Skip to content

zones.yml

What the reference will cover, so you know it’s coming rather than forgotten:

  • version, config (spike environment, cleanup and verify commands)
  • generated: — paths exempt from the diff-⊆-declared check because they are built, not authored
  • Per-zone: id, name, risk, owner, description, paths (glob patterns — the shapes GitHub rulesets use, matched by picomatch with dotfiles on — and their hardening: symlinks and hard links were Phase 0 findings), default_policy, secrets
  • unprotected: — paths reviewed and deliberately left open, so the closing gate stops asking about them. Everything unlisted is unprotected too; this list only silences the question
  • The schema system zone that cycle init always creates, and why