IDKMesh

GitHub Bootstrap Config Rendering v0.1

Status: experimental implementation contract
Issue: #596 / C8-C
Authority: rendering only; no filesystem write, GitHub mutation, secret resolution, dispatch, verification, approval, push, or merge authority.

Purpose

C8-C turns the deterministic C8-A bootstrap file plan into deterministic bytes for the project-side configuration portion of a GitHub-first installation.

The renderer consumes a validated idkmesh.github_bootstrap.GitHubBootstrapPlan and emits exactly these files:

Workflow wrappers remain C8-D. Filesystem application and safe re-run behavior remain C8-F.

Determinism and generated identity

For the same bootstrap plan, rendering must produce byte-identical UTF-8, newline-terminated output.

Every rendered file carries:

The content digest is evidence for a later apply/re-run boundary. It does not authorize overwriting a file by itself; C8-F must compare retained generated identity with the actual target content and preserve user edits.

ProjectManifest seed

The generated .idkmesh/project.json is a valid ProjectManifest v0.1 seed.

Safety defaults include:

The generated target branch comes from the validated bootstrap plan.

Connector seed

The generated .idkmesh/connections.json is valid connector-profile input.

The initial template contains one Jules connector because it demonstrates the secret-reference boundary without inventing a credential value.

It is deliberately:

The bootstrap never reads JULES_API_KEY. The owner must configure the secret outside tracked repository files and must update the Source identity before enabling the connector.

Vendored DomainPack

The generated software-engineering DomainPack is semantically identical to the canonical checked-in examples/domain-packs/software-engineering-v0.1.domain-pack.json.

Tests compare the rendered document with that canonical source and validate it against schemas/domain-pack.schema.json. Drift therefore fails CI rather than silently creating a second software-engineering policy.

Generated README

The generated .idkmesh/README.md explains:

Dry-run integration

idkmesh init --github --dry-run continues to perform zero writes.

Its JSON form additionally emits rendered_config_files, including content, digest, size, ownership, and overwrite metadata. Human-readable output shows the rendered paths and digests without printing secret material.

Apply mode remains fail-closed.

Failure semantics

Rendering fails closed when:

A C8-A/C8-C mismatch must not be treated as permission to silently omit or add project files.

Non-goals

This slice does not:

Verification

Focused tests cover:

Follow-on