `@ankhorage/devtools`.

## 7.1.5

### Patch Changes

- a859aea: Update Ankhorage dependencies: `@ankhorage/ankh`, `@ankhorage/devtools`.

## 7.1.4

### Patch Changes

- 6f88db1: Update Ankhorage dependencies: `@ankhorage/ankh`, `@ankhorage/devtools`.

## 7.1.3

### Patch Changes

- 2da5618: Materialize public local Infra outputs that declare environment-variable names into the generated app `.env.local`, preserving unrelated entries while keeping secret outputs as references.

## 7.1.2

### Patch Changes

- e707284: Render standalone Infra help from the canonical provider manifest through the shared Ankh CLI help runtime.

## 7.1.1

### Patch Changes

- 7440682: Expose the project-scoped credential port constructor from `@ankhorage/infra/project` for downstream host composition without exposing credential storage details.

## 7.1.0

### Minor Changes

- afc7347: Persist provider-generated control-plane credential bundles inside Infra-owned project/environment state, reuse them across fresh processes, and remove them only with complete environment destruction.

## 7.0.0

### Major Changes

- 1778b96: Add provider-neutral service preparation before workload materialization and extend trusted control-plane credential hosts with optional lookup and explicit persistence so providers can prepare bootstrap state without runtime-specific coupling. Read-only lifecycle operations remain side-effect free.

## 6.0.0

### Major Changes

- 99a0dbd: Align Infra with Contracts 20 and add production S3 backup/recovery acceptance for the Supabase production slice.

## 5.1.6

### Patch Changes

- 57da4cf: Prove the released Hetzner, k3s, Supabase and R2 composition with independent object-storage ownership and privileged output isolation.

## 5.1.5

### Patch Changes

- 7da18cd: Make project Infra destroy idempotent when no stored ownership state exists, avoiding provider resolution for never-provisioned or already-destroyed environments.

## 5.1.4

### Patch Changes

- 3a4d8a3: Consume the current Infra networking TLS contract while proving the released k3s production HTTPS integration in the Hetzner composition acceptance baseline.

## 5.1.3

### Patch Changes

- 246e468: Retain compute targets and compute ownership when runtime-owned resources survive `infra destroy`, so production persistence is not orphaned by underlying host deletion. Production composition validation now runs against k3s 0.3.1+ and Kubernetes 0.7.3+, including current workload-template materialization.

## 5.1.2

### Patch Changes

- 343eefe: Prove in the real local Minikube acceptance that reconciliation prunes stale Infra-owned resources without deleting unrelated Kubernetes resources.

## 5.1.1

### Patch Changes

- 0771f29: Add reproducible local Minikube + Supabase Phase 8 parity acceptance against the released provider-neutral adapters and runtime fixes.

## 5.1.0

### Minor Changes

- 51a60f2: Expose a typed project lifecycle that applies the canonical Infra use cases while preserving environment-scoped state and generated artifact ownership.

## 5.0.0

### Major Changes

- 11216db: Replace the embedded Minikube implementation and application-specific deployment helpers with a provider-neutral typed environment lifecycle.

  Infra now resolves the published compute, runtime, database/auth/storage, authorization and secret-store packages selected by the canonical manifest. It exposes `validate`, `plan`, `generate`, `up`, `status`, `outputs`, `down` and `destroy` through both the standalone executable and the Ankh provider. Environment-scoped state records exact ownership and secret references, while destroy requires exact project/environment confirmation and explicit confirmation for persistent deletion.

  Consumers must migrate from removed Minikube, OAuth, port-forward, reset and app-serving APIs to the canonical manifest plus the eight lifecycle commands. Project tooling should use the renamed async owner APIs from `@ankhorage/infra/project`, such as `resolveInfraProjectAsync`, `readStoredInfraStateAsync` and `writeInfraGeneratedArtifactsAsync`.

