Files

1.7 KiB

Canonical repository and deployment rules

This repository is authoritative only for its owned component. Use sibling clones of https://git.qomar.pw/otche/otche-backend.git, https://git.qomar.pw/otche/otche-frontend.git and https://git.qomar.pw/otche/otche-deploy.git. Keep API/worker/watchdog in one backend Go module and separate runtime processes. Never copy private operational workspaces over these sources.

Edit here, prove the affected behavior, audit the explicit file allowlist, commit/push normally, then fetch reviewed full commits into the deployment host clones. Deploy through otche-deploy/update.py and its documented protected external env/override. No archive-based source deployment, force/reset, dirty-work overwrite or unreviewed latest-branch activation. Coordinate quiescence before activation; retain the exact existing Compose project, external named volumes, private secrets/TLS/config/proofs and held evidence. Verify live commit IDs, health, old-data continuity and requested acceptance after rollout.

Never commit real secrets, tokens, runtime output, sample payloads, proof logs, private certificates or live host inventory. No credentials in remote URLs or persistent helpers. Windows signing remains operator-supplied. Do not weaken VM/network/Windows protections to pass acceptance.

Windows display names

The complete Windows display label, including build/version text, is explicitly authored in editable Profile.name. NEVER derive or append the display build from environment telemetry, qualification, a revision lookup or a frontend formatter. Each Run stores an immutable profile_name snapshot; profile renames do not rewrite historical names. Technical environment.os_build telemetry and source fingerprints remain separate and unchanged.