Skip to content

Audit report

The website is maintained in the standalone private devSatym/resilience-gate-docs repository, with public implementation and reviewed evidence read from the ignored upstream checkout pinned to 2420ff4c2a88b1fa4a19e413cb0752e271480081. Website work performs no live cloud, Kubernetes, payment, promotion, or Terraform apply operation. Platform application, infrastructure, tests, and release workflows are not tracked here.

The initial monorepo implementation was locally verified without remote publication. Its audits remain under migration-evidence/monorepo-audit/. Repository separation and private transfer remain recorded under docs/website/audit/migration/. The current Cloudflare target is https://resilience-gate.devsatym.xyz with base /; a configured target or successful private transfer does not establish deployment or private website hosting. The superseded Workers campaign remains under docs/website/audit/cloudflare/. New Git-integrated Pages checks and publication observations are recorded separately under docs/website/audit/cloudflare-pages/, with their own deployed Git identity.

Acceptance uses explicit states. Automated checks and representative accessibility evaluation do not establish full WCAG certification or production-readiness of the platform. Website captures demonstrate website behavior, with independent build identities; they are excluded from the platform gallery and static publication.

Every measured PASS in the following table describes the earlier monorepo build and its recorded input identity, using the original /resilience-gate/ project base. These historical results do not verify the subsequent source resolver or current Cloudflare root-base hosting. Later outcomes and counts must come from their corresponding receipts.

Check State Actual evidence
Source/content allowlist PASS 56 canonical entries, six sections, ten diagrams, 34 reviewed captures validated
Adapter/helper tests PASS 47 cases: schema, routes, metadata, links/anchors, MDX/HTML, traversal/symlinks, unknown evidence, originals, SVG resources, static-public boundary
Type and syntax PASS Astro check: zero errors/warnings/hints; JavaScript syntax validation passes
Production static output PASS 57 HTML files including 404; over 5,000 internal links/assets/anchors checked; staged original/derivative hashes verified
Project-base browser suite PASS 155 passed: Chromium 145, Firefox 10; 56 pages at 1440/390 px plus 360/768/1280/1536 and 200% zoom
Root-base compatibility PASS Fresh output build at /: 57 HTML files, 5,094 links/assets/anchors; 155 browser checks passed in Chromium/Firefox
Accessibility sample PASS Browser suite 16 scans in both themes and screenshot audit 11 states: zero axe violations
Keyboard and progressive enhancement PASS Search selection/empty/Escape, mobile menu, themes, TOC/anchors, code copy, gallery dialog/focus/filter/reset, no-JavaScript homepage/gallery
Screenshot visual review PASS Eleven actual captures inspected; original SHA-256 and capture/build/viewport/theme metadata preserved
Mobile Lighthouse PASS Three runs each: homepage 95/96/97 median 96; release 100/100/100 median 100; corrected accessibility/best-practices/SEO100
Canonical development watcher PASS Actual addition and removal of a temporary marker rendered; canonical source restored
Existing documentation validator PASS All 34 original captures and 14 legacy SVGs checked; final link count recorded in final receipt
Existing platform validation PASS Helm/Terraform/shell/Kustomize/Compose checks; 231 tests passed, 1 deselected; Permit2 suite 13 passed
Signer and marked recovery PASS Separate signer/Permit2 invocation 23 passed; marked fake-dependency recovery 1 passed
Independent source review PASS Complete coverage inventory and flagship mechanisms reviewed; introduced high/medium findings corrected
Remote publication NOT RUN No authorized repository publication/setup action taken; no public URL claimed
External HTTP link crawl NOT RUN Repository-local targets validated and commit URLs derived; remote link availability not exhaustively fetched

Historical machine-readable receipts now live under migration-evidence/monorepo-audit/sanitized-results/; final-checks.json records the prior final tested input identity and artifact-manifest.json records its artifact hashes separately from these reports. That Pagefind evaluation used production output at its recorded base and browser origin. Search terms included Redis fallback, missing metrics, promotion, x402, cleanup, and the actual HTTP error phrase database unavailable. Axe manual-review entries remain in the raw receipt; manual-accessibility.json records the sampled search/CTA contrast and decorative-symbol dispositions.

docs/website/audit/migration/local-checks.json is the authoritative record for actual standalone source bootstrap, content, unit, type, syntax, production build, and browser checks that were run. It identifies the documentation build separately from the pinned upstream repository/revision and records actual outcomes and counts. The preceding historical 47-unit and 155-browser totals are not asserted as new standalone totals.

The generated publication inventory retains virtual input paths and website or upstream origin, documentation HEAD/dirty state, upstream {repository, revision}, and publicInputDigest. Repository creation, verified privacy, transferred commit, and push outcome are separately recorded in repository-transfer.json. These machine receipts avoid a circular report checksum and distinguish transfer from hosting.

These repository-separation receipts retain their original project/root-base checks and transfer observations. They are not rewritten as Cloudflare results. GitHub CI now validates PRs, main pushes, and manual checks only; it has no Pages or Cloudflare publishing job/secrets. Pages now uses native Git builds after staged initialization, with strict public HTTPS verification recorded separately. Native builds do not automatically wait for GitHub validation.

Pages evidence and historical Workers findings

Section titled “Pages evidence and historical Workers findings”

The current hosting procedure follows the pinned handbook deployment guide and update guide. This checkpoint records the migration to native Git-integrated Pages configuration, not a measured hosted pass. Actual later local outcomes belong to docs/website/audit/cloudflare-pages/local-checks.json; setup, deployed Git identity, origin, DNS/certificate, and browser observations retain separate receipts in that campaign. An absent result remains unmeasured, and no handbook or earlier pass fills it.

