> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nika.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# fs

> Contract, placement, related fields and source examples for this Nika YAML field.

[Language reference](/reference/language/overview) / `fs`

## Meaning and placement

### → permits

The schema declares this field at the location below.

| Property             | Declaration                         |
| -------------------- | ----------------------------------- |
| Requirement          | Optional in this object             |
| Schema location      | `/properties/permits/properties/fs` |
| type                 | "object"                            |
| additionalProperties | false                               |

**In the same object:** [env](/reference/language/words/env) · [exec](/reference/language/words/exec) · [net](/reference/language/words/net) · [tools](/reference/language/words/tools)

[Schema source (use the pointer above)](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/schemas/workflow.schema.json)

## In a source template

Excerpt from `templates/api-upload-and-create.nika.yaml`, source lines 55–64. This is a fragment, not a runnable workflow.

```yaml illustration theme={"system"}
  # half — an unlisted host is refused at RUN, mid-flight, with the bytes
  # already on the wire.
  net: { http: ["api.example.com"] }   # SLOT: the host from const.api_base
  fs:
    # A `multipart:` file part names a path, and that read crosses the boundary
    # like any other: measured, without this entry the call dies `NIKA-SEC-004 ·
    # ./out/assets/asset-1.png resolves outside the declared permits.fs.read
    # boundary`. One exact file, never the tree it sits in. The drift detector
    # models a multipart part as a read (2026-07-29) — the former NIKA-DRIFT-001
    # false hint is closed.
```

### Templates containing this field

| Template                                    | Source                                                                                                                                            |
| ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- |
| `templates/api-upload-and-create.nika.yaml` | [Line 58](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/templates/api-upload-and-create.nika.yaml#L58) |
| `templates/chain.nika.yaml`                 | [Line 41](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/templates/chain.nika.yaml#L41)                 |
| `templates/docker-report.nika.yaml`         | [Line 43](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/templates/docker-report.nika.yaml#L43)         |
| `templates/etl-state.nika.yaml`             | [Line 57](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/templates/etl-state.nika.yaml#L57)             |
| `templates/fanout.nika.yaml`                | [Line 72](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/templates/fanout.nika.yaml#L72)                |
| `templates/human-gated-ship.nika.yaml`      | [Line 68](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/templates/human-gated-ship.nika.yaml#L68)      |
| `templates/media-asset-pack.nika.yaml`      | [Line 41](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/templates/media-asset-pack.nika.yaml#L41)      |
| `templates/website-brief.nika.yaml`         | [Line 46](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/templates/website-brief.nika.yaml#L46)         |

These are literal key occurrences in the source files, not an execution or conformance claim. [How to instantiate a template](/guides/templates).

## Contract and implementation

This page projects the named specification revision. Check [released engine status](/reference/status) and [the validation workflow](/guides/agent-authoring) before running a file. An optional field is not evidence that every engine supports every value.

Canonical identity: `language:word:fs`. Spec revision: [`c5ebbb7b862b`](https://github.com/supernovae-st/nika-spec/tree/c5ebbb7b862b68bc6cf7235efba61173b844afc6).

[How documentation stays connected](/reference/knowledge-system).
