From e78a1ec1e9a4a388577f75d962305c6fea64d5ab Mon Sep 17 00:00:00 2001 From: tmk241 Date: Fri, 14 Aug 2026 08:23:14 +0200 Subject: [PATCH] docs(skill): preserve canonical Apsuflow declarations --- skills/apsuflow/SKILL.md | 18 +++++++++++++----- 1 file changed, 13 insertions(+), 5 deletions(-) diff --git a/skills/apsuflow/SKILL.md b/skills/apsuflow/SKILL.md index e5eca24..85f1a1f 100644 --- a/skills/apsuflow/SKILL.md +++ b/skills/apsuflow/SKILL.md @@ -71,11 +71,19 @@ declaration diff, passes `fmt --check`, `validate`, and preferably `apply --dry-run`, then applies that exact reviewed file set. Record its revision, context, dry-run, and post-apply workload/route evidence. -Do not create a second source of truth through hand-edited runtime state or an -uncommitted mystery file. A manual restart may be an emergency diagnostic action, -but the durable repair belongs in IaC and must converge after re-apply. If live -state cannot be reconstructed from the elected declaration, stop and reconcile -that drift before making another change. +Keep one canonical ordered declaration set in the elected IaC repository; it may +contain multiple `.apsu` files. A host-side `.apsu` is only an optional +convenience mirror: keep it at one predictable path, prove it byte-identical to +the reviewed revision before use, and remove temporary inspection or deployment +copies. Do not create a second source of truth through hand-edited runtime state +or an uncommitted mystery file. + +If the elected declaration is missing, stop and recover its reviewed repository +revision or ask the owner for it. A control-plane backup may restore the server's +canonical desired state, but it is not a supported `.apsu` export; never generate +replacement IaC from a backup, SQLite, or inferred live state. A manual restart +may be an emergency diagnostic action, but the durable repair belongs in IaC and +must converge after re-apply. ## Install and update