diff --git a/docs/operations/workspaces.md b/docs/operations/workspaces.md index a50815f5..76ebe5e0 100644 --- a/docs/operations/workspaces.md +++ b/docs/operations/workspaces.md @@ -11,10 +11,17 @@ boundary between what can be published and what can be used by an installation. | Installation operator | Git source, selected workspace, write-only runtime secrets, validation, connectivity, and preprocessing | commits or pushes to the workspace repository | | Reviewer | NL→SQL decisions in a pinned session | workspace publication or preprocessing | -The root catalog has `schema_version: 1` and an ordered list of workspace identities. Each entry -must have a matching schema-v3 descriptor at `/workspace.yaml` in the same Git commit. The -application validates a complete candidate revision and activates it atomically; invalid content -leaves the preceding active revision in place. + +The root catalog has `schema_version: 1` and an ordered list of workspace identities. + + + +Schema v3 is the only accepted workspace descriptor. Schema v1 and v2 workspace descriptors are +rejected before activation. Each catalog entry must have a matching descriptor at +`/workspace.yaml` in the same Git commit. The application validates a complete candidate +revision and activates it atomically; invalid content leaves the preceding active revision in +place. + ## Operator sequence diff --git a/scripts/verify-schema-v3-only.sh b/scripts/verify-schema-v3-only.sh index da0637a6..68b00621 100755 --- a/scripts/verify-schema-v3-only.sh +++ b/scripts/verify-schema-v3-only.sh @@ -266,13 +266,10 @@ check_dist_tree() { if [[ $runtime_only -eq 0 ]]; then require_trusted_files_at "$root" \ scripts/workspace_descriptor_doc_contract.py README.md PROJECT_STATE.md \ - docs/install/local-workspace-registry.md docs/install/server-workspace-registry.md \ - docs/workspace-diagnostic-protocol.md + docs/install/first-start.md docs/operations/workspaces.md "$root/scripts/workspace_descriptor_doc_contract.py" \ - --document "$root/README.md" --project-state "$root/PROJECT_STATE.md" \ - --document "$root/docs/install/local-workspace-registry.md" \ - --document "$root/docs/install/server-workspace-registry.md" \ - --document "$root/docs/workspace-diagnostic-protocol.md" + --document "$root/README.md" \ + --document "$root/docs/operations/workspaces.md" fi echo "schema-v3-only absence gate passed"