# Product brief

Current hosting authority (2026-10-05): the owner subsequently authorized Cloudflare publication of the handbook and its fourteen approved original screenshots while keeping `devSatym/gcp-security-handbook` private. The website is public at verified `https://security.devsatym.xyz/`, served by native Git-integrated Cloudflare Pages Free with production on `main` and automatic branch previews. Current provider, custom-domain and hosted verification receipts are recorded separately in `audits/cloudflare-status.json`; website publication does not establish current GCP cloud health. Billing, repository visibility, nameservers, unrelated DNS and the original application repository remain outside this publication scope.

Historical private-delivery authorization checkpoint (2026-10-05): the owner approved committing and pushing the verified site to the existing private handbook repository. At that checkpoint the approval covered the private documentation commit/push only; Pages settings/dispatch/publication, DNS and billing remained separately unauthorized. See `audits/private-push-authorization.json` and actual Git history for that earlier boundary. The later Cloudflare instruction supersedes its hosting restriction.

The handbook explains how an untrusted source change becomes a permitted workload, and why observation remains necessary after admission. A reviewer needs bounded, inspectable claims; a security engineer needs the authority model and residual risks; an operator needs safe local inspection and deliberate historical reproduction.

The delivered product is an English static Astro/Starlight handbook in `website/` of the separate private documentation repository `devSatym/gcp-security-handbook`. It has six navigation groups, complete concept/workflow/evidence/runbook/reference pages, immutable source links, searchable catalogues, responsive themes and accessible diagrams. Success means a reader can trace one digest, distinguish cloud authority from signing identity, compare CI with admission, and identify what historical evidence actually demonstrated.

The edition is pinned to `cbbc807c0c150e106affa89fbb1b9e8349005749` in the original `devSatym/gcp-supply-chain-security` implementation repository. That source project's reviewed main `28c00d0` is Azure, and its root README is preserved. The handbook has its own newly initialized Git history and main branch; it does not import application history or change the source project remotely. Capture dates are not content review dates or build revisions. We assume basic Git/container knowledge, not supply-chain terminology.

Non-goals are new cloud controls, application features, active cluster verification, real-time pipeline state, paid search, analytics or an authentication backend. The authorized static documentation deployment uses Cloudflare's native Git build path. Local checks, provider deployment and hosted verification remain separate observations. Browser tests establish website behavior only.

The initial implementation and domain/identity addendum prepared local artifacts before the later hosting authorization. Current production uses `DOCS_SITE=https://security.devsatym.xyz` at `/`; native non-main previews use Cloudflare's validated `CF_PAGES_URL`. The `https://devsatym.github.io/gcp-security-handbook/` and `/gcp-supply-chain-security/` profiles remain independently tested compatibility paths. The retained manual GitHub Pages workflow is unused and belongs to the historical hosting option. The source repository remains private; its privacy does not restrict access to the public website.

Cloudflare runs `npm run build:cloudflare` from `website` and publishes `dist`. That command checks source hygiene, types, unit/content contracts, static output and Free asset limits; it does not run the complete Playwright suite. Read-only GitHub CI runs the browser matrix independently. Native Pages builds do not automatically wait for that CI result, so maintainers review previews and passing checks before merging production changes.

The addendum adds central author/project identity, About and contribution routes, original editorial/social imagery, and the owner-requested gallery of all fourteen unchanged historical screenshots. The 48 authored pages retain the six causal navigation groups; full-resolution evidence, pinned hashes, truthful context and limitations remain central. The approved originals are already published, including disclosed terminal/account metadata. No additional pixel redaction was selected or applied; any future derivative requires owner direction and truthful provenance.

Acceptance: all required topics have substantial source-grounded pages; no empty advertised routes; catalogue validators reject invalid references; production base-path links/search resolve; bounded accessibility/visual/performance audits are measured and reported; engineering documents reflect actual implementation; source-project files remain unchanged.
