Repository navigation
packages env
Scope. Root env contract for golden-path and other root-workspace apps. Control Center explicitly does not import
@safrs/env/server. Sovereign capsules validate env locally. Do not treat this package as the repo-wide env schema.
Runtime environment validation built on @t3-oss/env-* plus Zod. Split into server and client halves so browser bundles never see server-only variables (DATABASE_URL, Stripe secrets). Invalid values throw at process start.
| File | Purpose |
|---|---|
packages/env/src/server.ts |
Server-side schema and serverEnv singleton (createServerEnv) |
packages/env/src/client.ts |
Client-safe schema and clientEnv singleton (createClientEnv) |
packages/env/package.json |
Exports ./client and ./server subpaths; no workspace deps |
Server (packages/env/src/server.ts):
-
DATABASE_URL— must be a URL (required). -
NODE_ENV— one ofdevelopment | test | production. -
APP_URL— must be a URL. -
STRIPE_SECRET_KEY— optional, but when present must start withsk_. -
STRIPE_WEBHOOK_SECRET— optional, but when present must start withwhsec_.
The Stripe keys are optional so the baseline builds without credentials; the prefix checks catch swapped or truncated values early. onValidationError fails fast with a sorted, comma-separated list of the offending variable names.
Client (packages/env/src/client.ts):
-
NEXT_PUBLIC_APP_URL— optional URL.
Both use emptyStringAsUndefined: true so empty strings never masquerade as real values.
import { serverEnv } from "@safrs/env/server";
import { clientEnv } from "@safrs/env/client";
const url = serverEnv.DATABASE_URL;The createServerEnv / createClientEnv factories accept an explicit environment object, which makes the package trivially testable without mutating process.env.
-
@safrs/databaseconsumesserverEnv.DATABASE_URLto build its Prisma client (packages/database/src/client.ts). -
@safrs/web(golden-path) validates its own environment through the same factories. -
tools/doctormirrors the server schema for its diagnostics: it readsDATABASE_URL,APP_URL, andNODE_ENVfrom.envand checks them against the disposable-database guard (tools/doctor/src/checks.mjs).
pnpm --filter @safrs/env lint
pnpm --filter @safrs/env typecheck
pnpm --filter @safrs/env test-
Database — consumes
serverEnv.DATABASE_URL - Doctor tool — environment diagnostics
- Shared packages
SAFRS — the Sentra Agent-First Repository Standard — defines how a software repository should be structured, governed, and enforced when autonomous Artificial Intelligence agents perform a substantial share of engineering work by Sentra Artificial Intelligence.
SAFRS v1.1 addresses that problem through five coupled mechanisms:
- a six-layer repository architecture from Trust Boundary to Human Authority;
- a role-based permission model in which capability never implies trust;
- a four-tier risk model with cumulative mandatory controls;
- a multi-agent execution protocol with explicit task states and one mutation owner per bounded scope;
- a knowledge governance model that distinguishes current architecture, historical decisions, execution plans, Git history, and running code.
Built in Indonesia as part of the Sentra Artificial Intelligence ecosystem.
Sentra Artificial Intelligence · Source Repository · Official Website
Dr Ferdi Iskandar — Creator & Maintainer
LinkedIn ·
ORCID ·
Hugging Face ·
Kaggle ·
Medium ·
Substack ·
X ·
Threads
MyPrompt · Sentra Artificial Intelligence · Indonesia
- SentraBot
- Kediri History
- Academic Smartboard
- Avery
- Portfolio Dr. Novia
- Golden Path (legacy demonstrator)
- Control Center
- Capsule template
- Risk model (R0–R3)
- Agent roles and permissions
- Capsule sovereignty
- Multi-agent protocol
- Document lifecycle
- Sensitive paths
- Verification integrity
Lore — how this repository grew
- Schemas (
@safrs/schemas) - Environment (
@safrs/env) - Database (
@safrs/database) - API (
@safrs/api) - UI (
@safrs/ui) - Telemetry (
@safrs/telemetry) - Token (
@sentra/token) - Config (
@safrs/config) - Auth (
packages/auth)
- SAFRS governance checkers
- SAFRS Automation Control Plane
- Gaffer Runtime
- Doctor
- Project wizard
- project-standalone
- Capabilities
- Codegen
- Deps-graph
- Status CLI
- Task CLI