Audit report
Acceptance boundary
Section titled “Acceptance boundary”The website is maintained in the standalone private devSatym/resilience-gate-docs repository, with public implementation and reviewed evidence read from the ignored upstream checkout pinned to 2420ff4c2a88b1fa4a19e413cb0752e271480081. Website work performs no live cloud, Kubernetes, payment, promotion, or Terraform apply operation. Platform application, infrastructure, tests, and release workflows are not tracked here.
The initial monorepo implementation was locally verified without remote publication. Its audits remain under migration-evidence/monorepo-audit/. Repository separation and private transfer remain recorded under docs/website/audit/migration/. The current Cloudflare target is https://resilience-gate.devsatym.xyz with base /; a configured target or successful private transfer does not establish deployment or private website hosting. The superseded Workers campaign remains under docs/website/audit/cloudflare/. New Git-integrated Pages checks and publication observations are recorded separately under docs/website/audit/cloudflare-pages/, with their own deployed Git identity.
Acceptance uses explicit states. Automated checks and representative accessibility evaluation do not establish full WCAG certification or production-readiness of the platform. Website captures demonstrate website behavior, with independent build identities; they are excluded from the platform gallery and static publication.
Prior monorepo measured checks
Section titled “Prior monorepo measured checks”Every measured PASS in the following table describes the earlier monorepo build and its recorded input identity, using the original /resilience-gate/ project base. These historical results do not verify the subsequent source resolver or current Cloudflare root-base hosting. Later outcomes and counts must come from their corresponding receipts.
| Check | State | Actual evidence |
|---|---|---|
| Source/content allowlist | PASS | 56 canonical entries, six sections, ten diagrams, 34 reviewed captures validated |
| Adapter/helper tests | PASS | 47 cases: schema, routes, metadata, links/anchors, MDX/HTML, traversal/symlinks, unknown evidence, originals, SVG resources, static-public boundary |
| Type and syntax | PASS | Astro check: zero errors/warnings/hints; JavaScript syntax validation passes |
| Production static output | PASS | 57 HTML files including 404; over 5,000 internal links/assets/anchors checked; staged original/derivative hashes verified |
| Project-base browser suite | PASS | 155 passed: Chromium 145, Firefox 10; 56 pages at 1440/390 px plus 360/768/1280/1536 and 200% zoom |
| Root-base compatibility | PASS | Fresh output build at /: 57 HTML files, 5,094 links/assets/anchors; 155 browser checks passed in Chromium/Firefox |
| Accessibility sample | PASS | Browser suite 16 scans in both themes and screenshot audit 11 states: zero axe violations |
| Keyboard and progressive enhancement | PASS | Search selection/empty/Escape, mobile menu, themes, TOC/anchors, code copy, gallery dialog/focus/filter/reset, no-JavaScript homepage/gallery |
| Screenshot visual review | PASS | Eleven actual captures inspected; original SHA-256 and capture/build/viewport/theme metadata preserved |
| Mobile Lighthouse | PASS | Three runs each: homepage 95/96/97 median 96; release 100/100/100 median 100; corrected accessibility/best-practices/SEO100 |
| Canonical development watcher | PASS | Actual addition and removal of a temporary marker rendered; canonical source restored |
| Existing documentation validator | PASS | All 34 original captures and 14 legacy SVGs checked; final link count recorded in final receipt |
| Existing platform validation | PASS | Helm/Terraform/shell/Kustomize/Compose checks; 231 tests passed, 1 deselected; Permit2 suite 13 passed |
| Signer and marked recovery | PASS | Separate signer/Permit2 invocation 23 passed; marked fake-dependency recovery 1 passed |
| Independent source review | PASS | Complete coverage inventory and flagship mechanisms reviewed; introduced high/medium findings corrected |
| Remote publication | NOT RUN | No authorized repository publication/setup action taken; no public URL claimed |
| External HTTP link crawl | NOT RUN | Repository-local targets validated and commit URLs derived; remote link availability not exhaustively fetched |
Historical machine-readable receipts now live under migration-evidence/monorepo-audit/sanitized-results/; final-checks.json records the prior final tested input identity and artifact-manifest.json records its artifact hashes separately from these reports. That Pagefind evaluation used production output at its recorded base and browser origin. Search terms included Redis fallback, missing metrics, promotion, x402, cleanup, and the actual HTTP error phrase database unavailable. Axe manual-review entries remain in the raw receipt; manual-accessibility.json records the sampled search/CTA contrast and decorative-symbol dispositions.
Standalone migration evidence
Section titled “Standalone migration evidence”docs/website/audit/migration/local-checks.json is the authoritative record for actual standalone source bootstrap, content, unit, type, syntax, production build, and browser checks that were run. It identifies the documentation build separately from the pinned upstream repository/revision and records actual outcomes and counts. The preceding historical 47-unit and 155-browser totals are not asserted as new standalone totals.
The generated publication inventory retains virtual input paths and website or upstream origin, documentation HEAD/dirty state, upstream {repository, revision}, and publicInputDigest. Repository creation, verified privacy, transferred commit, and push outcome are separately recorded in repository-transfer.json. These machine receipts avoid a circular report checksum and distinguish transfer from hosting.
These repository-separation receipts retain their original project/root-base checks and transfer observations. They are not rewritten as Cloudflare results. GitHub CI now validates PRs, main pushes, and manual checks only; it has no Pages or Cloudflare publishing job/secrets. Pages now uses native Git builds after staged initialization, with strict public HTTPS verification recorded separately. Native builds do not automatically wait for GitHub validation.
Pages evidence and historical Workers findings
Section titled “Pages evidence and historical Workers findings”The current hosting procedure follows the pinned handbook deployment guide and update guide. This checkpoint records the migration to native Git-integrated Pages configuration, not a measured hosted pass. Actual later local outcomes belong to docs/website/audit/cloudflare-pages/local-checks.json; setup, deployed Git identity, origin, DNS/certificate, and browser observations retain separate receipts in that campaign. An absent result remains unmeasured, and no handbook or earlier pass fills it.
The unchanged Workers campaign under docs/website/audit/cloudflare/ records the initial expired session, later valid Pages OAuth, old zone visibility/subscription checks, and blocked Workers attempt. Its follow-up rechecks/2026-10-04-authentication-readiness.json confirmed user:read, account:read, pages:write, and offline_access. The historical missing Workers/zone scopes and Billing Read HTTP 403 explain the old attempt; they are not current prerequisites for a Pages subdomain with external DNS.
The last retained read-only DNS sample found Spaceship nameservers and target A/AAAA/CNAME NXDOMAIN. It is not a new Pages measurement. The current procedure registers the custom domain with Pages, then hands off one new CNAME resilience-gate → resilience-gate-docs.pages.dev to the owner at Spaceship. It requires no active Cloudflare zone or nameserver migration and preserves all existing records. Current Pages account/project/Git-source access, the separate GitHub App grant, native deployment, and strict hosted verification must be inspected and recorded independently.
The publication runbook starts with paused Git-source creation, confirms the actual assigned Pages hostname, verifies the first Pages-origin build, and promotes metadata only after normal custom-host TLS works. Configuration enables branch previews while automatic main production remains paused; continuous production is enabled after initial verification. Private source and noindex do not make the static publication private. Original JSON receipts and audit hashes remain unchanged.
Initial findings and reruns
Section titled “Initial findings and reruns”| ID | Severity | Requirement/page | Finding | Correction and rerun |
|---|---|---|---|---|
| W01 | HIGH | RG-W03 / adapter | Raw HTML active content and MDX expressions bypassed Markdown URL checks | Parsed attribute validation, safe tags/imports, expression rejection; regressions and independent pass |
| W02 | HIGH | RG-W09 / diagrams | Serial edges implied nonexistent calls; replay check shown before settlement | Component graph, actual payment ordering and Redis hit branch; source/render review passed |
| W03 | MEDIUM | RG-W03 / source links | Safe directory and tracked sanitized-log references rejected | Tree links and tracked public-log permalinks; logs remain uncopied; helper/content pass |
| W04 | MEDIUM | RG-W06 / favicon | Base prefix applied twice caused 404 | Native unprefixed favicon setting; asset/browser checks and corrected Lighthouse best-practices 100 |
| W05 | MEDIUM | RG-W05 / gallery | Missing observed window displayed null | Explicit Not recorded helper; both themes/mobile and gallery assertions pass |
| W06 | MEDIUM | RG-W08 / diagrams | Mobile enlargement was distant from the image | Clickable SVG and adjacent controls; adapter regression and mobile review pass |
| W07 | HIGH | RG-W10 / dev | Deleting all generated pages could lose collection entries on watch updates | Incremental changed-file writes and safe stale-file pruning; actual edit/restore verification passes |
| W08 | MEDIUM | RG-W06 /404 | Custom homepage Hero rendered on missing routes | Native fallback Hero; Chromium/Firefox404 tests pass |
| W09 | MEDIUM | RG-W03 / provenance | SVG CSS case/SMIL and reread input races weakened integrity | Parsed resource checks; cache validated buffers; regression/re-review pass |
| W10 | MEDIUM | RG-W04 / homepage | Historical failure initially called a latency failure | Actual 75-second paid-preflight failure restored from report; source pass |
| W11 | LOW | RG-W04 / design | Invalid authorization called a challenge | Missing-header challenge separated from generic rejected 402; source pass |
| W12 | LOW | RG-W03 / headings | H1 removal could shift duplicate heading anchors | Preserve title aliases and reject title/section collisions; regression pass |
| W13 | LOW | RG-W03 / software design | Owned-output description omitted generated gallery data | Added site/src/data/ to the as-built ownership description; independent acceptance pass |
| W14 | LOW | RG-W08 / homepage | Axe manual review identified a label on a generic div | Explicit group role added; final rendered axe/browser rerun recorded in the final receipt |
The initial acceptance round left no unresolved critical/high introduced website defect. Its failing measurements are retained alongside corrections. This issue table does not claim review of unmeasured migration behavior; the standalone receipt records the new checks and any failures.
Historical non-product failures investigated
Section titled “Historical non-product failures investigated”Installing both Python lockfiles simultaneously found a pre-existing python-dotenv pin conflict. Sequential installation follows existing CI and allowed validation without editing locks. A repeated broad pytest run during concurrent audits hit one 1-second paid-marker timing assertion (230 passed, 1 failed, 1 deselected); the complete validation round passed 231, and the isolated failing test subsequently passed. The underlying platform was unchanged.
Occupied local ports belonged to other projects. Test/audit port overrides preserved those servers. Native Starlight popover selectors and Pagefind pagination required test-harness corrections. Query_transport_error was not present in mapped prose, so the sixth search was changed to the actual documented database-unavailable phrase; no tokenizer bug was claimed.
Limits and maintenance
Section titled “Limits and maintenance”The initial Astro 7 build emitted non-fatal bundler warnings about its generated MDX head-injection directive and Starlight fallback/i18n collection notices. Actual assets, MDX gallery JavaScript, and search were verified in that round; warnings remain in the historical diagnostics. Standalone diagnostics belong to the migration receipt. Private authoring-source permalinks require access to the documentation repository, while implementation citations use the public pinned upstream source. Remote permalink availability was not exhaustively crawled; preparation validates logical canonical targets.
Both project and website limits remain visible: privately retained fresh raw evidence is unavailable to public readers; source tests and historical campaigns are separate; signer outage traffic continuity and cleanup read errors remain platform caveats. Read the implementation report, coverage, and requirements.
Maintained by Satyam Agnihotri · DevOps & Cloud Engineer