# policy-nexus Permanent publication for the estate's policy surface. Serves `policy.coulomb.social`. This repo publishes estate **canon and architecture decision records** from the repositories that own them, at stable URLs, with visible status and currency. Pages are generated, never authored here: the source of truth stays upstream and this repo never writes back. Regulatory intake and disclosure decisions belong to `risk-nexus`; publishable records may arrive from it like any other source. This repo does not interpret them. Not a CMS, not a documentation site, not a policy author, and not a source of legal advice. - Intent: `INTENT.md` - Workplans: `workplans/` Build and verify the publication locally with: ```sh make check make build make currency ``` `publication.json` is the explicit source and address registry. A build fails closed when a source is unavailable or an immutable revision would change. Production publication is split from runtime ownership. This repository builds and publishes the immutable OCI site image; `rapp-policy-nexus` owns the Helm package, exposure checks, and rollback; `railiance-apps` selects the approved production digests. A release build additionally refuses dirty or synthetic source provenance: ```sh make release-build make image-build IMAGE_REF=forgejo.coulomb.social/coulomb/policy-nexus:git-$(git rev-parse HEAD) ``` Tags are discovery handles only. Production always records the registry-resolved OCI digest and the SHA-256 of `build/publication-manifest.json`.