removedInput schema / $schema
Removed value: -"http://json-schema.org/draft-07/schema#"
removedInput schema / additionalProperties
Removed value: -false
removedInput schema / properties / aws / additionalProperties
Removed value: -false
removedInput schema / properties / aws / properties / cloudAccountLink / minLength
Removed value: -1
removedInput schema / properties / aws / properties / policyRefs / items / pattern
Removed value: -"^(aws::)?([a-zA-Z0-9/+=,.@_-])+$"
removedInput schema / properties / aws / properties / roleName / maxLength
Removed value: -64
removedInput schema / properties / aws / properties / roleName / pattern
Removed value: -"^([a-zA-Z0-9/+=,.@_-])+$"
removedInput schema / properties / aws / properties / trustPolicy / additionalProperties
Removed value: -false
removedInput schema / properties / aws / properties / trustPolicy / properties / Statement / items / additionalProperties
Removed value: -{}
removedInput schema / properties / aws / properties / trustPolicy / properties / Version / minLength
Removed value: -1
removedInput schema / properties / azure / additionalProperties
Removed value: -false
removedInput schema / properties / azure / properties / cloudAccountLink / minLength
Removed value: -1
removedInput schema / properties / azure / properties / roleAssignments / items / additionalProperties
Removed value: -false
removedInput schema / properties / azure / properties / roleAssignments / items / properties / roles / items / minLength
Removed value: -1
removedInput schema / properties / azure / properties / roleAssignments / items / properties / roles / minItems
Removed value: -1
removedInput schema / properties / azure / properties / roleAssignments / items / properties / scope / minLength
Removed value: -1
removedInput schema / properties / description / maxLength
Removed value: -250
removedInput schema / properties / gcp / additionalProperties
Removed value: -false
removedInput schema / properties / gcp / properties / bindings / items / additionalProperties
Removed value: -false
removedInput schema / properties / gcp / properties / bindings / items / properties / resource / minLength
Removed value: -1
removedInput schema / properties / gcp / properties / bindings / items / properties / roles / items / pattern
Removed value: -"^roles\\/([a-zA-Z0-9])+(\\.([a-zA-Z0-9])+)?$"
removedInput schema / properties / gcp / properties / bindings / items / properties / roles / minItems
Removed value: -1
removedInput schema / properties / gcp / properties / cloudAccountLink / minLength
Removed value: -1
removedInput schema / properties / gcp / properties / scopes / items / minLength
Removed value: -1
removedInput schema / properties / gcp / properties / serviceAccount / pattern
Removed value: -"^.+@.+\\.gserviceaccount\\.com$"
changedInput schema / properties / gvc / description
Previous value: -"GVC slug (lowercase kebab-case). Use the GVC the user named; otherwise discover with list_resources (kind=\"gvc\") and let them choose — never guess (a wrong GVC targets the wrong environment)."New value: +"GVC slug. If the user named none, list_resources (kind \"gvc\") and let them choose."
removedInput schema / properties / gvc / maxLength
Removed value: -63
removedInput schema / properties / gvc / minLength
Removed value: -1
removedInput schema / properties / gvc / pattern
Removed value: -"^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$"
removedInput schema / properties / memcacheAccess / items / additionalProperties
Removed value: -false
removedInput schema / properties / memcacheAccess / items / properties / clusterLink / minLength
Removed value: -1
removedInput schema / properties / memcacheAccess / maxItems
Removed value: -5
changedInput schema / properties / name / description
Previous value: -"Resource name (lowercase kebab-case, starts with a letter, 2-64 chars). Names are IMMUTABLE — renaming = delete + recreate (loses URL, DNS, policy links)."New value: +"Resource name. Immutable: renaming is delete and recreate."
removedInput schema / properties / name / maxLength
Removed value: -64
removedInput schema / properties / name / minLength
Removed value: -2
removedInput schema / properties / name / pattern
Removed value: -"^[a-z]([-a-z0-9])*[a-z0-9]$"
changedInput schema / properties / nativeNetworkResources / description
Previous value: -"Optional replacement for the full nativeNetworkResources array (wholesale). Each item requires name, ports, and exactly one provider block."New value: +"Optional replacement for the full nativeNetworkResources array (wholesale). Each item requires name, ports, and exactly one provider block. Shape: [{name, FQDN, ports: [], and exactly one of awsPrivateLink {endpointServiceName} or gcpServiceConnect {targetService: projects/PROJECT/regions/REGION/serviceAttachments/NAME}}]."
removedInput schema / properties / nativeNetworkResources / items / additionalProperties
Removed value: -false
removedInput schema / properties / nativeNetworkResources / items / description
Removed value: -"Cloud-native network resource. Required: name, ports, and exactly one provider block: awsPrivateLink or gcpServiceConnect. FQDN is optional and should be set when TLS clients must validate the target certificate."
