@zephytiju/juntai-typescript-sdk
v3.8.0
Published
Aggregate generated TypeScript clients for Console-facing Juntai services
Readme
Juntai TypeScript SDK
@zephytiju/juntai-typescript-sdk is the single aggregate npm package for generated clients of Console-facing Juntai services. It consumes reviewed, immutable, service-owned OpenAPI artifacts and publishes all approved clients under collision-free full-service-ID subpaths.
npm install @zephytiju/juntai-typescript-sdkimport { createClient as createDefinitionClient } from "@zephytiju/juntai-typescript-sdk/services/axiom.definition";
import { createClient as createOperationsClient } from "@zephytiju/juntai-typescript-sdk/services/axiom.operations";
import { createClient } from "@zephytiju/juntai-typescript-sdk/services/platform.application-metadata";
import { createClient as createAccountClient } from "@zephytiju/juntai-typescript-sdk/services/platform.account";
import { createClient as createBlueprintClient } from "@zephytiju/juntai-typescript-sdk/services/platform.blueprint";
import { createClient as createIamClient } from "@zephytiju/juntai-typescript-sdk/services/platform.iam";
import { createClient as createVanguDeploymentClient } from "@zephytiju/juntai-typescript-sdk/services/platform.vangu-deployment";
import { createClient as createUsageCostClient } from "@zephytiju/juntai-typescript-sdk/services/juntai.usage-cost";
import { createClient as createPrismCompositionClient } from "@zephytiju/juntai-typescript-sdk/services/prism.composition";
import { createClient as createPrismBuildClient } from "@zephytiju/juntai-typescript-sdk/services/prism.build";
import { createClient as createLatticeOntologyClient } from "@zephytiju/juntai-typescript-sdk/services/lattice.ontology";
import { createClient as createLatticeGenerationClient } from "@zephytiju/juntai-typescript-sdk/services/lattice.runtime-generation";All imports resolve from this one aggregate dependency; there are no service-specific npm packages. Account exposes opaque Account/v1, AccountProfile/v1, integration-binding, stable-error, authorization-action, idempotency, and concurrency contracts. Application Metadata includes the exact application-documentation discovery contract, Blueprint exposes only the Console-facing Blueprint Service API, IAM exposes the exact same-origin account and immutable-application administration contract, and Vangu Deployment exposes authorized target inspection plus immutable PREVIEW, APPLY, and REMOVE execution control.
Axiom Definition exposes generated pipeline creation and discovery, revision history, validation, readiness, release, and release-search contracts. Axiom Operations exposes generated execution and production-activity discovery, import validation and submission, checkpoint inspection, source-gap search, redrive, and waiver contracts. Both clients preserve the owning services' required tenant, request, authorization, idempotency, cursor, and stable-error types without handwritten Axiom DTOs.
Prism Composition exposes Operating System and UI-page authoring, exact revisions, layout-variant application, and Ready for release. Prism Build exposes build creation, lookup, pagination, and deliberate retry for exact Ready-for-release revisions with [email protected]; historical [email protected] requests and receipts remain supported. Inject context.fetch and the reviewed same-origin gateway base URL for each service. Draft mutations preserve If-Match; commands preserve Idempotency-Key. After an ambiguous response, recover by the existing operation identity instead of automatically replaying the command. A successful build confirms publication and association; application sealing and deployment remain with Application Metadata and Vangu.
Version 3.8.0 adds resolveBuildSubmission from Build Service 1.3.0. Pass the original Idempotency-Key header and exact application_id path value to recover {build, identityExpiresAt} without a request body or query. SUBMISSION_NOT_FOUND is point-in-time absence; SUBMISSION_IDENTITY_EXPIRED is unresolved recovery. Neither permits automatic create/retry or payload matching. Preserve a scoped local identity before submitting, and keep it out of URLs and telemetry. The returned BuildView is authoritative under current application/build read access.
Version 3.7.0 pins Composition and Build Service 1.2.0. getUiPageDraft accepts includeAuthoring: true with blueprintAssetId, blueprintVersionId, and targetSlotId for an unplaced candidate, or instanceId for one saved instance; omitting selectors projects the current instances. Candidate discovery requires no prior binding fingerprint. The generated projection includes typed declarations, original Schema definitions (including boolean schemas), preset digests and explicit default absence. Save optional LayoutNodeInput.splitAllocation with version 1 and positive child-ID shares totaling 1000000; exact template validation and persistence belong to Composition. Allocated snapshots require Builder 1.2.0. Authorization, stale ETag, incompatible metadata and oversize errors remain visible to callers.
