commit 4474c461b9b8175461ca8a49d932949053a8e6fb
parent c6f8a5ace100bfe0abf1c1c03796d82f53f11f5c
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date: Mon, 28 Sep 2026 13:13:38 -0400
docs: PUBLISH.md's container section says what the per-site mount keeps and what the image bakes
The per-site mount no longer holds .next (it stays in the container), out/
carries the composed public/ and nothing baked, and both the container and the
deploy phase refuse a bundle that does not name its site. The image bakes
common/ and export/ through Dockerfile.build.dockerignore's allow-list, and
archilyzer doctor reports its age.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Diffstat:
1 file changed, 15 insertions(+), 7 deletions(-)
diff --git a/PUBLISH.md b/PUBLISH.md
@@ -405,11 +405,17 @@ serial host build+deploy (one site at a time).
|---|---|---|
| `transcripts/` (corpus + `index.mdb` + archive cache) | `/data/transcripts` | ro |
| `export/.export-index` (shared + per-site staging) | `/data/export/.export-index` | ro |
-| `export/.export-builds/<siteId>` (public/out/.next/caches) | `/site` | rw |
+| `export/.export-builds/<siteId>` (public/, out/, .compose-cache) | `/site` | rw |
| `settings.json` (build config, mounted fresh — not baked) | `/data/settings.json` | ro |
-The per-site `/site` mount is persistent, so incremental `next build` (`.next`) and
-incremental compose (`.compose-cache`) stay warm across builds.
+The per-site `/site` mount is persistent, so incremental compose (`.compose-cache`)
+stays warm across builds. `next build` runs in the container's own `.next` and starts
+fresh each time. A Turbopack production build keeps no cache between runs anyway.
+The container's `export/public` is a link to the composed `/site/public`, so `out/`
+carries this site's data and nothing baked into the image. Before handing `out/`
+back, the container checks that its `site.json` and `corpus.json` both name the site,
+and the deploy phase checks again. A bundle that names another site, or no site, is
+refused.
**Tuning.**
@@ -422,10 +428,12 @@ incremental compose (`.compose-cache`) stay warm across builds.
per-site archive materialize for a faster build with no download bundles.
**Notes.** Containers run as your host uid/gid (`-u`), so files under
-`.export-builds/` are host-owned, not root-owned. The image bakes the repo source and
-deps; a code change rebuilds it, but layer caching keeps that cheap (deps re-install
-only when the lockfile moves). `.export-builds/` is gitignored and excluded from the
-image build context. The editor mounts the host's `docker/build-site.sh` over the
+`.export-builds/` are host-owned, not root-owned. The image bakes the export build's
+source (common/, export/) and its deps; a code change rebuilds it, but layer caching
+keeps that cheap (deps re-install only when the lockfile moves). Its build context is
+the allow-list in `Dockerfile.build.dockerignore`, about 7 MB from any checkout. It
+never includes the corpus, generated `export/public` data or `.export-builds/`.
+`archilyzer doctor` says whether the image is there and older than its Dockerfile. The editor mounts the host's `docker/build-site.sh` over the
baked one, so an image older than the checkout still runs today's script.
---