44 lines
1.5 KiB
Markdown
44 lines
1.5 KiB
Markdown
# policy-nexus
|
|
|
|
Permanent publication for the estate's policy surface. Serves
|
|
`policy.coulomb.social`.
|
|
|
|
This repo publishes estate **canon and architecture decision records** from
|
|
the repositories that own them, at stable URLs, with visible status and
|
|
currency. Pages are generated, never authored here: the source of truth stays
|
|
upstream and this repo never writes back.
|
|
|
|
Regulatory intake and disclosure decisions belong to `risk-nexus`; publishable
|
|
records may arrive from it like any other source. This repo does not interpret
|
|
them.
|
|
|
|
Not a CMS, not a documentation site, not a policy author, and not a source of
|
|
legal advice.
|
|
|
|
- Intent: `INTENT.md`
|
|
- Workplans: `workplans/`
|
|
|
|
Build and verify the publication locally with:
|
|
|
|
```sh
|
|
make check
|
|
make build
|
|
make currency
|
|
```
|
|
|
|
`publication.json` is the explicit source and address registry. A build fails
|
|
closed when a source is unavailable or an immutable revision would change.
|
|
|
|
Production publication is split from runtime ownership. This repository builds
|
|
and publishes the immutable OCI site image; `rapp-policy-nexus` owns the Helm
|
|
package, exposure checks, and rollback; `railiance-apps` selects the approved
|
|
production digests. A release build additionally refuses dirty or synthetic
|
|
source provenance:
|
|
|
|
```sh
|
|
make release-build
|
|
make image-build IMAGE_REF=forgejo.coulomb.social/coulomb/policy-nexus:git-$(git rev-parse HEAD)
|
|
```
|
|
|
|
Tags are discovery handles only. Production always records the registry-resolved
|
|
OCI digest and the SHA-256 of `build/publication-manifest.json`.
|