commit a10aaee063474547d06a1c60f8c844524a37d1fa
parent 195a9d6e67e499496dab4da28925a26155924ff8
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date: Mon, 28 Sep 2026 15:12:44 -0400
docs: AGENTS.md "The source mirror" — what the step is, never print the operator files, never bypass the gate, no `.git` segment
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Diffstat:
1 file changed, 20 insertions(+), 0 deletions(-)
diff --git a/AGENTS.md b/AGENTS.md
@@ -339,6 +339,26 @@ The editor's `instrumentation.ts` arms the runners on boot, which resumes long-r
sweeps against production data. To exercise `common/` controllers over the real corpus,
run them offline with `tsx` instead of starting a server.
+# The source mirror
+
+`archilyzer source publish` (`common/publish/source.ts`), which `archilyzer build homepage` and
+the `/sites` Homepage jobs run, puts this repo on the project site read-only:
+- a fresh clone of `main`, scrubbed by git-filter-repo;
+- audited against a denylist, every object and every file;
+- published as a dumb-HTTP mirror at `/source/archilyzer.git/`, a raw tree and a tarball.
+
+**A refusal withdraws the previous publish** from `public/` and `out/`, and `deploy homepage`
+refuses a source it cannot vouch for.
+- **The operator's two files live OUTSIDE the repo** (`~/.config/archilyzer/source-scrub.txt`,
+ `source-denylist.txt`). **Never print, cat, quote, log or commit them** — they hold the private
+ strings the gate keeps off the site. Code reads them; you may count lines or check a mode.
+- **Never bypass the gate.** No denylist or scrub file of your own, no hand-edited
+ `homepage/.source-publish.json`. A refusal is fixed by an operator scrub rule, or by removing the
+ text from history.
+- **Never publish a path segment named `.git`:** wrangler's upload drops it silently.
+
+Everything else is in [PUBLISH.md](PUBLISH.md), "The source mirror (homepage)".
+
# Roadmap
Long-running work on the local-AI derived corpus is tracked in [PLAN.md](PLAN.md).