Reference
dev.git_binding
domain: devkind: record
a developer TENANT's binding to a Git repository the developer controls. The Tenant Admin configures this once; the git-publisher engine (S2+) then mirrors every component published in the tenant (and, optionally, project manifests) into this repo. The credential is NEVER stored here in the clear: `credential_ref` names a Vault secret (deploy key / fine-grained PAT). One active binding per tenant (id ds:{tenant}:dev/git_binding/default).
| Field | Type | Required | Description |
|---|---|---|---|
schema | โ | โ | |
id | string | โ | |
tenant | string | the developer tenant this binding belongs to; pushes go ONLY to this repo | |
repo_url | string | โ | the developer-owned Git remote, e.g. https://github.com/<owner>/<repo>.git |
host | string/null | git host derived from repo_url (e.g. github.com); added to the tenant's broker egress allow-list | |
default_branch | string | branch the publisher pushes to | |
path_convention | string | where each component's source is laid out in the repo (mirrors the components repo layout by default) | |
credential_ref | string | โ | Vault secret id holding the deploy key / PAT โ the token itself is NEVER stored in the registry |
credential_kind | string/null | how to authenticate to the remote | |
include_project_manifest | boolean | also commit the studio.project graph as JSON, so authoring state is versioned | |
status | string | draft until Test connection succeeds; error if a push/auth fails | |
last_test | object/null | {at, ok, detail} โ result of the most recent Test connection | |
last_push | object/null | {at, commit, component_id} โ most recent successful publisher push (set by the git-publisher engine, S2+) | |
created_by | string/null | ||
created_at | string/null | ||
updated_by | string/null | ||
updated_at | string/null |