## 4.1.12

### Patch Changes

- af1d003: Update Ankhorage dependencies: `@ankhorage/contracts`.
- a67796e: Update Ankhorage dependencies: `@ankhorage/supabase-vault`.
- 64bbf27: Update Ankhorage dependencies: `@ankhorage/supabase-vault`.

## 4.1.11

### Patch Changes

- aa85aff: Update Ankhorage dependencies: `@ankhorage/supabase-vault`.

## 4.1.10

### Patch Changes

- fb11cb2: Update Ankhorage dependencies: `@ankhorage/supabase-vault`.

## 4.1.9

### Patch Changes

- 427552a: Update Ankhorage dependencies: `@ankhorage/contracts`.

## 4.1.8

### Patch Changes

- 1952e2e: Update Ankhorage dependencies: `@ankhorage/contracts`, `@ankhorage/supabase-vault`.

## 4.1.7

### Patch Changes

- 6670cb5: Update Ankhorage dependencies: `@ankhorage/contracts`.

## 4.1.6

### Patch Changes

- 2734478: Update Ankhorage dependencies: `@ankhorage/contracts`.

## 4.1.5

### Patch Changes

- ec1f351: Update Ankhorage dependencies: `@ankhorage/supabase-vault`.

## 4.1.4

### Patch Changes

- ed2b643: Update Ankhorage dependencies: `@ankhorage/contracts`, `@ankhorage/paradox`, `@ankhorage/supabase-vault`.

## 4.1.3

### Patch Changes

- 9cb5d75: Require generated app-image builds to execute the app-installed Expo CLI and fail before export when dependencies are missing.

## 4.1.2

### Patch Changes

- b25415f: Emit Minikube README and Kong templates in their canonical generated format.

## 4.1.1

### Patch Changes

- 591cecb: Derive Minikube app runtime resources and canonical forward groups from enabled app deployment targets, reconcile obsolete Web runtime resources and owned forwards during native-only upgrades, and retry transient post-restart forwarding failures so native apps can recover provider endpoints without a nonexistent app Service.

## 4.1.0

### Minor Changes

- 66ef9aa: Add a provider-aware runtime port-forward lifecycle and export `ensureProjectInfrastructureRuntime` from `@ankhorage/infra/project`.

## 4.0.0

### Major Changes

- 82e969e: Align infrastructure generation with canonical `infra.apis[]`, remove generated-API database projection and public generator exports, treat external APIs as infrastructure no-ops, and report internal API provisioning as unsupported in Phase 1.

## 3.3.0

### Minor Changes

- 716f678: Derive Supabase OAuth redirect allowlists from canonical app deployment targets, using enabled Web state and stable Android/iOS schemes instead of a separate native redirect environment variable.

## 3.2.0

### Minor Changes

- f4ffc4b: Expose canonical project inspection, filtered generated runtime-environment access, and trusted project database URL resolution through `@ankhorage/infra/project`.

## 3.1.1

### Patch Changes

- f38e50b: Delegate project `AppManifest` structural validation to the canonical parser published by `@ankhorage/contracts` and remove Infra's duplicate manifest guard implementation.

## 3.1.0

### Minor Changes

- 2e90e4a: Expose the canonical project and lifecycle application-service boundary through `@ankhorage/infra/project`, including project reconciliation, lifecycle execution, and generated port-forward endpoint resolution for trusted consumers such as Studio.

## 3.0.0

### Major Changes

- e4549c9: Consume the canonical Contracts 6 module manifest boundary and require `infra.modules` instead of the removed legacy `infra.plugins` field.

## 2.0.1

### Patch Changes

- 6ff65a4: Keep Supabase Auth runtime environment assignments declarative across OAuth reconciliation so repeated Minikube Infra Up runs can safely reapply the generated deployment.

## 2.0.0

### Major Changes

- a4dda40: Consume the canonical generated API desired-state contract, generate deterministic Supabase/Postgres database artifacts, and remove the obsolete generated API handler/OpenAPI artifact surface.

