l1spec is the file. Undeclared tools are not constructed.
Same idea as Terraform versus .tf.
apiVersion: l1spec.lightfoot.cloud/v0,
kind: L1Graph, schema
l1spec/schema/l1spec.v0.json.
Allowlists are enumerated pairs. Wildcards fail. Verb prefixes are
not a security boundary — AWS_DENY operations fail even
when they look like reads. Spec values cannot interpolate
${ENV}.
-
reject
phoneHome: true— Lightfoot does not collect incidents -
reject
dataPlaneother thancustomer - reject Wildcard AWS operations
-
reject
Any operation in
AWS_DENY -
reject
mergeAllowed: true - reject Swarm / emergent routing
- reject Write-classified identities
- reject Gates targeting a Lightfoot-hosted desk
- reject A router with tools, identities, or connectors
Gate platforms in the schema: pagerduty, jira, servicenow, gitlab, github, datadog, newrelic. Actions: none, comment, draft-pr, annotate-alert, annotate-incident. The v0 runner implements three of those writes; see Trust.
l1ctl validate graphs/ec2-disk-pressure.l1.yaml