import type { ApplyAction, ApplyPlan, PendingApproval, SecretResolverFn } from '@enterprise-skills/launchops-core'; interface LaunchCommonOptions { manifest?: string; json?: boolean; skipVendors?: string; } /** * Secret resolution for plan/apply (B5): `vercel-project://` sources — the * scheme the launchops-cli README has advertised since v0.4 — previously * FAILED under `es launch` because only the env resolver was wired. Routed * explicitly: vercel-project:// needs VERCEL_TOKEN and says so when absent; * everything else resolves from env exactly as before. */ export declare function launchSecretResolver(): SecretResolverFn; export declare function launchInitCommand(options: { manifest?: string; tenant?: string; force?: boolean; }): Promise; export declare function launchAdaptersCommand(options: { json?: boolean; }): Promise; /** * `launch doctor` (readiness B8): the credentials step existed in NO next-step * hint — a user's first contact with VERCEL_TOKEN et al. was a scan failure. * Doctor answers "can this manifest run here", per vendor, BEFORE anything * else: adapter registered → credential env present → (--live) a real * authenticate probe. Read-only; exits 1 when anything is missing. */ export declare function launchDoctorCommand(options: LaunchCommonOptions & { live?: boolean; }): Promise; export declare function launchScanCommand(options: LaunchCommonOptions): Promise; export declare function launchDiffCommand(options: LaunchCommonOptions): Promise; export declare function launchReportCommand(options: LaunchCommonOptions & { out?: string; format?: string; organization?: string; title?: string; }): Promise; export declare function launchAdviseCommand(options: { tier?: string; json?: boolean; }): Promise; export declare function launchPlanCommand(options: LaunchCommonOptions & { out?: string; }): Promise; /** * Parse a plan file at the boundary, the same discipline the evidence reader * uses: this file drives real infrastructure mutations, so "not a plan" must be * a clean refusal rather than a raw SyntaxError from `JSON.parse` or a * `not iterable` TypeError thrown from inside the executor's action loop. */ export declare function parsePlanFile(raw: string, source: string): ApplyPlan; export interface LaunchApplyOptions extends LaunchCommonOptions { dryRun?: boolean; verifyRetries?: number; env?: string; /** Injectable for tests, same shape as deploy.ts. */ fetchImpl?: typeof fetch; git?: (args: string) => string; } /** * §20.2 deployment event for an executed launch plan (v2 slice 3): a * launch-day apply and a release promotion become the same class of evidence. * One TERMINAL event per run — `failed` if any action failed, `rolled_back` * when a rollback plan completed, else `succeeded`. A run that executed * nothing (all gated/skipped) records nothing: there was no deployment. * Posting failure never rewrites the apply outcome, but it is loud and exits * nonzero — the operator asked for evidence and the trail is incomplete. */ export declare function postLaunchDeploymentEvent(plan: ApplyPlan, results: Array<{ outcome: string; }>, options: LaunchApplyOptions): Promise; export declare function launchApplyCommand(planRef: string, options: LaunchApplyOptions): Promise; export interface LaunchDecisionOptions extends LaunchCommonOptions { identity?: string; role?: string; reason?: string; ticket?: string; scope?: string; expires?: string; /** * Commander's `--no-mirror` sets this to false (it does NOT set a `noMirror` * flag). Undefined means "not specified" and mirrors, which is the default. * Offline tenants pass --no-mirror; per D-3 the tenant queue is the authority. */ mirror?: boolean; /** Bind the mirror to this commit instead of HEAD (CI resolves approvals * from a job whose checkout need not be the governed commit). */ commit?: string; repository?: string; fetchImpl?: typeof fetch; git?: (args: string) => string; } /** * Mirror the resolved approval server-side (slice 3, ruling D-3). * * The tenant queue is the authority; this is a countersigned summary. A * mirroring failure therefore NEVER changes the local decision — the approval * stands — but it is loud and exits nonzero, because an operator running in a * governed repo asked for an audit trail and did not get one. * * Only the action DESCRIPTOR crosses: vendor, verb, resource type and id. The * `parameters` block (env-var values) and the nested `inverse` stay tenant-side, * and the server refuses them if they ever appear. */ export declare function postApprovalMirror(approval: PendingApproval, options: LaunchDecisionOptions): Promise<{ recorded: boolean; duplicate?: boolean; countersigned?: boolean; } | null>; /** Stable digest of the gated action, so the mirror binds to what was approved. */ export declare function actionDigest(action: ApplyAction): string; export declare function launchApproveCommand(id: string, options: LaunchDecisionOptions): Promise; export declare function launchRejectCommand(id: string, options: LaunchDecisionOptions): Promise; export declare function launchListApprovalsCommand(options: { status?: string; vendor?: string; json?: boolean; }): Promise; export declare function launchRollbackCommand(planRef: string, options: LaunchCommonOptions & { resultsFile?: string; }): Promise; export declare function launchTemplatesCommand(options: { json?: boolean; }): Promise; export declare function launchNewCommand(template: string, options: { manifest?: string; force?: boolean; json?: boolean; param?: string[]; }): Promise; export declare function launchWatchCommand(options: LaunchCommonOptions & { interval?: string; ticks?: number; }): Promise; export {}; //# sourceMappingURL=launch.d.ts.map