policy-nexus/README.md

44 lines
1.5 KiB
Markdown

# policy-nexus
Permanent publication for the estate's policy surface. Serves
`policy.coulomb.social`.
This repo publishes estate **canon and architecture decision records** from
the repositories that own them, at stable URLs, with visible status and
currency. Pages are generated, never authored here: the source of truth stays
upstream and this repo never writes back.
Regulatory intake and disclosure decisions belong to `risk-nexus`; publishable
records may arrive from it like any other source. This repo does not interpret
them.
Not a CMS, not a documentation site, not a policy author, and not a source of
legal advice.
- Intent: `INTENT.md`
- Workplans: `workplans/`
Build and verify the publication locally with:
```sh
make check
make build
make currency
```
`publication.json` is the explicit source and address registry. A build fails
closed when a source is unavailable or an immutable revision would change.
Production publication is split from runtime ownership. This repository builds
and publishes the immutable OCI site image; `rapp-policy-nexus` owns the Helm
package, exposure checks, and rollback; `railiance-apps` selects the approved
production digests. A release build additionally refuses dirty or synthetic
source provenance:
```sh
make release-build
make image-build IMAGE_REF=forgejo.coulomb.social/coulomb/policy-nexus:git-$(git rev-parse HEAD)
```
Tags are discovery handles only. Production always records the registry-resolved
OCI digest and the SHA-256 of `build/publication-manifest.json`.