How the Factory's docs and website are built for their public addresses, and who publishes them. Publishing them is the owner's decision of 29 September 2026: both sites, open to indexing, with local paths and archive links stripped and everything else kept. Private session identifiers are stripped too, under the owner's standing rule that private conversation links never go public. It releases no product: Factory stays local infrastructure in development, and all 27 customer-value epics remain open.
Build
npm run publish:build # writes docs/ and website/ under <local-cache>
node --test test/public-build.test.ts # the public build's own tests
node scripts/build-public.ts <outRoot> writes <outRoot>/docs and <outRoot>/website instead. The output is regenerable and never committed. The committed site/ and website/ stay the local builds, byte for byte, and the public build never writes inside the repository.
| Site | Address | Built from |
|---|---|---|
| Docs | https://docs.plumbfactory.fyi | The Markdown in docs/, by the docs site's builder |
| Website | https://plumbfactory.fyi | apps/website/, by the website's builder, with every honesty check it runs locally |
What changes for publication
- Local paths become placeholders. Every local machine path and archive location (home directories, other volumes, the evidence archive, the checkout's ignored evidence and state, machine temporary paths) is shown as a placeholder in angle brackets, such as
<local evidence archive>, always in code formatting, so sentences and code blocks keep their shape. The footer and the reference note say so. - Records are published. Each JSON file in
docs/, receipts included, becomes a record page with the same placeholders; every hash, date and count is as committed. A local path that is a key keeps its file's name, as in<local evidence file: portfolio-final.png>, so no two keys of one object become one and each hash still says which file it describes; a key that would still repeat another is numbered, as in<local evidence archive> (2). An image indocs/that a page links is copied. Any other repository file (source, tests, the README, the handover, the intent) is named without a link, and the website marks such evidence "(not published)". - Private session identifiers are removed. In a record, the value of a key naming a session or conversation (
session_id,session,thread_idand the like) becomes<private session 1>,<private session 2>and so on, one number for each session in that record, so entries that shared a session still share its number. Any other UUID in a record, such as the one in an image tool's output file name, becomes<private identifier 1>and so on. Each record's note says which of these apply to it. - The sites link each other. The website's links into the docs go to the public docs and must resolve there, anchors included; every docs page links back to the website.
- Indexing is allowed. The website drops its request not to be indexed. Each page names its canonical and Open Graph address, and each site has
robots.txtandsitemap.xml. - The capture is approved. The dashboard capture's frame says it shows the owner's real Portfolio, approved for publication on 29 September 2026. Its image is still held to the SHA-256 its receipt records.
What stops it
The build writes nothing, and lists every problem, when:
- any file of either site still holds a local path, a home directory, a private conversation link, a private conversation identifier (a UUID, a UUID written without hyphens as Notion writes a page's, or an identifier after a label such as
session_id), an email address or a token-like string (images are read too: their text chunks for all of these, their pixels and signed provenance for paths, links and labelled identifiers, since the provenance carries UUIDs of its own that name the image); - a placeholder falls outside code formatting;
- a link or image resolves neither inside the two sites nor to an outside web address, or names an anchor its page lacks;
- a page's canonical or Open Graph address is not its own;
- the docs build warns, or any check of the website fails;
- either output directory holds anything but an identical previous build. A build never overwrites: remove the old one and build again.
rm -rf <local-cache> && npm run publish:build
Who publishes
Only the coordinator deploys, and only with the owner's approval: with Cloudflare's cf CLI under the factory auth profile, from the two output directories. No agent deploys or calls Cloudflare, and nothing in this repository does.
Canonical addresses and the sitemap name each page by its file (/execution.html), which any static host serves. If the host instead serves pages at addresses without .html and redirects these, set it to serve files as named, or each canonical address answers with one redirect.
