Status: experimental implementation contract
Issue: #596 / C8-C
Authority: rendering only; no filesystem write, GitHub mutation, secret
resolution, dispatch, verification, approval, push, or merge authority.
C8-C turns the deterministic C8-A bootstrap file plan into deterministic bytes for the project-side configuration portion of a GitHub-first installation.
The renderer consumes a validated
idkmesh.github_bootstrap.GitHubBootstrapPlan and emits exactly these files:
.idkmesh/README.md;.idkmesh/project.json;.idkmesh/connections.json;.idkmesh/domain-packs/software-engineering-v0.1.domain-pack.json.Workflow wrappers remain C8-D. Filesystem application and safe re-run behavior remain C8-F.
For the same bootstrap plan, rendering must produce byte-identical UTF-8, newline-terminated output.
Every rendered file carries:
The content digest is evidence for a later apply/re-run boundary. It does not authorize overwriting a file by itself; C8-F must compare retained generated identity with the actual target content and preserve user edits.
The generated .idkmesh/project.json is a valid ProjectManifest v0.1 seed.
Safety defaults include:
low;The generated target branch comes from the validated bootstrap plan.
The generated .idkmesh/connections.json is valid connector-profile input.
The initial template contains one Jules connector because it demonstrates the secret-reference boundary without inventing a credential value.
It is deliberately:
enabled: false;auth.secret_ref = env:JULES_API_KEY;sources/github/OWNER/REPOSITORY.The bootstrap never reads JULES_API_KEY. The owner must configure the secret
outside tracked repository files and must update the Source identity before
enabling the connector.
The generated software-engineering DomainPack is semantically identical to the
canonical checked-in
examples/domain-packs/software-engineering-v0.1.domain-pack.json.
Tests compare the rendered document with that canonical source and validate it
against schemas/domain-pack.schema.json. Drift therefore fails CI rather than
silently creating a second software-engineering policy.
The generated .idkmesh/README.md explains:
user_seed versus idkmesh_managed;idkmesh init --github --dry-run continues to perform zero writes.
Its JSON form additionally emits rendered_config_files, including content,
digest, size, ownership, and overwrite metadata. Human-readable output shows
the rendered paths and digests without printing secret material.
Apply mode remains fail-closed.
Rendering fails closed when:
GitHubBootstrapPlan;A C8-A/C8-C mismatch must not be treated as permission to silently omit or add project files.
This slice does not:
Focused tests cover: