{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "urn:bmp:schema:bmp.manifest:v1",
  "title": "BMP run manifest (bmp.manifest/v1)",
  "description": "The commit marker of one backup run (FR-STO.5, FR-DR.1, storage section 5.4). Stored as RFC 8785 canonical JSON and signed with Ed25519 over the canonical form without the signature member (storage section 5.5). Plaintext metadata only: no key, password, wrapped key or plaintext hash of an encrypted payload ever appears in it.",
  "type": "object",
  "additionalProperties": false,
  "required": ["schema", "platform", "run", "artifacts", "retention", "chain", "signature"],
  "properties": {
    "schema": { "const": "bmp.manifest/v1" },
    "platform": {
      "type": "object",
      "additionalProperties": false,
      "required": ["instanceId", "version"],
      "properties": {
        "instanceId": { "type": "string", "pattern": "^[0-9a-f]{32}$" },
        "version": { "type": "string", "pattern": "^[0-9A-Za-z.+-]+$" }
      }
    },
    "run": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "id", "planId", "planName", "planKey", "serverId", "serverName", "serverKey", "environment", "trigger",
        "attempt", "parentRunId", "startedUtc", "finishedUtc", "status", "failedSources", "safetySnapshotFor"
      ],
      "properties": {
        "id": { "$ref": "#/$defs/uuid" },
        "planId": { "$ref": "#/$defs/uuid" },
        "planName": { "type": "string" },
        "planKey": { "$ref": "#/$defs/keySegment" },
        "serverId": { "$ref": "#/$defs/uuid" },
        "serverName": { "type": "string" },
        "serverKey": { "$ref": "#/$defs/keySegment" },
        "environment": { "$ref": "#/$defs/keySegment" },
        "trigger": { "enum": ["Manual", "Schedule", "Api", "Retry", "Drill"] },
        "attempt": { "type": "integer", "minimum": 1 },
        "parentRunId": { "$ref": "#/$defs/uuidOrNull" },
        "startedUtc": { "$ref": "#/$defs/utc" },
        "finishedUtc": { "$ref": "#/$defs/utc" },
        "status": { "enum": ["Succeeded", "SucceededWithWarnings", "Failed", "Cancelled", "Interrupted"] },
        "failedSources": {
          "type": "array",
          "items": {
            "type": "object",
            "additionalProperties": false,
            "required": ["sourceId", "sourceName", "errorCode"],
            "properties": {
              "sourceId": { "$ref": "#/$defs/uuid" },
              "sourceName": { "type": ["string", "null"] },
              "errorCode": { "type": "string", "pattern": "^[A-Za-z0-9]+$" }
            }
          }
        },
        "safetySnapshotFor": { "$ref": "#/$defs/uuidOrNull" }
      }
    },
    "artifacts": {
      "type": "array",
      "minItems": 1,
      "items": { "$ref": "#/$defs/artifact" }
    },
    "retention": {
      "type": ["object", "null"],
      "additionalProperties": false,
      "required": ["policy", "mode", "lockMode", "retainUntilUtc"],
      "properties": {
        "policy": { "type": "string" },
        "mode": { "enum": ["Count", "Age", "Gfs", "Forever"] },
        "lockMode": { "$ref": "#/$defs/lockMode" },
        "retainUntilUtc": { "$ref": "#/$defs/utcOrNull" }
      }
    },
    "chain": {
      "type": "object",
      "additionalProperties": false,
      "required": ["type", "parentRunId"],
      "properties": {
        "type": { "const": "full" },
        "parentRunId": { "$ref": "#/$defs/uuidOrNull" }
      }
    },
    "compose": {
      "description": "The compose projects the run captured, each one restore point (pipeline section 11.6); null, or absent in manifests written before it, when it captured none.",
      "type": ["array", "null"],
      "items": { "$ref": "#/$defs/composeProject" }
    },
    "signature": {
      "type": "object",
      "additionalProperties": false,
      "required": ["alg", "keyId", "canonicalization", "value"],
      "properties": {
        "alg": { "const": "Ed25519" },
        "keyId": { "$ref": "#/$defs/uuid" },
        "canonicalization": { "const": "RFC8785" },
        "value": { "type": "string", "pattern": "^[A-Za-z0-9+/]{86}==$" }
      }
    }
  },
  "$defs": {
    "uuid": { "type": "string", "pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$" },
    "uuidOrNull": {
      "type": ["string", "null"],
      "pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"
    },
    "utc": { "type": "string", "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}Z$" },
    "utcOrNull": { "type": ["string", "null"], "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}Z$" },
    "keySegment": { "type": "string", "pattern": "^[a-z0-9._-]{1,255}$" },
    "sha256": { "type": "string", "pattern": "^[0-9a-f]{64}$" },
    "sha256OrNull": { "type": ["string", "null"], "pattern": "^[0-9a-f]{64}$" },
    "lockMode": { "enum": ["None", "Governance", "Compliance"] },
    "composeProject": {
      "type": "object",
      "additionalProperties": false,
      "required": ["sourceId", "project", "workingDir", "configFiles", "startOrder", "services", "volumes", "envFileIncluded", "databaseSources"],
      "properties": {
        "sourceId": { "$ref": "#/$defs/uuid" },
        "project": { "type": "string", "pattern": "^[a-z0-9][a-z0-9_-]{0,62}$" },
        "workingDir": { "type": "string" },
        "configFiles": { "type": "array", "items": { "type": "string" } },
        "startOrder": { "type": "array", "items": { "type": "string" } },
        "services": {
          "type": "array",
          "items": {
            "type": "object",
            "additionalProperties": false,
            "required": ["service", "container", "image", "imageDigest", "dependsOn"],
            "properties": {
              "service": { "type": "string" },
              "container": { "type": "string" },
              "image": { "type": "string" },
              "imageDigest": { "type": ["string", "null"] },
              "dependsOn": { "type": "array", "items": { "type": "string" } }
            }
          }
        },
        "volumes": { "type": "array", "items": { "type": "string" } },
        "envFileIncluded": { "type": "boolean" },
        "databaseSources": { "type": "array", "items": { "$ref": "#/$defs/uuid" } }
      }
    },
    "artifact": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "id", "key", "fileName", "sourceId", "sourceType", "sourceName", "container", "database", "tool", "archiveFormat",
        "layers", "compression", "encryption", "sizeBytes", "plainSizeBytes", "sha256", "payloadSha256", "storage",
        "fileIndex", "droppedEntries", "restoreHints"
      ],
      "properties": {
        "id": { "$ref": "#/$defs/uuid" },
        "key": { "type": "string", "pattern": "^[a-z0-9._/-]{1,1024}$" },
        "fileName": { "type": "string", "pattern": "^[a-z0-9._-]{1,255}$" },
        "sourceId": { "$ref": "#/$defs/uuidOrNull" },
        "sourceType": {
          "enum": [
            "Folder", "File", "DockerVolume", "DockerContainerFilesystem", "DockerImage", "ComposeProject",
            "PodmanVolume", "PodmanContainerFilesystem", "Database", "ConfigFiles", "CustomCommand", null
          ]
        },
        "sourceName": { "type": ["string", "null"] },
        "container": {
          "type": ["object", "null"],
          "additionalProperties": false,
          "required": ["runtime", "name", "imageDigest"],
          "properties": {
            "runtime": { "type": "string" },
            "name": { "type": "string" },
            "imageDigest": { "type": ["string", "null"] }
          }
        },
        "database": {
          "type": ["object", "null"],
          "additionalProperties": false,
          "required": [
            "engine", "engineVersion", "edition", "variants", "databaseNames", "backupMode", "consistencyMode",
            "dumpFormat", "commandProfileVersion", "facts"
          ],
          "properties": {
            "engine": { "type": "string" },
            "engineVersion": { "type": ["string", "null"] },
            "edition": { "type": ["string", "null"] },
            "variants": { "type": "array", "items": { "type": "string" } },
            "databaseNames": { "type": "array", "items": { "type": "string" } },
            "backupMode": { "type": ["string", "null"] },
            "consistencyMode": { "type": ["string", "null"] },
            "dumpFormat": { "type": ["string", "null"] },
            "commandProfileVersion": { "type": ["integer", "null"], "minimum": 1 },
            "facts": { "type": ["object", "null"], "additionalProperties": { "type": "string" } }
          }
        },
        "tool": {
          "type": ["object", "null"],
          "additionalProperties": false,
          "required": ["name", "version", "context", "image"],
          "properties": {
            "name": { "type": "string" },
            "version": { "type": ["string", "null"] },
            "context": { "type": ["string", "null"] },
            "image": { "type": ["string", "null"] }
          }
        },
        "archiveFormat": { "enum": ["Native", "Tar", "TarGz", "TarZst", "TarXz", "TarBz2", "Zip", "SevenZip"] },
        "layers": { "type": "array", "items": { "type": "string", "pattern": "^[a-z0-9-]+$" } },
        "compression": {
          "type": "object",
          "additionalProperties": false,
          "required": ["algorithm", "level", "location"],
          "properties": {
            "algorithm": { "enum": ["None", "Gzip", "Zstd", "Xz", "Bzip2", "Deflate", "Lzma2"] },
            "level": { "enum": ["Fastest", "Fast", "Balanced", "High", "Maximum", null] },
            "location": { "enum": ["Remote", "Platform", "None"] }
          }
        },
        "encryption": {
          "type": "object",
          "additionalProperties": false,
          "required": ["mode", "envelope", "keyId", "keyVersion", "keyFingerprint", "recipientFingerprints", "recoveryStanza"],
          "properties": {
            "mode": { "enum": ["None", "PlatformKey", "Password", "PublicKey"] },
            "envelope": { "enum": ["BMENC/1", "OpenPGP", "ZipAes", "SevenZipAes", null] },
            "keyId": { "$ref": "#/$defs/uuidOrNull" },
            "keyVersion": { "type": ["integer", "null"], "minimum": 1 },
            "keyFingerprint": { "type": ["string", "null"] },
            "recipientFingerprints": { "type": "array", "items": { "type": "string" } },
            "recoveryStanza": { "type": "boolean" }
          }
        },
        "sizeBytes": { "type": "integer", "minimum": 0 },
        "plainSizeBytes": { "type": ["integer", "null"], "minimum": 0 },
        "sha256": { "$ref": "#/$defs/sha256" },
        "payloadSha256": { "$ref": "#/$defs/sha256OrNull" },
        "storage": {
          "type": "object",
          "additionalProperties": false,
          "required": ["versionId", "etag", "partSizeBytes", "partCount", "objectLockMode", "retainUntilUtc"],
          "properties": {
            "versionId": { "type": ["string", "null"] },
            "etag": { "type": ["string", "null"] },
            "partSizeBytes": { "type": ["integer", "null"], "minimum": 1 },
            "partCount": { "type": ["integer", "null"], "minimum": 1 },
            "objectLockMode": { "$ref": "#/$defs/lockMode" },
            "retainUntilUtc": { "$ref": "#/$defs/utcOrNull" }
          }
        },
        "fileIndex": {
          "type": ["object", "null"],
          "additionalProperties": false,
          "required": ["key", "sizeBytes", "sha256"],
          "properties": {
            "key": { "type": "string", "pattern": "^[a-z0-9._/-]{1,1024}$" },
            "sizeBytes": { "type": "integer", "minimum": 0 },
            "sha256": { "$ref": "#/$defs/sha256" }
          }
        },
        "droppedEntries": {
          "type": ["array", "null"],
          "items": {
            "type": "object",
            "additionalProperties": false,
            "required": ["path", "code", "reason"],
            "properties": {
              "path": { "type": "string" },
              "code": { "type": "string" },
              "reason": { "type": "string" }
            }
          }
        },
        "restoreHints": {
          "type": ["object", "null"],
          "additionalProperties": false,
          "required": ["tool", "argv"],
          "properties": {
            "tool": { "type": "string" },
            "argv": { "type": "array", "items": { "type": "string" } }
          }
        }
      }
    }
  }
}
