Repository navigation
docs: the story — contract fragments, environments and two clouds, a generated contract reference, and navigation a reader can follow - #142
Merged
Conversation
…generated contract reference, and navigation a reader can follow New explanation pages for contract fragments, environments and overlays, workspaces, OpenTofu state, governance parity, the semantic layer, the Command Center and federation; how-tos for one contract on two clouds and evolving a live product; a contract field reference generated from the schemas bundled in the pinned CLI, with a --check step in cli-consistency; the navbar and sidebar reorganised by Diataxis with every page reachable; a rewritten home page and a Getting Started tutorial run end to end on 0.18.1; and cross-links from the existing pages into the story.
fas89
force-pushed
the
docs/story-0.18.1
branch
from
October 5, 2026 09:25
9034210 to
038043e
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
#141 makes every existing page correct for 0.18.1. This PR adds what the site never had: a story a reader can follow, from installing the CLI to running a governed product on two clouds. It also adds the explanation pages behind that story.
New pages
concepts/fragments.md— contract fragments.fluid splitwrites.--envoverlays apply after$refresolution.concepts/contract-refs.md(docs: 0.18.0 contract confinement — $ref root, DuckDB sandbox, contract-loading API #139) for how a single$refresolves rather than repeating it.cli/split.mdandcli/bundle.mdbecome complete references that link to it.concepts/environments-and-overlays.md,concepts/workspaces.md(fluid.workspace.yaml),concepts/state.md(where OpenTofu state lives and how it is keyed), andconcepts/governance-parity.md. Governance parity is stated as measured: GCP against real BigQuery, Cloud KMS and Data Catalog on 4 Oct 2026, matching forge-clidocs/governance-parity.md(#694).recipes/one-contract-two-clouds.mdis a runnable how-to. The switch-clouds pages now give the measured claim instead of "one line".reference/).scripts/gen_contract_reference.py, and deterministic: 0.7.5 stable, plus the 0.7.6 preview delta.cli-consistency.ymlruns--check, so a CLI bump that changes a schema fails CI until the pages are regenerated. The job stays read-only.concepts/semantic-layer.md,concepts/command-center.md,concepts/federation.mdandrecipes/evolve-a-live-product.md.Navigation and front door
data-product-forge[local], and all its output is real. It says why it does not use--quickstart: on 0.18.1 the quickstart's local apply writes a placeholder file.Tested
npm run docs:buildexits 0.node scripts/check-dist-links.mjs: Clean, 137,770 references across 242 built pages.scripts/check_cli_docs.pyagainstdata-product-forge==0.18.1: all OK, including the flag oracle over every documentedfluidinvocation.scripts/check_providers.pyOK;scripts/gen_contract_reference.py --checkOK./forge_docs/and walked it in a browser.Security review
A dedicated review of this delta found one HIGH, now fixed. The Workload Identity Federation setup lacked an attribute condition and a role-scoped
principalSet, which would let any AWS role in the account impersonate the deploy service account. Also fixed:<your-domain>and<your-state-bucket>.verify --strictin CI.gitleaks reports no leaks.
Prior art