Zum Hauptinhalt springen

Seed attribute ownership audit (AB#6317)

A blueprint update imports its seed with Upsert, which is a full replace of the entity. Which attribute values survive depends on the effective ownership of every attribute (see Blueprints and the engine rules Attribute Ownership): SeedOwned (default) is overwritten by the seed, TenantOwned, RuntimeState and Secret keep the stored value. Since AB#6313 the engine additionally keeps a non-empty stored value when a SeedOwned attribute arrives empty or omitted (the seed value guard); a non-empty, different seed value still wins. This audit lists, for every platform and app blueprint, which attributes the seeds write, who owns them, and which of them hold values that a tenant enters or changes. It is generated and can be rerun at any time.

Result​

  • Scope: 26 blueprints with 138 seed files and 2951 seed entities, resolved against 32 CK models (origin/main snapshot of 2026-10-10, repositories below).
  • Seed-written attribute rows: 899 (one row per blueprint, CK type and attribute): SeedOwned 674, RuntimeState 158, TenantOwned 60, Secret 7. No attribute was left unresolved.
  • Name-heuristic triage of the written rows: blueprint 607, runtime 154, tenant (already marked) 60, tenant-looking but SeedOwned 37, credential-looking 41 (of these 22 are SeedOwned). Every SeedOwned row that looks tenant-entered or credential-like was reviewed by hand and is reconciled below; one is a new finding (N1).
  • Omitted attributes: 324 SeedOwned attributes of seeded types are not written by the seed (table 2 of the full table); the guard keeps their non-empty stored value, except attributes with a CK default (AB#6395).

Reconciliation with the findings and decisions​

IdWhereOwnership todayWork itemState
F1System.Communication/Adapter.AdapterConfigurationSecretAB#6312fixed (System.Communication 4.7.0)
F2System.Identity/DataPolicy PolicyEnforcementMode, PolicyScopeTenantOwnedAB#6324fixed (System.Identity 2.23.0)
F3Meshmakers.Accounting/CategorizationRule rule attributes, CostCategory, FiscalYearSeedOwnedAB#6325open
F4System.StreamData archives Archive.RawRetentionMs, Archive.MaxRetroactiveReachMsSeedOwned, omitted by all seedsAB#6328open
F5System.Identity Client/ApiResource/ApiScope/IdentityResource Enabled, AllowedScopes, AllowedGrantTypes, AutoProvisionInChildTenants, Client SecretsTenantOwned / SecretAB#6329fixed (2.23.0), except N1
F6System.Communication PipelineTrigger.CronExpression, Pipeline.PipelineDefinitionSeedOwnedAB#6328open
F7System.Ai AiQuotaLimit, AiAgentConfig, AiToolPolicySeedOwnedAB#6328open
F8System.Communication/EnergyCommunityConfigurationRuntimeState (kept, lost on ExportRt)AB#6328open
F9System.UI Dashboard, DashboardWidgetSeedOwnedAB#6328open, policy decision first
F10FamilyOs Household, CalendarCategorynot in scan scopeAB#6328open
N1System.Identity/ApiResource.Secrets (the seed writes it empty, api-resources.yaml:42)SeedOwnedAB#6443new, found by this re-scan
D1System.Communication/AiConfiguration AiModel, MaxTokens, TemperatureSeedOwned on purposecomment in the CK attribute filedecision: a model bump must reach every tenant
D2/D3ServiceAccountConfiguration.IssuerUri, System/TenantIdSeedOwned on purposeAB#5027, AB#5115decision: empty means "own installation"
D4other System.Identity/Client flags (token lifetimes, RequirePkce, ...)SeedOwnedAB#6329 commentdecision: stay blueprint-owned
R1-R8policy coverage, Helm repository URLs, rollup time zone, saved query limits, sample data, form flagsSeedOwned-reviewed, blueprint-owned (reasons in the table)

Open question (no evidence of a tenant edit yet): saved queries (System/*Query) shipped by the app blueprints are SeedOwned; if tenants edit them in Studio, the same decision as for F9 applies.

