KNOWLEDGE / OPERATING DOCUMENTATION

Documentation is operating evidence.

Architecture, getting started and Day-2 knowledge stay attached to the systems they describe.

Project groups
13
Documents
109
Reading model
Architecture → Day-2
PROJECT DOCUMENT STREAM
OPENFORGE
40 docs
01

Documentation Overview

OSS Project Blueprint, reusable engineering standards, templates, and reference practices.

02

Core Concepts

Core concepts, three-tier architecture, trust models, and governance principles in OpenForge.

03

Getting Started

Step-by-step roadmap for adopting OpenForge standards and templates in new or existing OSS projects.

04

Standards

OpenForge standards grouped by engineering concern and lifecycle.

05

Templates Catalog

Catalog of reusable, production-tested implementation templates provided in OpenForge.

06

Architecture Blueprints

Recommended platform and service architecture patterns combining OpenForge standards and templates.

07

Operations Guide

Post-deployment lifecycle, observability, backup/recovery, and operational standards.

08

Reference & Source Map

Authoritative source mapping across OpenForge standards, templates, reference implementations, and evidence.

09

Troubleshooting Guide

Evidence-first symptom-cause-action debugging methodology and lessons-learned codification.

10

Architecture Decision Records (ADR)

Key architectural decisions, design rationale, and trade-offs behind OpenForge.

11

Repository Standard

OSS repository structure, required root files, and maintainability baseline.

12

Documentation Standard

Dual-language documentation model, source-of-truth invariants, and structure.

13

GitHub Standard

Issue, PR, branch protection, and collaborative maintainer workflow baseline.

14

Development Standard

Language-specific tooling baseline, deterministic formatting, and task automation.

15

Engineering Tooling Standard

Toolchain selection, configuration management, and developer workflow consistency.

16

Engineering Tooling Matrix

Recommended linters, formatters, and build tools per programming language.

17

CI/CD Standard

Continuous integration, delivery pipelines, and validation quality gates.

18

CI/CD Security Standard

CI trust boundaries, permissions, runners, caches, and release isolation.

19

CI/CD Resilience Standard

Safe fallback strategies and failure mitigation during CI platform outages.

20

Reproducible Build Standard

Deterministic build artifacts, pinned environments, and verification discipline.

21

Change Management & Impact Analysis

Full workflow impact analysis before dependency, runtime, or toolchain changes.

22

Upgrade & Compatibility Engineering

Support windows, backward-compatibility testing, and drift prevention.

23

Security Standard

OpenForge baseline for secure development and operational boundaries.

24

Supply Chain Security Standard

Dependency governance, package identity verification, and registry defense.

25

Package & Artifact Identity

Immutable package provenance, checksum, signature, and metadata verification.

26

Plugin Supply-Chain Intake Standard

Integrity verification, runtime capability constraints, and plugin intake pipelines.

27

Developer Environment Security

Local workstation boundaries, credential isolation, and secure tool execution.

28

AI-Assisted Engineering Security

Trust boundaries for AI agents, prompt injection defense, and sandbox isolation.

29

Container, Kubernetes & IaC Security

Hardened container images, non-root execution, NetworkPolicies, and policy-as-code.

30

Reference Implementation Metrics

Repository maturity scorecard and evidence model for OpenForge standards compliance.

31

Secrets & Machine Identity

Short-lived tokens, OIDC federation, secret scanning, and zero hardcoded credentials.

32

Vulnerability Management

CVE triage procedures, risk prioritization, patching workflows, and SLA.

33

Security & Incident Response

Incident triage, mitigation, communication, and lessons-learned codification.

34

Release Standard

Semantic Versioning, automated changelog, and tag-triggered distribution.

35

Release Security

Cryptographic signing, SBOM generation, provenance attestations, and distribution trust.

36

Security Exceptions & Waivers

Time-bounded exception handling, risk ownership, and expiration auditing.

37

Maintainer Governance

Risk-based governance and approval workflows for 1-person and multi-maintainer OSS.

38

Internationalization Standard

Multilingual UI resource structures, translation keys, and locale consistency.

39

OSS Compliance Standard

Apache 2.0 licensing, SPDX headers, dependency compatibility, and attribution.

40

Reference Practices Audit

Extracting, codifying, and validating repeatable patterns from real OSS projects.

CLUSTERDECK
3 docs
NARWHAL
9 docs
NFS QUOTA AGENT
7 docs
LDAPIUM
5 docs
BELUGA
5 docs
BELUGA MANAGER
4 docs
SIQOQ
3 docs
K-PAAS LITE
11 docs
KUBE-READY-BOX
7 docs
KUBEMETAL
7 docs
NARWHAL PORTAL
7 docs
SITE
1 docs
READING PATH
01 Architecture02 Getting Started03 Operations / Day-204 Project evidence