Skip to content

CI-16: Public release/source mirror for the private development repository (SC-8 ruling 2026-09-03) #2439

Description

@Chris0Jeky

Wave: Smart CI Fabric (ADR-0066). Tracker: CI-00 #2324. Human gate it serves: CI-13 #2337 section A (public assets) — OUTSTANDING_TASKS.md §J SC-8.

Ruling this issue implements

Maintainer decision packet, 2026-09-03, SC8 = private development repository + public release/source mirror. Development, CI, issues and the control plane go private for v0.3.0 (ADR-0066); Releases, checksums/provenance and the GPL-3.0-only source stay public through a mirror repository. GitHub Pages keeps publishing (Pro allows it from a private repository). The launch kit and any awesome-selfhosted wording point at the mirror, not at the private repository.

Scope (agent-preparable)

  • Options memo, one page: (a) a separate public repository that receives a source snapshot per release tag plus the Release assets; (b) the same, but the whole history mirrored on every tag; (c) Releases only, source as a tarball attached to each Release. Score each against ADR-0050 (corresponding-source obligation), the checksum/provenance chain (release-desktop.yml), the awesome-selfhosted activity criteria, and the private-repository secret boundary (nothing in the mirror may carry a token, a runner label, or a private workflow).
  • The publishing mechanism for the chosen option: a tag-triggered workflow in the private repository that pushes the snapshot/history and re-publishes the Release assets with unchanged sha256s, fail-closed on any mismatch; the mirror repository has no Actions of its own that execute pushed code.
  • Docs: README.md install links, docs/product/LAUNCH_KIT.md ([Docs][Launch] Draft docs/product/LAUNCH_KIT.md for the v0.3.0 downloadable release (q-6 A) #2242), LICENSING.md corresponding-source pointer, docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md A/J, docs/REVIVAL_PLAN.md commitment 6 — all point at the mirror once it exists.
  • Rehearsal while still public: a no-publish dry run that proves the mirror push and asset re-publication on a prerelease tag.

Human-only

Acceptance

  • The chosen option is recorded on this issue with the memo linked; the mechanism is proven on a prerelease tag with unchanged asset hashes; every public-facing link above resolves to the mirror; OUTSTANDING_TASKS.md §J SC-8 stays [x] (decision made) and CI-13 section A carries the evidence.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Priority IIThe active direction's next tranche: wedge capabilities, significant defects, near-term hardening.ciCI/CD pipeline, workflow, and build infrastructure changes.strategyStrategic planning and direction

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions