Skip to content

feat: launch the public documentation platform - #1

Merged
litroc merged 10 commits into
developfrom
feat/public-documentation-platform
Jul 15, 2026
Merged

feat: launch the public documentation platform#1
litroc merged 10 commits into
developfrom
feat/public-documentation-platform

Conversation

@litroc

@litroc litroc commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Outcome

Introduces the public Lightning IT documentation platform for docs.l-it.io: a pinned Docusaurus build, product-oriented information architecture, local Pagefind search, strict security headers, accessibility and browser coverage, reproducible release evidence, and a public-safe re-authored documentation corpus.

Every migration-derived page remains review-candidate with approval_status: pending. This PR does not assert accountable human content approval, migration acceptance, source deletion authorization, or production deployment.

Scope

  • ModuLix, IO, Wunderbox, and Atlas as peer product sections
  • cross-product architecture, security, compliance, support, lifecycle, glossary, and contribution guidance
  • 18 independently re-authored implementation candidates plus consolidated public governance and BSI mapping
  • visible ownership, approver, audience, classification, status, and review metadata
  • custom hydrated 404, responsive navigation, dark mode, tabs, accessible Mermaid, SEO metadata, sitemap, and local Pagefind search
  • standards-based generated-HTML validation, exact-origin route checks, byte-exact CSP hashes, and text-only rendering of untrusted search excerpts
  • Apache-2.0 licensing, third-party notices, deterministic SBOMs, provenance, and release evidence
  • required CI, dependency review, CodeQL, Scorecard, scheduled validation, and commit-bound preview/production acceptance workflows

Migration boundary

A restricted review covered the complete source inventory. Only the previously approved coarse total is public; paths, source identities, detailed classifications, findings, and dispositions remain restricted. No private Git history or source document was copied directly. Public concepts were independently re-authored and sanitized.

The public target index records 20 canonical target documents at content commit 7727957e35b720ad22f81df9986b350e07c9e691; semantic, security, and licensing approvals remain pending. Source deletion remains fail-closed on human review, preview, production, recovery tagging, and private cleanup evidence.

Validation

  • format, ESLint, markdownlint, cspell, TypeScript, metadata, content, migration-index, and license checks pass
  • full and production dependency audits report zero vulnerabilities
  • 20 component tests and 20 server-validation tests pass
  • 37/37 browser and automated accessibility tests pass; the close/reopen search race also passes 20/20 stress repetitions
  • all required search terms resolve, including the migrated public role term lit.rhel.baseline
  • 73 generated HTML files, 71 canonical routes, and 4,249 first-party references validate
  • 69 unique public external HTTPS links validate with authenticated GitHub rate limits
  • Lighthouse budgets pass for home, ModuLix, and security
  • exact cache policy, MIME type, compression, TLS, canonical route, 404, and final deployment-marker evidence is enforced
  • failed production acceptance overwrites stale passing evidence

Merge requirement

Use a merge commit for this PR. Do not squash or rebase: the public migration index intentionally binds to the immutable content commit above and CI fails closed if that commit is not preserved in history.

Intentional release gates

  • accountable product, security, technical, and licensing reviewers must approve the exact pending documents
  • GitHub-management and Cloudflare-management changes require their own protected promotions
  • scoped Cloudflare credentials, GitHub App repository narrowing, live preview validation, production validation, and source cleanup remain pending

Safety boundary

This changes only the public documentation repository. It does not modify the TYPO3 site at l-it.io, the customer portal at portal.l-it.io, or unrelated Cloudflare resources.

litroc added 4 commits July 15, 2026 01:32
Signed-off-by: litroc <litroc@users.noreply.github.com>
Signed-off-by: litroc <litroc@users.noreply.github.com>
Signed-off-by: litroc <litroc@users.noreply.github.com>
Signed-off-by: litroc <litroc@users.noreply.github.com>
@litroc
litroc requested a review from litdeg July 15, 2026 01:35
Signed-off-by: litroc <litroc@users.noreply.github.com>
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread scripts/generate-csp-hashes.mjs Fixed
Comment thread scripts/lib/validation.mjs Fixed
Comment thread scripts/validate-site.mjs Fixed
Comment thread scripts/validate-site.mjs Fixed
Comment thread src/components/GlobalSearch/HighlightedExcerpt.tsx Fixed
@litroc

litroc commented Jul 15, 2026

Copy link
Copy Markdown
Contributor Author

Human content-review handoff for head ebea806c7b322ed09e0aee4a148d69b3f8e9f67f:

  • exact 65-document content-tree SHA-256: e945cd49123213d4c1d8c3aeb03fbd68b33b384f145219e4481f3b51d8fe7612
  • Product Owners scope: 54 documents, decision pending
  • Security and Compliance Maintainers scope: 11 documents, decision pending

The committed authority policy intentionally has no authorized GitHub identities yet. An organization owner must populate and authorize those role mappings, then the named reviewers must approve this exact digest/ID set and the documents must be marked maintained/approved. This comment is a review request, not an approval record.

@litroc
litroc merged commit 5d75df4 into develop Jul 15, 2026
4 checks passed
@litroc
litroc deleted the feat/public-documentation-platform branch July 15, 2026 03:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants