Contributing
Development environment
Section titled “Development environment”uv sync # Python >= 3.12make lint # ruff check + ruff format --checkmake test # embedded PostgreSQL, local Executor, recorded fixturesmake console-check # Console typecheck, tests and buildmake docs-check # this site: build, then link checksmake openapi # regenerate docs/specs/unified/openapi.yamlmake test must never need cloud credentials.
Architecture rules
Section titled “Architecture rules”docs/architecture/unified/is the normative RFC;docs/specs/unified/describes implemented behaviour and is updated with it.- PostgreSQL is the only business authority and every resource has one writer.
tests/unit/test_layer_boundaries.pyenforces import direction, andtests/unit/test_openapi_drift.pyfails when the OpenAPI document drifts.- Tests run against a real throwaway PostgreSQL cluster, never a mock.
Secrets
Section titled “Secrets”Fixtures use the literal REDACTED for token, password and secret fields. Opt-in
live scripts read credentials from the environment, never print them and must
terminate every sandbox they create.
Pull requests
Section titled “Pull requests”make lint,make testandmake console-checkpass without credentials.- No credentials or real account data in the diff.
- Specs and docs are updated when behaviour, variables, commands or routes change.