# policy-nexus Permanent publication for the estate's policy surface. Serves `policy.coulomb.social`. This repo publishes estate **canon, architecture decisions, and explicitly disclosed risk records** from the repositories that own them, at stable URLs, with visible status and currency. Pages are generated, never authored here: the source of truth stays upstream and this repo never writes back. Regulatory intake and disclosure decisions belong to `risk-nexus`; publishable records may arrive from it like any other source. This repo does not interpret them. Not a CMS, not a documentation site, not a policy author, and not a source of legal advice. - Intent: `INTENT.md` - Owner publication contract: `docs/publication-contract.md` - ADR review ledger (unpublished work artefact): `docs/adr-review/` - Workplans: `workplans/` Build and verify the publication locally with: ```sh make check make build make currency ``` `publication.json` is the explicit source and address registry. A build fails closed when a source is unavailable or an immutable revision would change. `source-inventory.config.json` defines the bounded canon/ADR discovery scope, while `source-inventory.json` records an explicit reviewed disposition for every matching source. `make source-audit` fails when a source appears or disappears without that review. Working-tree-only files in sibling repos do not affect the audit; local checks inspect committed Git trees. The Forgejo workflow pulls exact `main` revisions for all inventoried source repos every day at 04:17 UTC and on manual dispatch. It fails visibly on an unavailable source, unreviewed inventory drift, invalid release, or overdue published document. Successful runs publish immutable `source-` candidates and a moving discovery tag, but never deploy them. Production promotion remains an explicit review of the registry-resolved OCI digest and publication-manifest digest together in `rapp-policy-nexus` and `railiance-apps`. Production publication is split from runtime ownership. This repository builds and publishes the immutable OCI site image; `rapp-policy-nexus` owns the Helm package, exposure checks, and rollback; `railiance-apps` selects the approved production digests. A release build additionally refuses dirty or synthetic source provenance: ```sh make release-build make image-build IMAGE_REF=forgejo.coulomb.social/coulomb/policy-nexus:git-$(git rev-parse HEAD) ``` Tags are discovery handles only. Production always records the registry-resolved OCI digest and the SHA-256 of `build/publication-manifest.json`.