removedInput schema / properties / nativeNetworkResources / items / properties
Removed value: -{
- "FQDN": {
- "description": "Optional FQDN override. If the target serves TLS, connect via this FQDN — the `name` hostname fails certificate validation.",
- "pattern": "^(?=.{1,253}$)([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]([a-z0-9-]{0,61}[a-z0-9])?$",
- "type": "string"
- },
- "awsPrivateLink": {
- "additionalProperties": false,
- "description": "AWS PrivateLink endpoint service. Mutually exclusive with gcpServiceConnect.",
- "properties": {
- "endpointServiceName": {
- "description": "Endpoint service name, e.g. com.amazonaws.vpce.<region>.vpce-svc-<id> (the platform enforces no format).",
- "minLength": 1,
- "type": "string"
- }
- },
- "required": [
- "endpointServiceName"
- ],
- "type": "object"
- },
- "gcpServiceConnect": {
- "additionalProperties": false,
- "description": "GCP Private Service Connect target (projects/PROJECT/regions/REGION/serviceAttachments/NAME). Mutually exclusive with awsPrivateLink. For Cloud SQL the instance must allow `cpln-prod01` as a PSC consumer project — PSC cannot be enabled from the GCP console (use gcloud or the API).",
- "properties": {
- "targetService": {
- "pattern": "^\\/?projects\\/(.+)\\/regions\\/(.+)\\/serviceAttachments\\/(.+)\\/?$",
- "type": "string"
- }
- },
- "required": [
- "targetService"
- ],
- "type": "object"
- },
- "name": {
- "description": "Required hostname workloads will dial for this native network resource; use a lowercase slug or domain.",
- "minLength": 1,
- "type": "string"
- },
- "ports": {
- "description": "Required TCP ports exposed by the PrivateLink or PSC target. Example: [5432].",
- "items": {
- "maximum": 65535,
- "minimum": 0,
- "type": "integer"
- },
- "maxItems": 10,
- "minItems": 1,
- "type": "array"
- }
-}
removedInput schema / properties / nativeNetworkResources / items / required
Removed value: -[
- "name",
- "ports"
-]
removedInput schema / properties / nativeNetworkResources / maxItems
Removed value: -50
changedInput schema / properties / networkResources / description
Previous value: -"Replace the full networkResources array (wholesale)."New value: +"Replace the full networkResources array (wholesale). Shape: [{name, agentLink, IPs: [ipv4] or FQDN, resolverIP, ports: []}]."
removedInput schema / properties / networkResources / items / additionalProperties
Removed value: -false
removedInput schema / properties / networkResources / items / properties
Removed value: -{
- "FQDN": {
- "description": "Fully qualified domain name. Mutually exclusive with IPs — bare IPs belong in IPs[]. If the target serves TLS, connect via this FQDN — the `name` hostname fails certificate validation.",
- "pattern": "^(?=.{1,253}$)([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]([a-z0-9-]{0,61}[a-z0-9])?$",
- "type": "string"
- },
- "IPs": {
- "description": "1-5 IPv4 addresses. Mutually exclusive with FQDN.",
- "items": {
- "pattern": "^(?:(?:25[0-5]|2[0-4]\\d|[01]?\\d?\\d)\\.){3}(?:25[0-5]|2[0-4]\\d|[01]?\\d?\\d)$",
- "type": "string"
- },
- "maxItems": 5,
- "minItems": 1,
- "type": "array"
- },
- "agentLink": {
- "description": "Agent that serves this resource (//agent/NAME or /org/ORG/agent/NAME). Optional per the platform schema.",
- "pattern": "^(\\/\\/agent\\/[a-z0-9-]+|\\/org\\/[a-z0-9-]+\\/agent\\/[a-z0-9-]+)$",
- "type": "string"
- },
- "name": {
- "description": "Unique resource name — lowercase slug or domain (becomes the hostname workloads dial).",
- "minLength": 1,
- "type": "string"
- },
- "ports": {
- "description": "Required list of 1-10 TCP ports, each 0-65535. Duplicates are removed and the list is sorted.",
- "items": {
- "maximum": 65535,
- "minimum": 0,
- "type": "integer"
- },
- "maxItems": 10,
- "minItems": 1,
- "type": "array"
- },
- "resolverIP": {
- "description": "Optional custom DNS resolver IPv4.",
- "pattern": "^(?:(?:25[0-5]|2[0-4]\\d|[01]?\\d?\\d)\\.){3}(?:25[0-5]|2[0-4]\\d|[01]?\\d?\\d)$",
- "type": "string"
- }
-}
removedInput schema / properties / networkResources / items / required
Removed value: -[
- "name",
- "ports"
-]
removedInput schema / properties / networkResources / maxItems
Removed value: -50
removedInput schema / properties / ngs / additionalProperties
Removed value: -false
changedInput schema / properties / ngs / description
Previous value: -"Replace the NGS cloud-identity block (full object — it replaces wholesale)."New value: +"Replace the NGS cloud-identity block (full object; it replaces wholesale). Shape: {cloudAccountLink, pub: {allow: [], deny: []}, sub: {allow: [], deny: []}, resp: {max, ttl}, subs, data, payload}; -1 means no limit."