The unchanged Workers campaign under docs/website/audit/cloudflare/ records the initial expired session, later valid Pages OAuth, old zone visibility/subscription checks, and blocked Workers attempt. Its follow-up rechecks/2026-10-04-authentication-readiness.json confirmed user:read, account:read, pages:write, and offline_access. The historical missing Workers/zone scopes and Billing Read HTTP 403 explain the old attempt; they are not current prerequisites for a Pages subdomain with external DNS.

The last retained read-only DNS sample found Spaceship nameservers and target A/AAAA/CNAME NXDOMAIN. It is not a new Pages measurement. The current procedure registers the custom domain with Pages, then hands off one new CNAME resilience-gate → resilience-gate-docs.pages.dev to the owner at Spaceship. It requires no active Cloudflare zone or nameserver migration and preserves all existing records. Current Pages account/project/Git-source access, the separate GitHub App grant, native deployment, and strict hosted verification must be inspected and recorded independently.

The publication runbook starts with paused Git-source creation, confirms the actual assigned Pages hostname, verifies the first Pages-origin build, and promotes metadata only after normal custom-host TLS works. Configuration enables branch previews while automatic main production remains paused; continuous production is enabled after initial verification. Private source and noindex do not make the static publication private. Original JSON receipts and audit hashes remain unchanged.

ID Severity Requirement/page Finding Correction and rerun
W01 HIGH RG-W03 / adapter Raw HTML active content and MDX expressions bypassed Markdown URL checks Parsed attribute validation, safe tags/imports, expression rejection; regressions and independent pass
W02 HIGH RG-W09 / diagrams Serial edges implied nonexistent calls; replay check shown before settlement Component graph, actual payment ordering and Redis hit branch; source/render review passed
W03 MEDIUM RG-W03 / source links Safe directory and tracked sanitized-log references rejected Tree links and tracked public-log permalinks; logs remain uncopied; helper/content pass
W04 MEDIUM RG-W06 / favicon Base prefix applied twice caused 404 Native unprefixed favicon setting; asset/browser checks and corrected Lighthouse best-practices 100
W05 MEDIUM RG-W05 / gallery Missing observed window displayed null Explicit Not recorded helper; both themes/mobile and gallery assertions pass
W06 MEDIUM RG-W08 / diagrams Mobile enlargement was distant from the image Clickable SVG and adjacent controls; adapter regression and mobile review pass
W07 HIGH RG-W10 / dev Deleting all generated pages could lose collection entries on watch updates Incremental changed-file writes and safe stale-file pruning; actual edit/restore verification passes
W08 MEDIUM RG-W06 /404 Custom homepage Hero rendered on missing routes Native fallback Hero; Chromium/Firefox404 tests pass
W09 MEDIUM RG-W03 / provenance SVG CSS case/SMIL and reread input races weakened integrity Parsed resource checks; cache validated buffers; regression/re-review pass
W10 MEDIUM RG-W04 / homepage Historical failure initially called a latency failure Actual 75-second paid-preflight failure restored from report; source pass
W11 LOW RG-W04 / design Invalid authorization called a challenge Missing-header challenge separated from generic rejected 402; source pass
W12 LOW RG-W03 / headings H1 removal could shift duplicate heading anchors Preserve title aliases and reject title/section collisions; regression pass
W13 LOW RG-W03 / software design Owned-output description omitted generated gallery data Added site/src/data/ to the as-built ownership description; independent acceptance pass
W14 LOW RG-W08 / homepage Axe manual review identified a label on a generic div Explicit group role added; final rendered axe/browser rerun recorded in the final receipt

The initial acceptance round left no unresolved critical/high introduced website defect. Its failing measurements are retained alongside corrections. This issue table does not claim review of unmeasured migration behavior; the standalone receipt records the new checks and any failures.

Historical non-product failures investigated

Section titled “Historical non-product failures investigated”

Installing both Python lockfiles simultaneously found a pre-existing python-dotenv pin conflict. Sequential installation follows existing CI and allowed validation without editing locks. A repeated broad pytest run during concurrent audits hit one 1-second paid-marker timing assertion (230 passed, 1 failed, 1 deselected); the complete validation round passed 231, and the isolated failing test subsequently passed. The underlying platform was unchanged.

Occupied local ports belonged to other projects. Test/audit port overrides preserved those servers. Native Starlight popover selectors and Pagefind pagination required test-harness corrections. Query_transport_error was not present in mapped prose, so the sixth search was changed to the actual documented database-unavailable phrase; no tokenizer bug was claimed.

The initial Astro 7 build emitted non-fatal bundler warnings about its generated MDX head-injection directive and Starlight fallback/i18n collection notices. Actual assets, MDX gallery JavaScript, and search were verified in that round; warnings remain in the historical diagnostics. Standalone diagnostics belong to the migration receipt. Private authoring-source permalinks require access to the documentation repository, while implementation citations use the public pinned upstream source. Remote permalink availability was not exhaustively crawled; preparation validates logical canonical targets.

Both project and website limits remain visible: privately retained fresh raw evidence is unavailable to public readers; source tests and historical campaigns are separate; signer outage traffic continuity and cleanup read errors remain platform caveats. Read the implementation report, coverage, and requirements.

Maintained by Satyam Agnihotri · DevOps & Cloud Engineer