3.0 KiB
Publication readiness
This file separates repository changes that can be verified in source from launch choices that require the repository owner or hosting operator. It is not a substitute for branch protection or a release checklist on the public forge.
Completed in the publication candidate
- The product README describes the implemented platform, user workflows, installation, development, architecture, limitations and security boundary.
- The development Compose stack is loopback-only and no longer ships a shared bootstrap token. The production reference also binds HTTP to loopback and requires an explicit externally visible base URL.
- The unauthenticated first-run setup endpoint enforces a 16 KiB body limit for both declared and streamed requests before JSON parsing.
- Private validation addresses were removed from the current tree.
- Gitea validation runs on
mainand change branches and includes the actual unit, integration and security suites. - The repository is MIT-licensed and a redacted history scan found no committed secret.
SECURITY.mdpublishes a fixed private reporting address.- The project icons have an explicit origin and license notice.
scripts/export-public-source.shcreates a parentless public candidate, removes the private deployment workflow and rejects private deployment markers, forbidden secret files and oversized files.- Pull requests from public forks cannot run on the self-hosted validation runner.
Owner confirmations before making the repository public
- Public forge policy — recommended: protect
main, require the managed validation job and one approving review, disallow force pushes, and create signed version tags from reviewed commits. - Images and Unraid — recommended: choose the public registry/image name,
publish immutable multi-platform digests plus an SBOM and provenance, then
complete the registry, support and template URLs in
unraid/devrunbook.xml. - Production deploy approval — recommended: place the external Unraid deploy controller behind a protected environment/manual approval. Its implementation is outside this repository and must independently enforce repository and revision allowlists, backups, health checks and rollback.
The private canonical history must remain private: old commits contain private-network validation addresses and work-domain author metadata. Publish only the parentless export produced from a reviewed commit; do not rewrite the shared private history.
Evidence note
release-evidence.json, evidence/performance-report.json and
evidence/security-scan-report.md preserve evidence for earlier release-candidate
commits. They must be regenerated for the final tagged commit after managed CI,
container scanning, performance validation and a restore drill. Likewise,
FILE_INDEX.txt and PACK_MANIFEST.sha256 belong to the historical version 1.2
implementation-contract archive; they are not an inventory of the current Git
tree.