import type { ArtifactBody, ObjectStore } from "./storage.js"; import type { GovernanceStore, LifecycleReceipt } from "./governance-store.js"; import { type OutputGovernanceConfig } from "./governance.js"; import type { ServerArtifact, ServerRunRecord, SkillsProductStore } from "../server/types.js"; /** * The object half of the artifact lifecycle: the storage seam's read/write * surface plus the two operations governance needs and the base seam does not * declare - object deletion (expiry sweep) and the quarantine move * (cancellation). ArtifactStorage implements all of them; a db-only embedder * omits the optional ones and rows-only governance still works. */ export interface RunObjectStore extends ObjectStore { deleteObject?(artifact: ServerArtifact): Promise; moveToQuarantine?(artifact: ServerArtifact): Promise; quarantineKeyFor(tenantId: string, runId: string, artifactId: string): string; } export interface GovernedArtifactWriter { write(run: ServerRunRecord, meta: Omit, body: ArtifactBody): Promise; } export interface OutputGovernanceOptions { store: SkillsProductStore; governanceStore: GovernanceStore; storage?: RunObjectStore; config?: OutputGovernanceConfig; /** Explicit override of the default visibility for this writer. */ visibility?: "private" | "public"; } /** * Apply the configured redaction patterns to run output before it is stored. * * The hook is pure and exported so the same patterns can guard logs and run * records that never pass through the artifact writer. */ export declare function redactRunOutput(value: unknown, patterns?: RegExp[]): string; /** Expiry timestamp for an artifact written now under the given TTL. Absent only when the TTL is undefined. */ export declare function expiresAtFor(createdAt: string, ttlSeconds: number | undefined): string | undefined; /** * The write-time gate. Every enforcement happens before the row exists: * * 1. redact the body text (before storage), * 2. refuse an output above the per-output cap, * 3. refuse a run whose accumulated outputs would exceed the per-run cap, * 4. stamp visibility (private by default) and expiresAt (createdAt + TTL), * 5. materialize (db column or S3 object) and persist. */ export declare function createGovernedArtifactWriter(options: OutputGovernanceOptions): GovernedArtifactWriter; /** * The retention sweep: delete every artifact whose expiresAt is in the past. * * Row deletion and object deletion both happen; the object is removed first so * an object with no row cannot outlive the row (a row with no object is only a * metadata entry, the safe direction). One append-only receipt records what was * deleted, when, and on whose request. Receipts have no update or delete path. */ export declare function expireArtifacts(options: { governanceStore: GovernanceStore; storage?: RunObjectStore; requestedBy: string; now?: string; }): Promise;