Hold the model fixed; improve context + tools. Upstream: lopopolo/harness-engineering (transform ideas into our owners — do not clone their tree). Prefer artifact over “codebase.”
When a decision is unresolved, read one owner below — do not load the full standards stack.
Markdown format does not change enforcement. Hard gates stay: lint (error + --max-warnings 0), tsconfig.check.json / brand types, proof journeys. Each invariant below names its ratchet.
Orthogonal to gates: prose is a terminal-readable routing layer; evidence lives in tests / type-check / proof.ts.
Bun.markdown.ansi)docs/harness/<name>.md + one bun run docs:<name> per contract (e.g. docs:cron)harness:status*Id / bare string IDs → lib/types/branded/README.md · skill .agents/skills/branded-ids/unknown / decode / wire vs interior → docs/WIRE_BOUNDARY.md@see refs → bun tools/bun-doc-refs.ts suggest "<api>" · docs/BUN_NATIVE_CAPABILITIES.mddocs/UNIFIED.mddocs/organization/VELOCITY_BASELINE.mdPROOF.md · lib docs/Bun/other map → Lib surface · bun run proof:installCLAIM-DISCOVERY.md · bun run docs:claim-discoveryREVIEW.mdFEEDBACK.mdAUTHORITY.mdbun ./docs/harness/README.md · bun run docs:harnessbun run harness:status (local ratchets + timings SSOT · ansiMarkdown) · --table · --show-actions-noisebun run docs:cron · cron.md · bun run test:cron · bun run test:cron-osbun run spine:schedule:once · claim spine-multi-tenant · cron.mdbun run test:tenant-runbooks · spine-tenants.md · claim spine-maintenance-runbooksbun run test:tenant-heal · claim spine-tenant-healbun run test:code-quality · code-quality.mdnoOrphans, freshRerun timeout, --smol, stdin vs bun run -) → docs/BUN_NATIVE_CAPABILITIES.md · workspace bunfig.toml [run]bun run test:ci-deploy · ci-deploy.md · claim ci-deploy-runbooksproject-r-score) → bun run cloudflare:env · config/r2-env.ts · tenants/cloudflare-pages.md · claim cloudflare-pages-env-ssot · bun test tests/r2-env.test.tsinstall-verify-journey) → bun run docs:install-verify · install-verify.md · bun run test:install-verifysearch-governance-basic) → bun run docs:search-governance · search-governance.md · bun run test:search-governancebun run docs:fresh-rerun · FRESH-RERUN.mdbun run docs:claim-discovery · CLAIM-DISCOVERY.mdsource switch) → bun run docs:ops-summary-endpoint · ops-summary-endpoint.md · bun run ops:diagnosebun run ops:seed:toc · tenants/toc-ops.md · /portal/toc/ · surface map (channels/rails/phones/ROI/bots vs MCP) · bun test tests/toc-ops-fixture.test.tsbun run ops:loop:baseline / ops:loop:post / ops:loop:live / ops:loop:backfill / ops:outbox:requeue · tenants/ops-loop-throughput.md · claim ops-loop-throughput · bun test tests/ops-loop-hardening.test.ts · note: LCR is attribution; use --drain --r2 for durable proof (projectorBackend)tenants/partner-onboarding-package.md · bun tools/onboard-partner-package.ts ASH-001 --dry-run · bun run telegram:link-chat -- ASH-001 tg:chat:… · bun test tests/onboard-partner-package.test.ts tests/telegram-templates.test.tsbun run telegram:verify · telegram:ops:consume · tenants/telegram-factory.md · lib/telegram/templates/ · bun test tests/telegram-flows.test.ts tests/telegram-templates.test.tsbun run docs:reference-discovery · .agents/skills/reference-discovery/SKILL.md · bun run reference:discover:check.agents/skills/harness-improve/SKILL.md.custom-instructions.mdlib/types/branded.ts — domain *Id brands; no bare string IDs after the boundarybun tools/branded-id-check.ts --staged --strict, bun run check:brands:types, tsc --project tsconfig.check.jsondocs/WIRE_BOUNDARY.md — unknown / decode stay at parse edgesharness/no-unknown-function-param (error), harness/no-decode-unknown-outside-boundary (error)bun run flag placement, script vs file resolution, --bun shebang, --console-depthbun test tests/fixtures/runtime-cli/ · claim runtime-cli-boundaries · runtimeconsole-depth-boundaries — lib/console-depth helpers (inspect/width/markdown)bun test tests/console-depth.test.ts · PROOF Lib surfacegithub-repository-ref-boundaries — Actions → git → CANONICAL_REMOTESbun test tests/github-repository-ref.test.ts · AUTHORITY.mdmacros-embed-boundaries — bundle-time macro inliningbun test tests/macros/embed-commit.test.ts · lib/macros/README.mdbun-shell-boundaries → bun test tests/fixtures/bun-shell/fs-native-boundaries → bun test tests/fs-bun.test.ts tests/bun-glob-scan.test.tssecurity-hash-boundaries → bun test tests/fixtures/security-hash/url-pattern-boundaries → bun test tests/bun-site-url.test.tssocial-metadata-boundaries → bun test tests/fixtures/social-metadata/blog-extraction-boundaries → bun test tests/fixtures/blog-extraction/fetch-page-boundaries → bun test tests/fixtures/fetch-page/blog-extraction-journey → bun test tests/journey/blog-extraction.test.ts (live bun.com)lib/path-bun — spine lib/ + tools/ import Bun path helpers, not path / node:pathbun run check:path-bun (pre-commit when lib/ or tools/ staged)Bun.env boxing — no Node process.env in spine lib/ + scripts/bun run check:bun-env, eslint bun/prefer-bun-env (error)invisible-chars — zero-width / bidi / format code points are \u escapes in source, never literal bytesbun run check:invisible-chars (pre-commit when spine or test .ts staged) · // invisible-ok to suppress · VS16 warn-only (--verbose lists)@see URLs — Bun APIs cite catalog URLsbun-doc-refs annotate-on-write · bun tools/bun-doc-refs.ts checkaudit-findings-catalog · bun run audit:verify · pre-commit + ci:harness · docs/audit/README.mdfactory-registry-cli-v1 — R2 artifact registry + CLI (publish, install, list, search, readme)bun test tests/registry.test.ts tests/cli.test.ts · claim factory-registry-cli-v1 · lib/factory/factory-registry-pages-proxy-v1 — Pages /api/registry R2 binding proxy (allowlisted keys, fail-closed)bun test tests/registry-pages-function.test.ts · claim factory-registry-pages-proxy-v1 · functions/api/registry/PROOF.md · lib/harness/proof.ts · bun run proof:install · bun run harness:statusFRESH-RERUN.md · freshRerun on each CRITICAL_PROOF_PATHS entry · paste output in PRlib/docs/** type-check — docs path SSOT is one era under day-loop tsctsconfig.check.json include lib/docs/**/* · claim lib-docs-typecheck · bun run type-checklib/utils/** type-check — utils island is one era under day-loop tsctsconfig.check.json include lib/utils/**/* · claim lib-utils-typecheck · bun run type-checklib/core/** type-check — core island is one era; ErrorSeverity enum at call sitestsconfig.check.json include lib/core/**/* · claim lib-core-typecheck · bun run type-checklib/security/** type-check — security island is one era under day-loop tsctsconfig.check.json include lib/security/**/* · claim lib-security-typecheck · bun run type-checkAGENTS.md routing · UNIFIED · brand manifest · projects triagebun run help · harness:status · cli-categories · actionable gate errorsAUTHORITY.mdPROOF.md · lib/harness/proof.tsFEEDBACK.md · harness:lessondocs:refresh operate loopbun install # prepare → husky
# pre-commit: hygiene ‖ harness → ast-grep
# pre-push: install:verify --quiet
bun run ci:harness:fast # quiet local parity (no hygiene)
bun run ci:harness # quiet harness envelope
bun run ci:core # install verify · hygiene · ci:harness (= GHA body)
# Actions offline (billing)? Local proof = required-check bodies:
# bun run ci:core
# bun run ts:verify && bun run imports:verify && bun run type-check:ci && bun run type-check:full
core (GHA main/PR or local) — install verify · cache lifecycle · hygiene · claim (PR) · ci:harness — one runner/installbun run ci:corefast (local) — ∥ cheap · test:changed dirtybun run ci:harness:fastharness — eslint-changed (PR) / full on main · test:changed:mainbun run ci:harnesslocal-only (Actions billing offline) — run ci:core + type-check scripts; admin-merge until GHA runners returnfeat/codex only — hygiene for branches without harness-gatessetup — shared Bun + install cache (+ optional eslint cache)types — type-check:ci then type-check:full (not matrix×2 installs)Required checks: Harness Gates + Type Check — see AUTHORITY.md. When Actions cannot start, local ci:core + type-check is the proof; GitHub status stays red until billing restores. Velocity / install-tax: VELOCITY_BASELINE.md. Pre-commit write tools fail if staged≠worktree (re-stage + retry).
