Skip to content

Docs: record native build provenance - #9

Merged
tony merged 2 commits into
masterfrom
docs-site-provenance
Sep 30, 2026
Merged

tony merged 2 commits into
masterfrom
docs-site-provenance

Conversation

@tony

@tony tony commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

The native docs build now records the selected source, native exporter and shared docs revisions before generation. The uploaded content has an exact artifact descriptor, which the shared publisher verifies before requesting AWS credentials.

The three checkouts are siblings, and selected-source builds restore no executable caches. Existing source-ref selection, release aliases, fork build-only behavior and PR preview cleanup remain unchanged. Both shared docs pins use 42dd5b71e6eefd785b9bf8ce11d34e8f1a058a22.

Validation:

  • Full outer gate passed in 40.00s on Ruby 4.0.7.
  • Four workflow regressions passed; missing-snapshot and missing-digest mutations fail.
  • The native exporter produced 693 methods from a clean selected source checkout.

The hosted preview run will establish the complete native-build-to-publication chain.

why: Native docs need the same source and artifact verification as shared
builds before the publisher receives AWS credentials.

what:
- Keep source, native exporter and shared docs checkouts separate.
- Record clean input revisions before generation and upload an exact
  artifact descriptor for the reviewed shared publisher.
- Disable executable caches for selected source builds and cover the
  snapshot, descriptor and paired workflow pins in focused regressions.
why: Ruby MCP discovery queries a live server. The previous shared
generator created a private socket directory but did not start its daemon,
so an isolated hosted build failed before publication.

what:
- Pin both the docs checkout and publisher to the reviewed generator fix
- Keep source selection and artifact publication contracts unchanged
- Verify the four workflow cases and full outer gate in 37.05 seconds

The publisher revision is approved in all 12 live IAM trust policies.
Hosted publication remains to be checked at this caller revision.
@tony
tony deployed to docs-preview September 30, 2026 01:22 — with GitHub Actions Active
@tony
tony marked this pull request as ready for review September 30, 2026 01:36
@tony
tony merged commit 508d118 into master Sep 30, 2026
77 of 79 checks passed
@tony
tony deployed to docs-preview-cleanup September 30, 2026 01:37 — with GitHub Actions Active
tony added a commit that referenced this pull request Sep 30, 2026
what:
- Record source, native exporter, and shared docs revisions
- Describe the exact uploaded artifact before publication
- Build from sibling checkouts without executable caches

why:
The publisher needs to verify that native Ruby documentation came from
the selected clean source and reviewed build tools before it requests
credentials or uploads to the site.

This branch was successfully deployed

2 active deployments
docs-preview-cleanup — 2a9fe925 Deployed Sep 30, 2026 by tony via cleanup #7
docs-preview — 2a9fe925 Deployed Sep 30, 2026 by tony via publish (pr-9, pr, false, docs-preview, true) / publish #19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant