fix(docs): preserve theme assets in deny-by-default publication
Publish documentation / publish (push) Successful in 36s

This commit is contained in:
Codex
2026-09-16 09:36:30 +02:00
parent 5f3680a0fb
commit b1c510a097
4 changed files with 169 additions and 3 deletions
+9 -1
View File
@@ -32,7 +32,11 @@ bash scripts/test-verify-dwh-auth-docs.sh
The strict build also verifies the public boundary: exactly 20 navigation pages,
five approved source assets, no internal pages/assets, and matching search entries.
Theme-generated assets are separate from those five source assets.
The locked Windmill theme requires a separate exact allowlist of 25 static assets;
MkDocs applies `exclude_docs` to those files too. Never replace the list with broad
directory exceptions. Sources under `docs/` may not shadow theme asset paths.
The verifier follows stylesheet/script/image references and CSS font references
from generated pages and fails when a local dependency is absent.
Choose a unique release identifier consisting of UTC timestamp and source SHA.
Record the current symlink and container identity before proceeding:
@@ -78,6 +82,10 @@ briefly interrupt this manual only.
`install/standalone-manual-it/` and `install/standalone-manual-en/`.
- Compare live home and `search/search_index.json` checksums to the build. Search
must contain only the 20 approved pages, never plans, reports or architecture.
- Check the actual stylesheet and JavaScript URLs in both installation pages:
HTTP 200, CSS served as `text/css`, JavaScript with a valid script content type,
and fonts available. In a browser confirm the stylesheets load and the layout is
styled. HTML 200 alone is not enough to accept a publication.
- Require HTTP 404 for retired/internal paths, including `architecture/overview/`,
`plans/2026-09-08-memory-management/`, and `operations/compose-reference/`.
- Record source SHA, release ID, previous release and checks in the cleanup/release