Files
DevRunbook-Public/docs/PUBLICATION_READINESS.md
DevRunbook release export cfd2804e27
Managed validation / full (push) Successful in 3m18s
Publish DevRunbook source
2026-09-03 04:09:17 +02:00

3.0 KiB

Publication readiness

This file separates repository changes that can be verified in source from launch choices that require the repository owner or hosting operator. It is not a substitute for branch protection or a release checklist on the public forge.

Completed in the publication candidate

  • The product README describes the implemented platform, user workflows, installation, development, architecture, limitations and security boundary.
  • The development Compose stack is loopback-only and no longer ships a shared bootstrap token. The production reference also binds HTTP to loopback and requires an explicit externally visible base URL.
  • The unauthenticated first-run setup endpoint enforces a 16 KiB body limit for both declared and streamed requests before JSON parsing.
  • Private validation addresses were removed from the current tree.
  • Gitea validation runs on main and change branches and includes the actual unit, integration and security suites.
  • The repository is MIT-licensed and a redacted history scan found no committed secret.
  • SECURITY.md publishes a fixed private reporting address.
  • The project icons have an explicit origin and license notice.
  • scripts/export-public-source.sh creates a parentless public candidate, removes the private deployment workflow and rejects private deployment markers, forbidden secret files and oversized files.
  • Pull requests from public forks cannot run on the self-hosted validation runner.

Owner confirmations before making the repository public

  1. Public forge policy — recommended: protect main, require the managed validation job and one approving review, disallow force pushes, and create signed version tags from reviewed commits.
  2. Images and Unraid — recommended: choose the public registry/image name, publish immutable multi-platform digests plus an SBOM and provenance, then complete the registry, support and template URLs in unraid/devrunbook.xml.
  3. Production deploy approval — recommended: place the external Unraid deploy controller behind a protected environment/manual approval. Its implementation is outside this repository and must independently enforce repository and revision allowlists, backups, health checks and rollback.

The private canonical history must remain private: old commits contain private-network validation addresses and work-domain author metadata. Publish only the parentless export produced from a reviewed commit; do not rewrite the shared private history.

Evidence note

release-evidence.json, evidence/performance-report.json and evidence/security-scan-report.md preserve evidence for earlier release-candidate commits. They must be regenerated for the final tagged commit after managed CI, container scanning, performance validation and a restore drill. Likewise, FILE_INDEX.txt and PACK_MANIFEST.sha256 belong to the historical version 1.2 implementation-contract archive; they are not an inventory of the current Git tree.