SIGN IN SIGN UP

feat(domainkit)!: replace grants with managed DNS attachments (#62)

## Summary

Replace the public grant/account-deduplication model with explicit
organization connections and exact domain attachments, while keeping
credential authorization and revocation coordination inside one
lifecycle capability.

## API

```ts
const result = await Connection.start({
  authorizedById: "org-admin",
  method,
  ownerId: "organization-1",
  repository,
});

if (result._tag === "Connected") {
  await Connection.attach({
    attachment: {
      connectionId: result.connection.id,
      createdAt: new Date(),
      domain: "mail.example.com",
      id: "attachment-1",
      target: {
        accountId: "provider-account",
        accountKind: "account",
        zoneId: "provider-zone",
        zoneName: "example.com",
      },
    },
    connectionId: result.connection.id,
    ownerId: "organization-1",
    repository,
  });
}
```

An additional organization reuses a credential only when the host
explicitly supplies an `authorizationId` after fresh provider proof; the
core never deduplicates by provider account.

## Lifecycle

```text
provider proof
  -> internal authorization + credential
  -> explicit organization ProviderConnection
  -> exact DomainAttachment + ProviderTarget
  -> persisted owner/attachment/capability authorization

final connection removal
  -> revocation-pending
  -> provider-defined revoke
  -> local authorization removal
```

- Connections may exist with zero attachments.
- Attachments are unique for an organization and exact domain, and
retain the selected account/zone target.
- Disconnect is blocked while attachments exist; failed final revocation
remains recoverable.
- `Grant`, grant algebra, excluded-domain state, implicit account reuse,
and repository-per-table public stores are removed as a breaking change.

## Validation

- `bun run --filter domainkit release:check`
- `bun run typecheck`
- `bun run test`
- `bun run lint`
- `bun run format:check`
- `git diff --check`
S
Saatvik Arya committed
7bafe22aa7a31a8679ec219f905aab66ebf3bebe
Parent: bfee334
Committed by GitHub <noreply@github.com> on 8/31/2026, 8:16:54 AM