ADR-0021: Public Publication Boundary

Status

ACCEPTED. This page supersedes the older [internal-host] Cloud publication note from 2026-05-31.

Context

kryssar.se is the public portfolio surface for Chaos Gremlin Engineering. It should show the work clearly: lab architecture, SAGA range progress, public-safe decisions, CTF writeups, and selected research notes.

The private lab still contains operational state, evidence paths, internal hostnames, raw telemetry, credentials, tokens, and unfinished planning notes. Those belong in the internal repositories and must not leak into the public site.

The current public site is built from the kryssar-public-site repository and deployed to the Loopia webhotel through the guarded publish pipeline. [internal-host] Cloud is not the active publication path for kryssar.se.

Decision

Use a three-stage publication boundary:

  1. 01Private CGE workspace

    State, evidence, and internal docs stay private.

  2. 02Curate and sanitize

    Only reviewed public-safe material moves forward.

  3. 03Astro static build

    `npm run validate` writes the audited `public_html/` artifact.

  4. 04Publication gate

    Content, link, asset, unsafe HTML, and leak checks must pass.

  5. 05Loopia webhotel

    The approved `public_html/` artifact is transferred and verified.

Only sanitized, portfolio-safe content crosses from the private workspace into the public build.

Publication Rules

Rule Public behavior
Secrets and credentials Never publish. Replace with public-safe labels.
Internal paths and evidence stores Describe by role, not filesystem path.
Internal IPs and host details Publish only when deliberately sanitized or structurally useful.
Generated state pages Rebuild from current state before deploy.
Obsolete migration notes Draft or remove when they contradict the live site.
Diagrams Render as visible diagrams, not raw Mermaid or broken image placeholders.

Current Flow

  1. Curated sync tooling refreshes public-safe source content from current state and selected source documents.
  2. npm run validate runs the Astro compiler and writes public-information/kryssar.se/public_html.
  3. public-site-audit.py --ci blocks broken local links, missing assets, stale implementation pages, leaked internal paths, unsafe HTML, malformed Mermaid blocks, and redaction prompt boilerplate.
  4. public_sync_workflow/run_public_sync.sh --dry-run-loopia previews the exact public_html/ transfer to Loopia.
  5. PUBLIC_SYNC_APPROVE_LOOPIA=1 public_sync_workflow/run_public_sync.sh --publish-loopia performs the live transfer after operator approval.
  6. External HTTPS route checks verify the published site before declaring success.

Consequences

  • The public site remains a representation of the operator and the lab, not an automated dump of internal notes.
  • Publication quality now depends on both source curation and automated gates.
  • ADRs and roadmap pages must be reviewed as public-facing prose, especially when old generated documents are promoted into kryssar.se.
  • Rendered-page checks are required when content uses diagrams, custom HTML, or generated dashboard fragments.

Related

  • scripts/public-site-audit.py -- static publication-quality gate
  • public_sync_workflow/run_public_sync.sh -- Astro validation, Loopia dry-run, and approval-gated publish wrapper