httk.core.project¶
The httk project anchor and the umbrella httk project command.
A project is a directory marked at its root by a .httk-project control
directory, discovered by walking upward exactly as git finds a .git.
This package owns that anchor — creating it, reading and validating its
project.json, and managing its Ed25519 identity and trust anchors — and the
extensible httk project command that operates on it. It creates no
workflow workspace; that is layered on by a workflow installation.
The anchor API is re-exported here for convenience; the command and its
extension registry live in httk.core.project.cli.
Submodules¶
Attributes¶
Functions¶
|
Normalize any accepted public key spelling to the recorded one. |
|
Find the nearest project root at or above start. |
|
Return the recorded representation of one raw Ed25519 public key. |
|
Create the project anchor from a legacy |
|
Initialize the project anchor: its metadata, its key, and its remotes dir. |
|
Return the stable display fingerprint of one public key. |
|
Decode a recorded public key, accepting the bare base64 spelling too. |
|
Adopt the project's current |
|
Return the project's own pinned public key, or |
|
Return where a project keeps its own signing key's public half. |
|
Read and validate the |
|
Return one named object member of |
|
Read one |
|
Return the nearest project root, refusing when there is none. |
|
Adopt one further public key as a trust anchor of this project. |
|
Return every key metadata pins: the project's own and any adopted one. |
|
Store one named object member of |
Package Contents¶
- httk.core.project.canonical_public_key(value: str) str[source]¶
Normalize any accepted public key spelling to the recorded one.
- httk.core.project.discover_project(start: str | os.PathLike[str] | None = None) pathlib.Path | None[source]¶
Find the nearest project root at or above start.
- httk.core.project.format_public_key(raw: bytes) str[source]¶
Return the recorded representation of one raw Ed25519 public key.
- httk.core.project.import_v1_project(root: str | os.PathLike[str], *, source: str | os.PathLike[str] | None = None, name: str | None = None) dict[str, object][source]¶
Create the project anchor from a legacy
ht.projectdirectory.Only the anchor is created: the project’s metadata and the adoption of the legacy identities its old manifests were signed with. A workflow installation adds the workspace and any queue import on top of this.
- httk.core.project.initialize_project(root: str | os.PathLike[str], *, name: str, description: str = '', default_queue: str | None = None, manifest_exclusions: collections.abc.Iterable[str] = ()) dict[str, object][source]¶
Initialize the project anchor: its metadata, its key, and its remotes dir.
This creates only the anchor —
.httk-projectwithproject.json, the project’s Ed25519 signing key, and theremotesdirectory. It creates no workflow workspace; a workflow installation layers that on top of the anchor so that a core-only installation still has a working project.
- httk.core.project.key_fingerprint(value: str) str[source]¶
Return the stable display fingerprint of one public key.
- httk.core.project.parse_public_key(value: str) bytes[source]¶
Decode a recorded public key, accepting the bare base64 spelling too.
- httk.core.project.pin_project_key(root: str | os.PathLike[str] | None = None) dict[str, object][source]¶
Adopt the project’s current
keys/project.pubas its trust anchor.Pinning is always an explicit act. Verification trusts the key recorded in
project.jsonand never the key a manifest carries in its own header, so adopting the key that is in the tree right now is exactly the decision an operator has to make consciously for an older project that has no pin.
- httk.core.project.pinned_project_key(metadata: collections.abc.Mapping[str, object]) str | None[source]¶
Return the project’s own pinned public key, or
Nonewhen absent.
- httk.core.project.project_public_key_path(root: str | os.PathLike[str]) pathlib.Path[source]¶
Return where a project keeps its own signing key’s public half.
- httk.core.project.read_project(root: str | os.PathLike[str]) dict[str, object][source]¶
Read and validate the
project.jsonof the project rooted at root.
- httk.core.project.read_project_section(root: str | os.PathLike[str], name: str) dict[str, object][source]¶
Return one named object member of
project.json, empty when absent.A section is a top-level member of the project manifest that some layer above the anchor owns — the workflow workspace registry, a campaign map — and reads and writes as a whole. The anchor does not interpret the member; it only guarantees that what a caller stores under a name comes back as the object it was, and refuses a member that some other writer has left as a non-object so a caller never silently reads a scalar as a mapping.
- httk.core.project.read_public_key_file(path: str | os.PathLike[str]) str[source]¶
Read one
*.pubfile and return its recorded public key.
- httk.core.project.require_project(start: str | os.PathLike[str] | None = None) pathlib.Path[source]¶
Return the nearest project root, refusing when there is none.
- httk.core.project.trust_project_key(root: str | os.PathLike[str] | None, key: str) dict[str, object][source]¶
Adopt one further public key as a trust anchor of this project.
- httk.core.project.trusted_project_keys(metadata: collections.abc.Mapping[str, object]) tuple[str, Ellipsis][source]¶
Return every key metadata pins: the project’s own and any adopted one.
The pinned key of
project.jsonis the trust anchor a manifest is checked against.trusted_keyscarries the additional anchors an operator has adopted deliberately — most often the legacy identities an imported httk v1 project signed its old manifests with.
- httk.core.project.write_project_section(root: str | os.PathLike[str], name: str, value: collections.abc.Mapping[str, object]) dict[str, object][source]¶
Store one named object member of
project.jsonand return the metadata.The write is an ordinary read-modify-write of the validated manifest, so the members the anchor owns are preserved untouched and only the named section is replaced. The section must be a mapping; the anchor stores its members verbatim without interpreting them.