2026-08-17 13:03:13 +00:00
|
|
|
# policy-nexus
|
|
|
|
|
|
2026-08-18 12:16:04 +02:00
|
|
|
Permanent publication for the estate's policy surface. Serves
|
|
|
|
|
`policy.coulomb.social`.
|
Scope: canon and ADRs outward, estate-bearing regulation inward
Operator answered the two blocking questions, so T06 is now specifiable and
T03 has a bounded corpus: two canon trees and roughly 68 ADRs across 18
repositories. Workplans, evidence and runbooks are out - a site that publishes
everything publishes nothing in particular.
T06 gains an inclusion test (does the rule constrain something the estate
actually does), a record format, and a candidate register drawn from what the
estate demonstrably touches rather than from a list of well-known regulations -
data protection and erasure, residency, procurement via vergabe-teilnahme,
identity assurance via the aal2 class, and the agentic tenant grouping. The
register is to confirm, not to assume.
The hard rule is now in the format itself: a record states what a source said
and when. Interpretation belongs to the repo making the decision. The estate
has no legal function and this repo must not grow one by accident.
Rewrote the README, which described a broader civic corpus than the repo is
scoped to and would have attracted the wrong contributions.
One question got sharper rather than resolved: publishing every ADR across 18
repos puts the estate's architecture, known gaps and residual risks in one
indexed public place. That is right for a document consumers must read, and it
is a decision to take deliberately rather than inherit from a default.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:27:02 +02:00
|
|
|
|
2026-08-18 12:16:04 +02:00
|
|
|
This repo publishes estate **canon and architecture decision records** from
|
|
|
|
|
the repositories that own them, at stable URLs, with visible status and
|
|
|
|
|
currency. Pages are generated, never authored here: the source of truth stays
|
|
|
|
|
upstream and this repo never writes back.
|
Scope: canon and ADRs outward, estate-bearing regulation inward
Operator answered the two blocking questions, so T06 is now specifiable and
T03 has a bounded corpus: two canon trees and roughly 68 ADRs across 18
repositories. Workplans, evidence and runbooks are out - a site that publishes
everything publishes nothing in particular.
T06 gains an inclusion test (does the rule constrain something the estate
actually does), a record format, and a candidate register drawn from what the
estate demonstrably touches rather than from a list of well-known regulations -
data protection and erasure, residency, procurement via vergabe-teilnahme,
identity assurance via the aal2 class, and the agentic tenant grouping. The
register is to confirm, not to assume.
The hard rule is now in the format itself: a record states what a source said
and when. Interpretation belongs to the repo making the decision. The estate
has no legal function and this repo must not grow one by accident.
Rewrote the README, which described a broader civic corpus than the repo is
scoped to and would have attracted the wrong contributions.
One question got sharper rather than resolved: publishing every ADR across 18
repos puts the estate's architecture, known gaps and residual risks in one
indexed public place. That is right for a document consumers must read, and it
is a decision to take deliberately rather than inherit from a default.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:27:02 +02:00
|
|
|
|
2026-08-18 12:16:04 +02:00
|
|
|
Regulatory intake and disclosure decisions belong to `risk-nexus`; publishable
|
|
|
|
|
records may arrive from it like any other source. This repo does not interpret
|
|
|
|
|
them.
|
Scope: canon and ADRs outward, estate-bearing regulation inward
Operator answered the two blocking questions, so T06 is now specifiable and
T03 has a bounded corpus: two canon trees and roughly 68 ADRs across 18
repositories. Workplans, evidence and runbooks are out - a site that publishes
everything publishes nothing in particular.
T06 gains an inclusion test (does the rule constrain something the estate
actually does), a record format, and a candidate register drawn from what the
estate demonstrably touches rather than from a list of well-known regulations -
data protection and erasure, residency, procurement via vergabe-teilnahme,
identity assurance via the aal2 class, and the agentic tenant grouping. The
register is to confirm, not to assume.
The hard rule is now in the format itself: a record states what a source said
and when. Interpretation belongs to the repo making the decision. The estate
has no legal function and this repo must not grow one by accident.
Rewrote the README, which described a broader civic corpus than the repo is
scoped to and would have attracted the wrong contributions.
One question got sharper rather than resolved: publishing every ADR across 18
repos puts the estate's architecture, known gaps and residual risks in one
indexed public place. That is right for a document consumers must read, and it
is a decision to take deliberately rather than inherit from a default.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:27:02 +02:00
|
|
|
|
2026-08-18 12:16:04 +02:00
|
|
|
Not a CMS, not a documentation site, not a policy author, and not a source of
|
|
|
|
|
legal advice.
|
Scope: canon and ADRs outward, estate-bearing regulation inward
Operator answered the two blocking questions, so T06 is now specifiable and
T03 has a bounded corpus: two canon trees and roughly 68 ADRs across 18
repositories. Workplans, evidence and runbooks are out - a site that publishes
everything publishes nothing in particular.
T06 gains an inclusion test (does the rule constrain something the estate
actually does), a record format, and a candidate register drawn from what the
estate demonstrably touches rather than from a list of well-known regulations -
data protection and erasure, residency, procurement via vergabe-teilnahme,
identity assurance via the aal2 class, and the agentic tenant grouping. The
register is to confirm, not to assume.
The hard rule is now in the format itself: a record states what a source said
and when. Interpretation belongs to the repo making the decision. The estate
has no legal function and this repo must not grow one by accident.
Rewrote the README, which described a broader civic corpus than the repo is
scoped to and would have attracted the wrong contributions.
One question got sharper rather than resolved: publishing every ADR across 18
repos puts the estate's architecture, known gaps and residual risks in one
indexed public place. That is right for a document consumers must read, and it
is a decision to take deliberately rather than inherit from a default.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:27:02 +02:00
|
|
|
|
|
|
|
|
- Intent: `INTENT.md`
|
2026-08-18 22:16:02 +02:00
|
|
|
- Owner publication contract: `docs/publication-contract.md`
|
|
|
|
|
- ADR review ledger (unpublished work artefact): `docs/adr-review/`
|
Scope: canon and ADRs outward, estate-bearing regulation inward
Operator answered the two blocking questions, so T06 is now specifiable and
T03 has a bounded corpus: two canon trees and roughly 68 ADRs across 18
repositories. Workplans, evidence and runbooks are out - a site that publishes
everything publishes nothing in particular.
T06 gains an inclusion test (does the rule constrain something the estate
actually does), a record format, and a candidate register drawn from what the
estate demonstrably touches rather than from a list of well-known regulations -
data protection and erasure, residency, procurement via vergabe-teilnahme,
identity assurance via the aal2 class, and the agentic tenant grouping. The
register is to confirm, not to assume.
The hard rule is now in the format itself: a record states what a source said
and when. Interpretation belongs to the repo making the decision. The estate
has no legal function and this repo must not grow one by accident.
Rewrote the README, which described a broader civic corpus than the repo is
scoped to and would have attracted the wrong contributions.
One question got sharper rather than resolved: publishing every ADR across 18
repos puts the estate's architecture, known gaps and residual risks in one
indexed public place. That is right for a document consumers must read, and it
is a decision to take deliberately rather than inherit from a default.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:27:02 +02:00
|
|
|
- Workplans: `workplans/`
|
2026-08-18 12:16:04 +02:00
|
|
|
|
|
|
|
|
Build and verify the publication locally with:
|
|
|
|
|
|
|
|
|
|
```sh
|
|
|
|
|
make check
|
|
|
|
|
make build
|
|
|
|
|
make currency
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
`publication.json` is the explicit source and address registry. A build fails
|
|
|
|
|
closed when a source is unavailable or an immutable revision would change.
|
2026-08-18 13:25:49 +02:00
|
|
|
`source-inventory.config.json` defines the bounded canon/ADR discovery scope,
|
|
|
|
|
while `source-inventory.json` records an explicit reviewed disposition for every
|
|
|
|
|
matching source. `make source-audit` fails when a source appears or disappears
|
|
|
|
|
without that review. Working-tree-only files in sibling repos do not affect the
|
|
|
|
|
audit; local checks inspect committed Git trees.
|
|
|
|
|
|
|
|
|
|
The Forgejo workflow pulls exact `main` revisions for all inventoried source
|
|
|
|
|
repos every day at 04:17 UTC and on manual dispatch. It fails visibly on an
|
|
|
|
|
unavailable source, unreviewed inventory drift, invalid release, or overdue
|
|
|
|
|
published document. Successful runs publish immutable `source-<source-set-digest>`
|
|
|
|
|
candidates and a moving discovery tag, but never deploy them. Production
|
|
|
|
|
promotion remains an explicit review of the registry-resolved OCI digest and
|
|
|
|
|
publication-manifest digest together in `rapp-policy-nexus` and
|
|
|
|
|
`railiance-apps`.
|
2026-08-18 12:16:04 +02:00
|
|
|
|
|
|
|
|
Production publication is split from runtime ownership. This repository builds
|
|
|
|
|
and publishes the immutable OCI site image; `rapp-policy-nexus` owns the Helm
|
|
|
|
|
package, exposure checks, and rollback; `railiance-apps` selects the approved
|
|
|
|
|
production digests. A release build additionally refuses dirty or synthetic
|
|
|
|
|
source provenance:
|
|
|
|
|
|
|
|
|
|
```sh
|
|
|
|
|
make release-build
|
|
|
|
|
make image-build IMAGE_REF=forgejo.coulomb.social/coulomb/policy-nexus:git-$(git rev-parse HEAD)
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Tags are discovery handles only. Production always records the registry-resolved
|
|
|
|
|
OCI digest and the SHA-256 of `build/publication-manifest.json`.
|