Full map: day-loop.md · curated Bun flags NOTE: ../guides/bun-test-flags-1.3.13.md.
bun run docs:harness # this index → bun ./file.md (native ANSI, no VM)
bun run harness:status # local ratchets + timings SSOT (ansiMarkdown)
# bun run harness:status -- --table # Bun.inspect family map + inspect.table
# bun run harness:status -- --show-actions-noise # unmute GHA 0-step / billing checks
bun run help
bun run type-check # tsconfig.check.json — spine agent surfaces
bun run build:affected # git-true workspaces → bun --filter
bun run test:affected # workspace package.json "test" scripts
bun run test:changed # --changed (dirty)
bun run test:changed:main # --main-head → origin/main|main
# bun run test:changed -- HEAD~1
# bun run test:changed -- main --parallel
# bun run test:changed:watch
bun run test:isolate # --isolate (fresh global per file)
bun run test:parallel # --parallel (workers; auto --isolate)
# SHARD=1/3 bun run test:shard
bun run ci:harness:fast # before push (quiet)
bun run proof:install # install only (also pre-push --quiet)
bun run check:path-bun && bun run check:bun-env
bun run projects:roots:check # product-leaf README + package.json (also ∥ cheap / pre-commit on projects/)
bun run lib:domains:check # lib/*/ README indexes (also ∥ cheap / pre-commit on lib/)
bun run build:defines # AST --define BUILD_* + DEBUG=false (prod DCE); runtime config stays Bun.env
# bun run build:defines:dev # DEBUG=true
# bun run build:defines:compile # standalone dist/fw-build-info
test:affected = workspaces; test:changed = import-graph (bun-test-changed.ts). Empty set exits 0. Docs: v1.3.13 --isolate / --parallel · --shard · --changed.
Terminal markdown: static files via bun ./file.md; live CLIs via ansiMarkdown / Bun.markdown.ansi (docs/BUN_NATIVE_CAPABILITIES.md · markdown ANSI). Opt-in inspect family: bun run harness:status -- --table (Bun.inspect · custom · table). Actions 0-step / billing checks stay muted; --show-actions-noise to show. When Actions is offline, local merge proof remains bun run ci:core (AUTHORITY.md).
Parallel agent lanes for platform mapping — run from broad to narrow:
| Wave | Command / owner | Output |
|---|---|---|
| 0 | bun run harness:status |
ratchet + claim inventory |
| 1 | bun run cloudflare:env · MCP cloudflare Pages API |
domain pins · deploy state |
| 2 | bun run verify:proof-taxonomy:save · bun run check:release-tracker |
13 contracts · 20 consistency |
| 3 | bun run ops:snapshot · bun run verify:portal · verify:pages-edge |
live portal + Pages edge |
Routing SSOT: docs/platform-routing.md · proof taxonomy: PROOF.md.
verify-all pipeline (ordered)bun-utils-test · install-platform · install-env · registry-client · bundler-loaders)check:release-trackerTests + release verify: bun-release-tracker · bun-runtime-nits-probes · install-platform/env · verification-channels · canonical-coverage · proof-taxonomy (+ tool) · proof-consistency · release-preview · docs-coverage · resolve-bun-binary · bun tools/verify-bun-release.ts.