The proof runs without a hand
Answers Derivation · Epistemology
Every push runs the rings a hand can run: the build, the proof that the committed artifact is the build of the committed ground, the breakage suite, the standards proof with its validator installed, and the site build. A deploy is of a commit those rings passed.
What goes wrong without it
A gate a person remembers to run is a gate that is skipped the day the person is hurried, and twice in one day a commit landed that no ring had seen because a shell chain broke silently. Determinism makes the strongest check free: the graph is a pure function of the ground, so a rebuild that differs from what was committed is a ground that moved without its artifact, and a plain comparison says so.
What proves it — 4
Each is a gate the build runs: a check inside a ring, a whole ring, or an eval beside them. A build stops at the first that refuses.
- eval:lawsthe laws bite
Every law refuses the breakage that is its own to refuse, every law has one, and every refusal the laws, the ledger law and the schema validator can make is reached by at least one: a sentence no breakage reaches is a sentence nobody has proved a gate can still say. - eval:recordthe record is the build
The committed graph, dates ledger, schemas, standards, editor mapping and the site's types are the build of the committed ground, byte for byte, and nothing a build writes is left uncommitted. - eval:hostthe host is the build
What the host serves is the build of a commit the rings passed: the tree clean, the run for that commit green, the build embedding that commit's graph; and once deployed, the origin answering as the build: the ground digest it serves the build's, a page and its files there, every former address answering with the status the law gives it, a bare name sent to its page, an address the graph does not have answering with the site's own page, the collector counting a signal the graph holds and refusing every other method, and the headers the host owes on every response. - eval:enginethe engine agrees with itself
The binder that runs while the graph is built and the binder that runs in a reader's browser find the same bindings: every pattern bound against the whole model to the same instances and the same rows in every role, the published example among them, and every view bound again from every row it answers from, row for row, and the port of the pattern law beside the browser's engine refuses every way a declared pattern can be broken exactly as the law does, and every question bound again from every row of its root kind finds an answer exactly where the build published one and nothing where it did not.
Derived from — 2
- Reproducible Builds project, reproducible-builds.orgReproducible Builds: definition
- Martin Fowler, martinfowler.com, revised 2024Continuous Integration
Where this model stands
.github/workflows/rings.yml runs on every push and pull request: the build, the record eval (the rebuilt artifact, schemas, standards, mapping and types are the commit's, byte for byte), the laws eval (every law refuses its own breakage, and every law has one), the standards proof with rdflib and pyshacl installed, and the site build with its site and design rings, which begins by holding the two runtimes of the binder to each other. The rings and the evals are catalogs in the law, and each names itself when it refuses.
The host is one Worker at the edge, and it is the site: it serves the build as its static assets, answers the endpoints the law declares, and runs first for every request, so the canonical origin, the headers, the addresses this graph once answered to and the not-found page are decided in one place from the ground rather than in a host's own config. The allowlist and the redirect list it carries are cut from the graph on every site build and committed, and the site ring holds them to it.
site/worker/scripts/deploy.mjs is the host eval, named from the law's catalog: it refuses a tree with changes, a commit whose run is not green, and a build that embeds another commit's graph; it deploys the Worker; and it then proves the origin by real requests, refusing a host whose ground digest is not the build's, a former address that does not answer as the law says, an unknown address that does not get the site's own page, a collector that does not count, or a response without the headers the host owes.
The same script runs from CI after the rings pass, when a deploy token is present as a repository secret; without one, the host is deployed from a machine and nothing else changes.
RUL-034