## 1.1.0

### Minor Changes

- bd82fe0: Add canonical environment-aware Auth redirect configuration and reconcile Minikube GoTrue callback settings through a forced, bounded deployment rollout.

## 1.0.6

### Patch Changes

- 296d006: update SUPABASE-VAULT

## 1.0.5

### Patch Changes

- f566fef: Update SUPABASE-VAULT

## 1.0.4

### Patch Changes

- 434d4da: Clear the Expo/Metro export cache before building generated Minikube app images so rotated browser-safe Supabase credentials replace stale values in the client bundle.

## 1.0.3

### Patch Changes

- 9ab757e: Prevent generated Supabase migration lifecycles from waiting indefinitely on blocked CLI telemetry, and report visible migration progress.

## 1.0.2

### Patch Changes

- aba801b: Preserve the browser-visible forwarded origin when generated app nginx redirects canonical static routes such as `/products` to `/products/`.

## 1.0.1

### Patch Changes

- efa43ed: Write generated Supabase browser env values into the app `.env.local` during Minikube Infra
  Up so local Expo auth clients receive the gateway URL and anon key.

## 1.0.0

### Major Changes

- 04b6470: Rebuild generated Minikube infrastructure around one app-owned Minikube profile per app slug.

  Generated local infra now uses namespace `app` for the app runtime and namespace `supabase` for Kubernetes-owned Supabase workloads. Host-owned Supabase Compose startup, `supabase-local-env.sh`, shared `minikube` profile fallbacks, and `supabase migration up --local` runtime ownership have been removed. Generated lifecycle scripts now use slug-scoped `up`, `down`, `reset`, `destroy`, `status`, and managed port-forward flows.

## 0.4.2

### Patch Changes

- 53c8e75: Make generated disabled Supabase profile verification safe when local generated profile state has
  never existed.

## 0.4.1

### Patch Changes

- f48b53f: Preserve app-specific Supabase local project identity while keeping the canonical Minikube workdir.

## 0.4.0

### Minor Changes

- dd7c668: Compose the canonical secret-store adapter from `infra.secretStore.provider`, generate the released Supabase Vault migration through the existing local Supabase lifecycle, and validate OAuth credential references before infrastructure generation.

## 0.3.7

### Patch Changes

- 1f86a8e: Finalize the generated API handler promise normalization so the package passes CI and generated apps remain compatible with `@typescript-eslint/require-await`.

## 0.3.6

### Patch Changes

- 89eb7cf: Generate in-memory API store methods with explicit `Promise.resolve(...)` returns instead of unnecessary `async`, so generated apps pass `@typescript-eslint/require-await`.

## 0.3.5

### Patch Changes

- ad6fd70: Support authentication manifests without authorization, resolve auth routes from the canonical `infra.auth.flow`, and keep Cerbos generation compatible with manifests that omit infra context.

## 0.3.4

### Patch Changes

- 13d1a02: Publish Infra against `@ankhorage/contracts` 2.0.0 so downstream consumers use the optional authorization contract consistently.

## 0.3.3

### Patch Changes

- 77be403: Make generated local Supabase profile schema deterministic by separating immutable migrations from generated reconciliation, applying profile desired state during local startup, and verifying the live database schema.

## 0.3.2

### Patch Changes

- f407622: Move the standalone infrastructure CLI and its tests under the canonical `src/cli/` package boundary while preserving the published `ankhorage-infra` binary.

## 0.3.1

### Patch Changes

- 997af24: Release package command entry changes.

## 0.3.0

### Minor Changes

- 0952c75: Add executable Ankh infra provider metadata, standalone CLI, and shared command dispatch.

## 0.2.1

### Patch Changes

- 9839fba: Update CONTRACTS & update docs

## 0.2.0

### Minor Changes

- 6abebe9: Generate Supabase profile table metadata and migrations from `manifest.infra.auth.profile`.

## 0.1.0

### Minor Changes

- a8dfa6b: Generate infrastructure artifacts from API definitions.