Blueprints in scope​

BlueprintSeed filesSeed entitiesWritten attribute rowsof which SeedOwned
EnergyCommunity.App-2.1.0125437
EnergyCommunity.Base-2.11.114488766
EnergyCommunity.Billing-2.8.118635244
EnergyCommunity.EdaIntegration-2.11.012496040
EnergyCommunity.Simulation-2.8.241185
MeshmakersAccounting.Host-2.0.0123015
MeshmakersAccounting.Tesla-2.2.024176
MeshmakersAccounting-2.3.13315911972
System.Ai.Default-2.0.4171818
System.Notification.Bootstrap-1.0.01451
System.Communication.MainLatest-2.1.0142110
System.Communication.Release-2.1.0142110
Locations.Austria-1.2.011236477
Samples.EnergyEnvironment-1.1.0789107107
Samples.Maintenance-1.1.01655
Samples.Photovoltaics-2.0.13172621
Samples.PipelineBasics-2.0.026108
Samples.Simulator.EnergyCommunity-2.0.03161311
System.Identity.Bootstrap-1.3.111335844
Office.ExcelImport-2.0.01265
System.TenantMode-1.1.01141
System.UI.EntityForms-1.5.01251818
System.UI.SystemCockpit-1.1.01131515
System.UI.TenantCockpit-1.3.0171515
SmartMeterInsights.Base-2.0.05148260
SmartMeterInsights.Dev-1.0.0114133

Method​

  1. Every blueprint.yaml below the repositories is read; its seedDataPath/seedDataPaths files are parsed, entity by entity and attribute by attribute (file and line are kept as evidence).
  2. The CK models (ConstructionKit/ckModel.yaml with attributes/, types/, records/) are loaded. An attribute of value type Secret is always Secret. For all others the effective ownership of an attribute on a type is the nearest assignment override on the type chain (ownership, else the deprecated isRuntimeState), otherwise the attribute definition, otherwise SeedOwned. Element-version suffixes (-1) are ignored.
  3. Each row is triaged by attribute name (credential, runtime, tenant-looking, blueprint) as an aid, not as a verdict. Every SeedOwned row that looks tenant-entered or credential-like is judged by hand against the CK description and the seed and recorded in findings.yaml as a finding (work item) or a decision/review (reason).
  4. A seed file that a manifest references but that is missing aborts the run (no silent gaps).
  5. Table 2 lists SeedOwned attributes of seeded types that no seed entity of the type writes (engine-stamped System/Rt* attributes are left out).

Scope and limits​

  • Repositories (origin/main snapshot, 2026-10-10): energy-community c0cb64a, meshmakers-app 65aa8c2, octo-ai-services fd4c85c, octo-common-services 1556366, octo-communication-controller-services bf45f46, octo-construction-kit ca257e7, octo-construction-kit-engine 9d5ce4d2, octo-identity-services 426fe8d, octo-office-integration 3f2c142, octo-platform-services 7ea5157, smart-meter-insights 5d7049e, plus the CK-only repositories octo-bot-services c3eb571, octo-report-services d312522, octo-communication-sdk 2142169, octo-adapter-loxone feeee40 and the demo/landing repositories landing-pages f0cbc7c, wwc26-landing-page c382c2f, demo-energy-iq cd0477c and demo-process-automation d867932 (19 repositories in total; the last four contribute CK models only, no blueprint).
  • Not covered because they are not in the scanned repositories: the FamilyOs and one-time-ticket blueprints and the private FdaSeen catalog. Blueprint samples under samples/, test fixtures and drafts are skipped.
  • The audit reads source files only. It does not know which tenants run which blueprint version and does not judge values on a tenant; whether a value is actually edited by tenants comes from the CK description, the seed comments and the work items.
  • Attribute-level ownership only. A pipeline definition or a dashboard layout is one attribute value (F6, F9).

Regenerate​

The script and findings.yaml are in scripts/seed-ownership-audit/ of the octo-documentation repository; its README.md has the snapshot loop and the command. The full tables are on the page Seed ownership audit: full table.