policy-nexus/README.md
tegwick c1b60f322e
All checks were successful
Build and publish policy-nexus image / build-and-push (push) Successful in 1m10s
feat: publish Risk Nexus findings and methods
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 01:56:46 +02:00

60 lines
2.5 KiB
Markdown

# policy-nexus
Permanent publication for the estate's policy surface. Serves
`policy.coulomb.social`.
This repo publishes estate **canon, architecture decisions, and explicitly
disclosed risk records** from the repositories that own them, at stable URLs,
with visible status and currency. Pages are generated, never authored here:
the source of truth stays upstream and this repo never writes back.
Regulatory intake and disclosure decisions belong to `risk-nexus`; publishable
records may arrive from it like any other source. This repo does not interpret
them.
Not a CMS, not a documentation site, not a policy author, and not a source of
legal advice.
- Intent: `INTENT.md`
- Owner publication contract: `docs/publication-contract.md`
- ADR review ledger (unpublished work artefact): `docs/adr-review/`
- Workplans: `workplans/`
Build and verify the publication locally with:
```sh
make check
make build
make currency
```
`publication.json` is the explicit source and address registry. A build fails
closed when a source is unavailable or an immutable revision would change.
`source-inventory.config.json` defines the bounded canon/ADR discovery scope,
while `source-inventory.json` records an explicit reviewed disposition for every
matching source. `make source-audit` fails when a source appears or disappears
without that review. Working-tree-only files in sibling repos do not affect the
audit; local checks inspect committed Git trees.
The Forgejo workflow pulls exact `main` revisions for all inventoried source
repos every day at 04:17 UTC and on manual dispatch. It fails visibly on an
unavailable source, unreviewed inventory drift, invalid release, or overdue
published document. Successful runs publish immutable `source-<source-set-digest>`
candidates and a moving discovery tag, but never deploy them. Production
promotion remains an explicit review of the registry-resolved OCI digest and
publication-manifest digest together in `rapp-policy-nexus` and
`railiance-apps`.
Production publication is split from runtime ownership. This repository builds
and publishes the immutable OCI site image; `rapp-policy-nexus` owns the Helm
package, exposure checks, and rollback; `railiance-apps` selects the approved
production digests. A release build additionally refuses dirty or synthetic
source provenance:
```sh
make release-build
make image-build IMAGE_REF=forgejo.coulomb.social/coulomb/policy-nexus:git-$(git rev-parse HEAD)
```
Tags are discovery handles only. Production always records the registry-resolved
OCI digest and the SHA-256 of `build/publication-manifest.json`.