feat(domainkit)!: replace grants with managed DNS attachments (#62)
## Summary
Replace the public grant/account-deduplication model with explicit
organization connections and exact domain attachments, while keeping
credential authorization and revocation coordination inside one
lifecycle capability.
## API
```ts
const result = await Connection.start({
authorizedById: "org-admin",
method,
ownerId: "organization-1",
repository,
});
if (result._tag === "Connected") {
await Connection.attach({
attachment: {
connectionId: result.connection.id,
createdAt: new Date(),
domain: "mail.example.com",
id: "attachment-1",
target: {
accountId: "provider-account",
accountKind: "account",
zoneId: "provider-zone",
zoneName: "example.com",
},
},
connectionId: result.connection.id,
ownerId: "organization-1",
repository,
});
}
```
An additional organization reuses a credential only when the host
explicitly supplies an `authorizationId` after fresh provider proof; the
core never deduplicates by provider account.
## Lifecycle
```text
provider proof
-> internal authorization + credential
-> explicit organization ProviderConnection
-> exact DomainAttachment + ProviderTarget
-> persisted owner/attachment/capability authorization
final connection removal
-> revocation-pending
-> provider-defined revoke
-> local authorization removal
```
- Connections may exist with zero attachments.
- Attachments are unique for an organization and exact domain, and
retain the selected account/zone target.
- Disconnect is blocked while attachments exist; failed final revocation
remains recoverable.
- `Grant`, grant algebra, excluded-domain state, implicit account reuse,
and repository-per-table public stores are removed as a breaking change.
## Validation
- `bun run --filter domainkit release:check`
- `bun run typecheck`
- `bun run test`
- `bun run lint`
- `bun run format:check`
- `git diff --check` S
Saatvik Arya committed
7bafe22aa7a31a8679ec219f905aab66ebf3bebe
Parent: bfee334
Committed by GitHub <noreply@github.com>
on 8/31/2026, 8:16:54 AM