Creating Datastores
Datastore creation is a privileged Trusted-runtime operation. PostgreSQL, Storage, Lake, scratch, identity, and Secret requirements must already exist in the selected versioned Application document.
Validate and preflight one logical Datastore before mutation:
ahri-tre --config application.toml config validate
ahri-tre --config application.toml config preflight \
--for datastore-create --datastore research
ahri-tre datastore create research --format json
The request carries only the Datastore configuration ID. It cannot override physical topology, paths, roles, credentials, Secret roots, or reset policy. Version 1 refuses existing, failed, or partially created components instead of adopting or force-resetting them.
Creation establishes the PostgreSQL identity binding and durable Managed-secret reference evidence before publishing readiness. Retry and compensation follow the authoritative owner state; uncertain commits fail closed.
For remote deployments, mount Storage at the exact container-visible path named by Application configuration before preflight. Restricted local references are never sent to runtime code.