One-way website mirror

Owner direction, 2026-09-27: MIZOKI-3-5/MIZOKICloudRun is authoritative. Website changes, tests and production deployments run there. The public MIZOKI-3-5/mizoki-3-5-website repository is downstream only, never a deploy source and never synced back into CloudRun.

Publication boundary

config/website-mirror.json is an explicit list of source-to-destination paths. It covers the website application, pages, assets, tests and /learn source pages. Private site_docs_internal, internal material and the large documentation corpus are excluded. Deployment scripts, workflows and repository governance files are not copied. New source files require a reviewed manifest addition; a wildcard must never publish private content into the public mirror.

The mirror is a source snapshot, not an assertion that this revision is live. MIRROR_SOURCE.json records the source SHA and every exported file's hash. Existing destination-only historical material remains in place, unowned by the exporter; it is not authoritative. Previous managed files removed from the manifest are deleted only if their bytes still match the previous stamp. No force pushes, history rewriting, merging back, Cloud Run deploys or IAM calls.

Activation order

  1. Merge the website repository's mirror-only review PR. Its workflow and local deploy entry points refuse deployment, and MIRROR_POLICY.md enables sync. The old workflow was disabled via GitHub's workflow setting on 2026-09-27.
  2. Supply WEBSITE_MIRROR_TOKEN in MIZOKICloudRun, restricted to Contents read/write on mizoki-3-5-website only (Metadata read is implicit). Do not repurpose the CLI credential, AUTO_MERGE_PR_TOKEN, or a GCP key. The source repo's built-in GITHUB_TOKEN cannot write another repository. No credential was created, copied or stored by this change. A missing token fails visibly.
  3. Merge the source review PR, then dispatch website-mirror.yml from main. Verify the destination stamp, hashes and source SHA. The workflow runs after source pushes and twice hourly, catching bot merges with suppressed events.
  4. Keep production deployment exclusively under the existing approved homepage workflow. Mirroring does not authorize a deployment or activate V4-17.

All executable automation lives in CloudRun. Destination receives data only. The source workflow always checks out current main, validates it has not moved before pushing, and uses a normal fast-forward push. A race fails safely and the next scheduled run reconciles it. The destination policy must already be present on main; the workflow cannot silently create its own authorization marker.

Local verification

Run the entire tests/website_mirror suite with stdlib unittest. Run the full tests/governance suite for protected workflow changes, following CI dependencies. The exporter defaults to plan-only:

python3 scripts/website_mirror/export.py --source . --sha FULL_SOURCE_SHA --destination /path/to/isolated/mirror

--apply writes files locally but neither commits nor pushes. Restore mistakes with a reviewed revert; retain git history and the previous source stamp. Never run deploy scripts to verify the mirror.

Remaining security work

On 2026-09-27 the legacy workflow was disabled and both repository-branch WIF grants on miz-oki-website-deployer were removed: workloadIdentityUser and serviceAccountTokenCreator for repository 1142157467, refs/heads/main. Fresh readback shows no SA-level bindings remain. The shared provider and homepage-prod-deployer policy are unchanged; production remains on revision mizoki-website-00253-fah at 100%, Ready=True, homepage HTTP 200. Backups and exact restoration commands are in the operator-local directory ~/mizoki-drive-sync-snapshots/website-mirror-retirement-20260927/. This did not revoke keys or project-level impersonation grants. No token-exchange refusal probe was run. The live GCP rollback key and owner-held environment variables were untouched; this mirror needs no GCP identity.

Tests are authoritative in CloudRun

The exported site tests reference parent-level governance modules in the private monorepo. They are mirrored for traceability, not promised to be independently runnable in this public repository. Run the full website suite in CloudRun; do not publish private governance files merely to satisfy standalone imports.

← All docsView source on GitHub →