Files
DevRunbook-Public/docs/PUBLICATION_READINESS.md
DevRunbook release export cfd2804e27
Managed validation / full (push) Successful in 3m18s
Publish DevRunbook source
2026-09-03 04:09:17 +02:00

56 lines
3.0 KiB
Markdown

# Publication readiness
This file separates repository changes that can be verified in source from
launch choices that require the repository owner or hosting operator. It is not
a substitute for branch protection or a release checklist on the public forge.
## Completed in the publication candidate
- The product README describes the implemented platform, user workflows,
installation, development, architecture, limitations and security boundary.
- The development Compose stack is loopback-only and no longer ships a shared
bootstrap token. The production reference also binds HTTP to loopback and
requires an explicit externally visible base URL.
- The unauthenticated first-run setup endpoint enforces a 16 KiB body limit for
both declared and streamed requests before JSON parsing.
- Private validation addresses were removed from the current tree.
- Gitea validation runs on `main` and change branches and includes the actual
unit, integration and security suites.
- The repository is MIT-licensed and a redacted history scan found no committed
secret.
- `SECURITY.md` publishes a fixed private reporting address.
- The project icons have an explicit origin and license notice.
- `scripts/export-public-source.sh` creates a parentless public candidate,
removes the private deployment workflow and rejects private deployment
markers, forbidden secret files and oversized files.
- Pull requests from public forks cannot run on the self-hosted validation
runner.
## Owner confirmations before making the repository public
1. **Public forge policy — recommended:** protect `main`, require the managed
validation job and one approving review, disallow force pushes, and create
signed version tags from reviewed commits.
2. **Images and Unraid — recommended:** choose the public registry/image name,
publish immutable multi-platform digests plus an SBOM and provenance, then
complete the registry, support and template URLs in `unraid/devrunbook.xml`.
3. **Production deploy approval — recommended:** place the external Unraid deploy
controller behind a protected environment/manual approval. Its implementation
is outside this repository and must independently enforce repository and
revision allowlists, backups, health checks and rollback.
The private canonical history must remain private: old commits contain
private-network validation addresses and work-domain author metadata. Publish
only the parentless export produced from a reviewed commit; do not rewrite the
shared private history.
## Evidence note
`release-evidence.json`, `evidence/performance-report.json` and
`evidence/security-scan-report.md` preserve evidence for earlier release-candidate
commits. They must be regenerated for the final tagged commit after managed CI,
container scanning, performance validation and a restore drill. Likewise,
`FILE_INDEX.txt` and `PACK_MANIFEST.sha256` belong to the historical version 1.2
implementation-contract archive; they are not an inventory of the current Git
tree.