---
schema: formation.doc/v0.1
kind: doc
visibility: public
canonical_url: https://topologyindex.com/docs/schemas/execution_lock/v0.1.md
document_kind: execution_lock
document_schema: formation.execution_lock/v0.1
max_document_bytes: 262144
path: /docs/schemas/execution_lock/v0.1.md
product_api_version: v1
schema_version: v0.1
title: formation.execution_lock/v0.1
---

# formation.execution_lock/v0.1

Frontmatter fields of a `execution_lock` document. Every security-, cost- and execution-relevant
value is a typed field; prose in the body can explain a rule but never override it. Undeclared
fields are rejected.

## Fields

- `schema` (required): exactly `formation.execution_lock/v0.1`
- `kind` (required): exactly `execution_lock`
- `created_at` (optional): ISO 8601 UTC timestamp, pattern `^(\d{4})-(\d{2})-(\d{2})T(\d{2}):(\d{2}):(\d{2})(?:\.(\d{1,9}))?Z$`, at most 30 characters
- `visibility` (optional): one of `private`, `public`
- `formation_digest` (required): sha256 digest, pattern `^sha256:[0-9a-f]{64}$`, at most 71 characters
- `canonicalizer_version` (required): version label, pattern `^[a-z0-9][a-z0-9._/-]{0,63}$`, at most 64 characters
- `spec_version` (required): version label, pattern `^[a-z0-9][a-z0-9._/-]{0,63}$`, at most 64 characters
- `runtime` (required): map (fields listed below)
- `runtime.name` (required): component name, pattern `^[a-z0-9@][a-z0-9@/._-]{0,127}$`, at most 128 characters
- `runtime.version` (required): pinned version, pattern `^[0-9A-Za-z][0-9A-Za-z._+-]{0,63}$`, at most 64 characters
- `sdk` (required): map (fields listed below)
- `sdk.name` (required): component name, pattern `^[a-z0-9@][a-z0-9@/._-]{0,127}$`, at most 128 characters
- `sdk.version` (required): pinned version, pattern `^[0-9A-Za-z][0-9A-Za-z._+-]{0,63}$`, at most 64 characters
- `adapter` (required): map (fields listed below)
- `adapter.name` (required): component name, pattern `^[a-z0-9@][a-z0-9@/._-]{0,127}$`, at most 128 characters
- `adapter.version` (required): pinned version, pattern `^[0-9A-Za-z][0-9A-Za-z._+-]{0,63}$`, at most 64 characters
- `harness` (required): map (fields listed below)
- `harness.name` (required): component name, pattern `^[a-z0-9@][a-z0-9@/._-]{0,127}$`, at most 128 characters
- `harness.version` (required): pinned version, pattern `^[0-9A-Za-z][0-9A-Za-z._+-]{0,63}$`, at most 64 characters
- `container_image` (required): null or map (fields listed below)
- `model_bindings` (required): array of 1 to 16 items, each map (fields listed below)
- `model_bindings[].slot` (required): identifier, pattern `^[a-z][a-z0-9_]{0,63}$`, at most 64 characters
- `model_bindings[].provider` (required): identifier, pattern `^[a-z][a-z0-9_]{0,63}$`, at most 64 characters
- `model_bindings[].model_id` (required): model identifier, pattern `^[A-Za-z0-9][A-Za-z0-9._:/@-]{0,127}$`, at most 128 characters
- `model_bindings[].endpoint_class` (required): identifier, pattern `^[a-z][a-z0-9_]{0,63}$`, at most 64 characters
- `model_bindings[].pinning` (required): one of `exact`, `provider_alias_mutable`
- `model_bindings[].bound_at` (required): ISO 8601 UTC timestamp, pattern `^(\d{4})-(\d{2})-(\d{2})T(\d{2}):(\d{2}):(\d{2})(?:\.(\d{1,9}))?Z$`, at most 30 characters
- `model_bindings[].observed_at` (optional): ISO 8601 UTC timestamp, pattern `^(\d{4})-(\d{2})-(\d{2})T(\d{2}):(\d{2}):(\d{2})(?:\.(\d{1,9}))?Z$`, at most 30 characters
- `model_bindings[].seed_supported` (required): boolean
- `model_bindings[].generation` (required): map (fields listed below)
- `model_bindings[].generation.temperature` (required): null or number from 0 to 2
- `model_bindings[].generation.top_p` (required): null or number from 0 to 1
- `model_bindings[].generation.max_output_tokens` (required): null or integer from 0 to 1000000000000
- `model_bindings[].generation.seed` (required): null or integer from 0 to 9007199254740991
- `tools` (required): array of 0 to 32 items, each map (fields listed below)
- `tools[].id` (required): tool identifier, pattern `^[a-z][a-z0-9_]{0,31}\.[a-z][a-z0-9_]{0,31}$`, at most 64 characters
- `tools[].implementation` (required): component name, pattern `^[a-z0-9@][a-z0-9@/._-]{0,127}$`, at most 128 characters
- `tools[].version` (required): pinned version, pattern `^[0-9A-Za-z][0-9A-Za-z._+-]{0,63}$`, at most 64 characters
- `tools[].digest` (required): null or sha256 digest, pattern `^sha256:[0-9a-f]{64}$`, at most 71 characters
- `tools[].metered` (required): boolean
- `tools[].cost_per_call_usd_micros` (required): null or integer from 0 to 1000000000000000
- `permission_policy` (required): map (fields listed below)
- `permission_policy.default` (required): exactly `deny`
- `permission_policy.network_access` (required): one of `none`, `allowlist`
- `permission_policy.network_allowlist` (required): array of 0 to 32 items, each hostname, pattern `^[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$`, at most 253 characters
- `context_strategy` (required): map (fields listed below)
- `context_strategy.kind` (required): one of `fresh_per_role`, `shared_transcript`, `summarized_handoff`
- `context_strategy.max_context_tokens` (required): null or integer from 0 to 1000000000000
- `dependency_lock_digest` (required): null or sha256 digest, pattern `^sha256:[0-9a-f]{64}$`, at most 71 characters
- `retry_policy` (required): map (fields listed below)
- `retry_policy.max_internal_retries` (required): integer from 0 to 10
- `retry_policy.max_infrastructure_retries` (required): integer from 0 to 10
- `retry_policy.retryable_failure_codes` (required): array of 0 to 10 items, each one of `budget.exhausted`, `time.exhausted`, `tool.unavailable`, `validator.failed`, `lease.lost`, `provider.error`, `coordination.repeated_handoff`, `cause.supervisor_bottleneck`, `cause.duplicate_work`, `cause.unknown`
- `pricing_snapshot_digest` (required): sha256 digest, pattern `^sha256:[0-9a-f]{64}$`, at most 71 characters
- `adaptation_rules` (required): array of 0 to 32 items, each identifier, pattern `^[a-z][a-z0-9_]{0,63}$`, at most 64 characters
- `capability_conformance` (required): map (fields listed below)
- `capability_conformance.result` (required): one of `conformant`, `nonconformant`, `not_checked`
- `capability_conformance.conformance_suite_version` (required): version label, pattern `^[a-z0-9][a-z0-9._/-]{0,63}$`, at most 64 characters
- `capability_conformance.checked_capabilities` (required): array of 0 to 32 items, each identifier, pattern `^[a-z][a-z0-9_]{0,63}$`, at most 64 characters
- `reproducibility` (required): one of `exact`, `limited`
