/** * Putting the check on a clock, and letting an agent manage the clock. * * `GOAL.md` argues the clock is where the money is, and the argument is * specific: a breach introduced by code shows up at deploy time and a deploy * hook catches it, but somebody opening the Supabase dashboard and running SQL * by hand is invisible to every deploy hook and every CI gate. Only a clock * catches that. One real database we examined had seven migrations applied that * way and never recorded. * * What runs on the clock is `verify`, not the full proof, and that is not an * optimisation. The scheduled job is the one aimed at production, and `verify` * is the half that connects as a role which cannot read a single customer row. * A schedule that pointed the seeding run at a production database would be * this product doing the thing it exists to prevent. * * It is a workflow file rather than a hosted cron because that is the version * that works today, with no service and no credential of ours: it uses the * repository's own secret, in the founder's own CI, and it is a file they can * read. The hosted schedule replaces this later; the shape an agent drives — * create, read, change, remove — does not change when it does. */ export declare const SCHEDULE_FILE = "crossline-watch.yml"; export declare const SCHEDULE_PATH = ".github/workflows/crossline-watch.yml"; /** * Written into the file so that removing and rewriting only ever touches ours. * * A developer who hand-edits this file owns it from then on, and a tool that * silently replaces an edited file is a tool people delete. */ export declare const SCHEDULE_MARKER: string; /** * The ladder from `GOAL.md`: free is daily, paid is hourly. * * Minute 17 rather than 0 deliberately. Every scheduled workflow written by * every tool fires on the hour, GitHub queues them, and a job that matters gets * to run whenever the stampede clears. */ export declare const FREQUENCIES: { readonly hourly: "17 * * * *"; readonly daily: "17 6 * * *"; readonly weekly: "17 6 * * 1"; }; export type Frequency = keyof typeof FREQUENCIES; export interface Schedule { path: string; cron: string; /** The named frequency, when the cron is one of ours. */ frequency: Frequency | null; /** False when the file exists but was not written by us. */ managed: boolean; } /** What is scheduled right now, or null when nothing is. */ export declare function readSchedule(cwd: string): Schedule | null; export type WriteOutcome = { ok: true; path: string; created: boolean; } | { ok: false; reason: string; }; /** * Create or change the schedule. * * Refuses a file it did not write, always. That file might be a workflow * somebody tuned, and the cost of being wrong is silently reverting work * somebody did on purpose. */ export declare function writeSchedule(cwd: string, cron: string): WriteOutcome; export type RemoveOutcome = { ok: true; removed: boolean; } | { ok: false; reason: string; }; /** Stop the clock. Refuses a file it did not write, for the same reason. */ export declare function removeSchedule(cwd: string): RemoveOutcome; /** * Resolve what the caller asked for into a cron expression. * * A raw cron is accepted because somebody will want one, and refused if it is * not five fields — a malformed schedule in a workflow file is a job that never * runs, and a watcher that never runs is worse than no watcher, because * everyone believes it is watching. */ export declare function cronFor(input: string): { ok: true; cron: string; } | { ok: false; reason: string; };