{
  "protocol": "smallgreen-install/v1",
  "status": "candidate",
  "deployment_ready": false,
  "contract_url": "https://raw.githubusercontent.com/ai-cooperation/audio-notes-sites/9d29844c858c3619dda9d98e1aa5ddc3d42e3e76/.smallgreen/install.yaml",
  "trigger": {
    "zh-tw": "先讀取此服務卡的 install.json，核對 Sites 能力、安裝環境及固定文件網址；前置檢查通過後，依這網站，幫我部署到我的帳號。遇到阻塞先停止並回報；分開回報網站部署、本人設定 Groq Key、合法傳檔與錄音驗收，不把模擬測試當成部署成功。",
    "en": "First read this card's install.json and verify Sites capability, the installation environment and pinned document URLs. After preflight passes, deploy this service to my account from this page. Stop and report blockers; report website deployment, owner Groq key setup and authorized audio acceptance separately. Mock tests are not deployment success."
  },
  "target": {
    "client": "chatgpt-work",
    "hosting": "sites",
    "execution_mode": "native-sites"
  },
  "hosting": {
    "managed_resources": [
      "site",
      "d1",
      "r2"
    ],
    "external_infrastructure": []
  },
  "runtime_setup": {
    "name": "GROQ_API_KEY",
    "timing": "after-deploy",
    "entry_channel": "application-ui",
    "chat_handling": "forbidden",
    "setup_path": "/#groq-settings"
  },
  "documents": {
    ".smallgreen/install.yaml": "https://raw.githubusercontent.com/ai-cooperation/audio-notes-sites/9d29844c858c3619dda9d98e1aa5ddc3d42e3e76/.smallgreen/install.yaml",
    ".smallgreen/acceptance.yaml": "https://raw.githubusercontent.com/ai-cooperation/audio-notes-sites/9d29844c858c3619dda9d98e1aa5ddc3d42e3e76/.smallgreen/acceptance.yaml",
    ".smallgreen/maintenance.yaml": "https://raw.githubusercontent.com/ai-cooperation/audio-notes-sites/9d29844c858c3619dda9d98e1aa5ddc3d42e3e76/.smallgreen/maintenance.yaml",
    "docs/WORK_DEPLOY.md": "https://raw.githubusercontent.com/ai-cooperation/audio-notes-sites/b484d674c8572ecfaf8f9649484fa59db98e2250/docs/WORK_DEPLOY.md",
    "docs/LIMITATIONS.md": "https://raw.githubusercontent.com/ai-cooperation/audio-notes-sites/b484d674c8572ecfaf8f9649484fa59db98e2250/docs/LIMITATIONS.md",
    "AGENTS.md": "https://raw.githubusercontent.com/ai-cooperation/audio-notes-sites/b484d674c8572ecfaf8f9649484fa59db98e2250/AGENTS.md"
  },
  "document_resolution": {
    "rule": "Use documents entries for matching contract-relative references; resolve other paths at source.commit. Fetch all required documents before provisioning. If instructions conflict, stop and report the conflict.",
    "missing_document_action": "stop",
    "allow_unpinned_fallback": false
  },
  "preflight": {
    "on_failure": "stop_before_resource_creation",
    "required_checks": [
      "native_sites_capability",
      "pinned_documents",
      "compatible_install_environment",
      "clean_dependency_install",
      "build_and_migration_bundle"
    ],
    "instructions": [
      "Verify native Sites tools and account access in the current agent session; a CLI name or website HTTP 200 is not capability evidence. Do not substitute external Cloudflare hosting.",
      "Fetch pinned documents using the mapping above and verify the application checkout SHA. A missing .smallgreen file at source.commit does not mean contract_url is unavailable.",
      "Record the operating system, shell and Sites execution profile. The pinned helper path failed on macOS with Bash 3.2 and missing Linux tools. Stop on this incompatible path; do not provision resources or install global tools to work around it.",
      "Managed Linux is unverified, not known to fail. In a compatible environment require a successful frozen clean dependency install and build with the hosting manifest and all migrations present. Reused node_modules do not pass this check.",
      "On dependency download timeout keep the log and report installation incomplete. Retry at most once with a stated time bound; do not change the lockfile or claim that a network timeout is a product defect."
    ]
  },
  "encryption_readiness": {
    "requirement": "Generate the documented 32-byte encryption key and store it only as a Sites secret. Validate its decoded length and encryption operation without logging it; a nonempty secret or storageReady alone is insufficient.",
    "known_failure_scope": "A malformed master key produced storageReady true followed by save HTTP 400 in local fault injection; this does not mean a valid key always fails."
  },
  "upload_authorization": {
    "website_login_implies_agent_access": false,
    "on_unavailable": "stop_audio_stage",
    "make_site_public_to_bypass_auth": false,
    "requirement": "Use a platform-supported authorized upload route with the verified owner and short-lived credentials. Follow the current Sites tool authorization requirements; a deployment request alone does not authorize every token-generation tool. Never request keys or tokens in chat or fabricate identity headers."
  },
  "completion_policy": {
    "report_stages": [
      "private_site_deployment",
      "owner_groq_setup",
      "authorized_audio_flow"
    ],
    "stage_results": [
      "passed",
      "failed",
      "blocked",
      "not_run"
    ],
    "mock_is_live_evidence": false,
    "deployment_success_requires": "Sites successful terminal state plus authenticated application health and working D1 and R2 with all migrations; homepage HTTP 200 or anonymous API 401 alone is insufficient.",
    "operational_success_requires": "Owner-configured Groq key plus authorized short-audio upload, a real Groq response and four saved documents read back with completion verification."
  },
  "verification_scope": {
    "checked_on": "2026-09-17",
    "scope_summary_url": "https://github.com/smallgreen-cloud/registry/blob/main/candidates/audio-notes-sites.md",
    "macos_portable_install": "failed",
    "clean_install": "unverified",
    "managed_linux_install": "unverified",
    "build_with_reused_dependencies": "passed",
    "local_mock_audio_flow": "passed",
    "fresh_account_deployment": "unverified",
    "real_groq_flow": "unverified",
    "note": "Local observations are not a SmallGreen Evidence Pack. Model review completion is not deployment completion."
  },
  "blockers": [
    "macOS portable 文件安裝路徑已實測不相容；乾淨安裝因下載逾時未完成，受管 Linux 路徑未驗證",
    "尚未完成全新 Work／Sites 帳號從服務卡啟動的獨立部署驗收",
    "尚未驗證 Work 對私人 Site 的持久合法附件傳輸授權",
    "尚未完成 Sites 受管 D1／R2 的全量備份、還原與 teardown zero-diff 驗收"
  ],
  "service_card": "https://smallgreen.cooperation.tw/services/audio-notes-sites/",
  "source": {
    "repository": "ai-cooperation/audio-notes-sites",
    "commit": "b484d674c8572ecfaf8f9649484fa59db98e2250",
    "license": "MIT"
  },
  "notice": "Candidate install discovery. Inspectable, not yet verified as SmallGreen Ready."
}