IAM consumers inject the session-aware fetch supplied by ConsolePageContext; the client neither owns credentials nor calls a protected origin directly:
const iam = createIamClient({
baseUrl: "/",
fetch: context.fetch,
});
const account = createAccountClient({
baseUrl: "/",
fetch: context.fetch,
});Lattice consumers
The package exposes latticeOntology and latticeRuntimeGeneration root namespaces, also available under clients["lattice.ontology"] and clients["lattice.runtime-generation"]. Their full service subpaths expose generated operations, types, and isolated factories from LatticeModelConfigurationService 0.4.0 and LatticeRuntimeGenerationService 0.1.0. sources/openapi.lock.json records each exact source revision, OpenAPI SHA-256, and output digest.
import { latticeOntology, latticeRuntimeGeneration } from "@zephytiju/juntai-typescript-sdk";
// Use the same-origin gateway paths reviewed for the host Console deployment.
const ontology = latticeOntology.createClient({ baseUrl: ontologyGatewayPath, fetch: context.fetch });
const generation = latticeRuntimeGeneration.createClient({ baseUrl: generationGatewayPath, fetch: context.fetch });
// Source selection is read-only and does not create an import plan.
const source = await latticeOntology.readBlueprintSource({
client: ontology,
path: { asset_id: assetId, version_id: exactVersionId },
query: { limit: 50 },
});
if (source.data) {
const selected = await latticeOntology.readBlueprintDefinition({
client: ontology,
path: { asset_id: assetId, version_id: exactVersionId, definition_id: definitionId },
query: { expected_digest: source.data.source_digest },
});
}
const preview = await latticeOntology.previewDefinitions({
client: ontology,
body: { bundle_id: bundleId, bundle_revision: revision, definition_ids: selectedDefinitionIds },
});
const operation = await latticeRuntimeGeneration.getGenerationOperation({
client: generation,
headers: { "X-Juntai-Application-ID": applicationId },
path: { generation_operation_id: operationId },
});Version 3.6.0 adds listBundleVersions, listDefinitionVersions, readBlueprintSource, and readBlueprintDefinition. Revision pages retain the first page’s through_revision on continuation; exact source pages retain source_digest as expected_digest. Source browsing returns bounded summaries; full definition reads preserve code authorization. Stale, missing, and denied reads remain typed errors. Blueprint discovery and exact resolution use the existing platform.blueprint contract.
Pass each factory instance through the operation's client option. Relative gateway paths work in the browser; server adapters use an absolute URL. Console owns session-aware fetch and rejects protected cross-origin calls. The SDK supplies neither session credentials nor gateway registration. Operations use the exact released flat names and snake_case request properties. Authoring commands preserve body expected_bundle_revision and idempotency_key; generation requires application scope and preserves exact reference versions, including Object version "1". Cancellation forwards If-Match when supplied, and evidence reads require expected_digest. Inspect returned data, error, response, and ETag; an accepted generation remains queued until authoritative lookup reports a terminal status. After an ambiguous command, recover using its existing identity instead of automatically replaying it.
npm run check:consumer installs a packed release into a clean directory, checks ESM exports and TypeScript declarations, bundles it for the browser without Node shims or runtime dependencies, and runs Chromium against explicit same-origin HTTP adapter fixtures. It exercises read-only source selection, digest-pinned pagination, exact definitions, authoring, preview/release, generation lookup/cancellation/evidence, pagination, session/correlation forwarding, denial, stale revision, expiry, cancellation, isolation, and lost-response recovery. These are SDK contract fixtures; service deployment and end-to-end LatticeConsole acceptance remain with their owning tasks. Run npx --no-install playwright install --with-deps chromium before local verification. --tarball <path> tests an already downloaded release; publication CI runs this against the integrity-verified public npm tarball.
The withdrawn unscoped [email protected] publication is historical
metadata only. Do not install it or treat it as target release evidence.
The repository has one package manifest, one canonical multi-source lock, one generated tree, one distribution directory, one changelog, one tarball, and one release pipeline. It never publishes service-specific packages or partial releases.
Releases authenticate to npm through Trusted Publishing with GitHub OIDC. Because the source repository is private and npm accepts Sigstore provenance only from public GitHub repositories, npm Sigstore provenance is disabled. The published tarball still carries dist/release-manifest.json and sources/openapi.lock.json, which pin every service-owned OpenAPI release, source commit, artifact digest, and generated output digest.
Onboarding
An owning service contributes a reviewed sources/registrations/<service-id>.json that pins its immutable OpenAPI artifact, source commit, release, generator profile, export namespace, and compatibility classification. Run:
npm ci
npm run fetch:artifacts
npm run resolve
npm run generate
npm run sync:exports
npm run verifyGeneration reads only sources/openapi.lock.json, creates a clean temporary source tree, verifies every output digest, and transactionally replaces the checked-in tree. CI regenerates twice and requires byte-identical output and a clean Git diff.
Boundary
Browser code calls an owning backend service through its module in this package. Configuration Registry, Artifact Registry, Registry metadata contracts, OCI workflows, and Juntai Query Engine are backend-only and are deliberately rejected by onboarding and packaging checks. Owning backend services use the Python distributions juntai-configuration-client and juntai-artifact-client; neither is an npm dependency or TypeScript surface.