removedInput schema / properties / ngs / properties
Removed value: -{
- "cloudAccountLink": {
- "description": "Link to the NGS (nats-account) cloud account.",
- "minLength": 1,
- "type": "string"
- },
- "data": {
- "description": "Maximum data quota. -1 means no limit.",
- "minimum": -1,
- "type": "integer"
- },
- "payload": {
- "description": "Maximum payload size. -1 means no limit.",
- "minimum": -1,
- "type": "integer"
- },
- "pub": {
- "additionalProperties": false,
- "description": "Publish permissions.",
- "properties": {
- "allow": {
- "description": "NATS subjects this identity may access (e.g. \"orders.>\", \"events.*.created\").",
- "items": {
- "minLength": 1,
- "type": "string"
- },
- "type": "array"
- },
- "deny": {
- "description": "NATS subjects explicitly denied to this identity.",
- "items": {
- "minLength": 1,
- "type": "string"
- },
- "type": "array"
- }
- },
- "type": "object"
- },
- "resp": {
- "additionalProperties": false,
- "description": "Response constraints.",
- "properties": {
- "max": {
- "description": "Maximum responses per request. -1 means no limit. The platform defaults this to 1 when resp is set.",
- "minimum": -1,
- "type": "integer"
- },
- "ttl": {
- "description": "Response TTL (e.g., \"5s\"). Format: #ms | #s | #m | #h.",
- "pattern": "^[0-9]+(ms|s|m|h)$",
- "type": "string"
- }
- },
- "type": "object"
- },
- "sub": {
- "additionalProperties": false,
- "description": "Subscribe permissions.",
- "properties": {
- "allow": {
- "description": "NATS subjects this identity may access (e.g. \"orders.>\", \"events.*.created\").",
- "items": {
- "minLength": 1,
- "type": "string"
- },
- "type": "array"
- },
- "deny": {
- "description": "NATS subjects explicitly denied to this identity.",
- "items": {
- "minLength": 1,
- "type": "string"
- },
- "type": "array"
- }
- },
- "type": "object"
- },
- "subs": {
- "description": "Maximum simultaneous subscriptions. -1 means no limit.",
- "minimum": -1,
- "type": "integer"
- }
-}
removedInput schema / properties / ngs / required
Removed value: -[
- "cloudAccountLink"
-]
changedInput schema / properties / org / description
Previous value: -"Organization slug (lowercase kebab-case). NEVER guess — if the user has not named one, ask. On org-not-found, stop and ask; do not retry variants."New value: +"Organization slug."
removedInput schema / properties / org / maxLength
Removed value: -63
removedInput schema / properties / org / minLength
Removed value: -1
removedInput schema / properties / org / pattern
Removed value: -"^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$"
removedInput schema / properties / removeTagKeys / items / minLength
Removed value: -1
removedInput schema / properties / spicedbAccess / items / additionalProperties
Removed value: -false
removedInput schema / properties / spicedbAccess / items / properties / clusterLink / minLength
Removed value: -1
removedInput schema / properties / spicedbAccess / maxItems
Removed value: -5
removedInput schema / properties / tags / items / additionalProperties
Removed value: -false
removedInput schema / properties / tags / items / properties / key / minLength
Removed value: -1
removedInput schema / properties / tags / maxItems
Removed value: -50
changedInput schema / required
Previous value: -[
- "org",
- "gvc",
- "name"
-]New value: +[
+ "gvc",
+ "name"
+]
removedOutput schema / $schema
Removed value: -"http://json-schema.org/draft-07/schema#"
removedOutput schema / additionalProperties
Removed value: -false
changedOutput schema / properties / data / description
Previous value: -"The full machine-readable result — list rows, the resource object, query results. Read THIS, not just the summary."New value: +"The full result. Read this, not only the summary."
addedOutput schema / properties / details
Added value: +{
+ "type": "string"
+}
removedOutput schema / properties / nextSteps / description
Removed value: -"Recommended follow-up actions for this task, in order."
removedOutput schema / properties / ok / description
Removed value: -"Whether the call succeeded."
removedOutput schema / properties / summary / description
Removed value: -"One-line summary of the result."