Treat Ledger as the source of truth for workflow identity, validated definition,
and revision history. Use yy ledger in a YYLO controller or yylo-ledger
standalone. Inspect COMMAND workflow --help; if the namespace is absent, do not
invent it or edit Ledger storage directly.
The read-only Ledger host also has no workflow execution endpoint.
yy ledger workflow search --text "release verification" --projection summary --limit 20 -f json
yy ledger workflow get RECORD_ID -f json
yy ledger workflow get RECORD_ID --raw
yy ledger workflow get RECORD_ID --validated
Prefer immutable IDs after discovery. Use bounded projections and explicit archive
scope. --validated emits normalized YAML only after schema validation.
A workflow v1 document requires a mapping with schema_version: v1, a non-empty
workflow_id, and a steps list whose step IDs are non-empty and unique.
schema_version: v1
workflow_id: focused-validation
steps:
- id: test
command: ["npm", "test"]
Create through file/stdin transport:
yy ledger workflow create --title "Focused validation" --file workflow.yaml
Ledger rejects unsafe or non-portable YAML, including duplicate keys, aliases, anchors, explicit tags, recursive structures, non-string mapping keys, implicit date/time values, non-finite numbers, CRLF input, and unsupported values. Never weaken validation by storing executable shell as an unvalidated substitute.
Read the current revision and history, then follow the installed
workflow update --help compare-and-replace contract. Bind updates to the
expected revision and preimage/digests, validate the result, and read it back.
On drift, stop and reconcile instead of forcing. Archive is non-destructive.
Before execution, freeze the exact workflow Record ID, revision, payload digest,
runner identity, inputs, and granted authorities. After execution, store bounded
outputs under artifact-yylo with workflow/run provenance. An execution request
never implies merge, release, publication, deployment, or production authority.
$ARGUMENTS
artifact-yylo records with workflow/run provenance - never overwrite the workflow definition with outputs.yy ledger workflow search --text "release verification" --projection summary --limit 20 -f json
yy ledger workflow get RECORD_ID --validated
Adapted from yylo-dev/yylo-skills (MIT) - v2.0.1; frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance.