One-way website mirror
Owner direction, 2026-09-27: MIZOKI-3-5/MIZOKICloudRun is authoritative.
Website changes, tests and production deployments run there. The public
MIZOKI-3-5/mizoki-3-5-website repository is downstream only, never a deploy
source and never synced back into CloudRun.
Publication boundary
config/website-mirror.json is an explicit list of source-to-destination paths.
It covers the website application, pages, assets, tests and /learn source pages.
Private site_docs_internal, internal material and the large documentation
corpus are excluded. Deployment scripts, workflows and repository governance
files are not copied. New source files require a reviewed manifest addition;
a wildcard must never publish private content into the public mirror.
The mirror is a source snapshot, not an assertion that this revision is live.
MIRROR_SOURCE.json records the source SHA and every exported file's hash.
Existing destination-only historical material remains in place, unowned by the
exporter; it is not authoritative. Previous managed files removed from the
manifest are deleted only if their bytes still match the previous stamp.
No force pushes, history rewriting, merging back, Cloud Run deploys or IAM calls.
Activation order
- Merge the website repository's mirror-only review PR. Its workflow and local
deploy entry points refuse deployment, and
MIRROR_POLICY.mdenables sync. The old workflow was disabled via GitHub's workflow setting on 2026-09-27. - Supply
WEBSITE_MIRROR_TOKENin MIZOKICloudRun, restricted to Contents read/write on mizoki-3-5-website only (Metadata read is implicit). Do not repurpose the CLI credential,AUTO_MERGE_PR_TOKEN, or a GCP key. The source repo's built-inGITHUB_TOKENcannot write another repository. No credential was created, copied or stored by this change. A missing token fails visibly. - Merge the source review PR, then dispatch
website-mirror.ymlfrommain. Verify the destination stamp, hashes and source SHA. The workflow runs after source pushes and twice hourly, catching bot merges with suppressed events. - Keep production deployment exclusively under the existing approved homepage workflow. Mirroring does not authorize a deployment or activate V4-17.
All executable automation lives in CloudRun. Destination receives data only. The source workflow always checks out current main, validates it has not moved before pushing, and uses a normal fast-forward push. A race fails safely and the next scheduled run reconciles it. The destination policy must already be present on main; the workflow cannot silently create its own authorization marker.
Local verification
Run the entire tests/website_mirror suite with stdlib unittest. Run the full
tests/governance suite for protected workflow changes, following CI dependencies.
The exporter defaults to plan-only:
python3 scripts/website_mirror/export.py --source . --sha FULL_SOURCE_SHA --destination /path/to/isolated/mirror
--apply writes files locally but neither commits nor pushes. Restore mistakes
with a reviewed revert; retain git history and the previous source stamp.
Never run deploy scripts to verify the mirror.
Remaining security work
On 2026-09-27 the legacy workflow was disabled and both repository-branch
WIF grants on miz-oki-website-deployer were removed: workloadIdentityUser and
serviceAccountTokenCreator for repository 1142157467, refs/heads/main. Fresh
readback shows no SA-level bindings remain. The shared provider and
homepage-prod-deployer policy are unchanged; production remains on revision
mizoki-website-00253-fah at 100%, Ready=True, homepage HTTP 200. Backups and
exact restoration commands are in the operator-local directory
~/mizoki-drive-sync-snapshots/website-mirror-retirement-20260927/. This did not
revoke keys or project-level impersonation grants. No token-exchange refusal
probe was run. The live GCP rollback key and owner-held environment variables
were untouched; this mirror needs no GCP identity.
Tests are authoritative in CloudRun
The exported site tests reference parent-level governance modules in the private monorepo. They are mirrored for traceability, not promised to be independently runnable in this public repository. Run the full website suite in CloudRun; do not publish private governance files merely to satisfy standalone imports.