ADR Template
Canonical Architecture Decision Record template, filename convention, and required sections.
Canonical Architecture Decision Record template, filename convention, and required sections.
Pinned tool versions and build reproducibility requirements.
Registry of planted canary tokens for intrusion detection.
Documents the Cloudflare security configuration for chrisnewcomb.name including WAF, DDoS, bot protection, and Zero Trust readiness.
Validation specification and authoring guide defining what all content in the Engineering Journal must comply with.
Canonical lifecycle model defining the allowed states and transition rules for all content in the Engineering Journal.
Canonical taxonomy defining all allowed domains and tags for content in the Engineering Journal.
Canonical frontmatter schema for all content in the Engineering Journal — deterministic and CI-enforced.
Repository governance standards, policies, and content lifecycle rules.
Template for governance policies and standards documents.
Step-by-step playbooks for security incidents specific to this repository's architecture.
Defines how lifecycle states are rendered visually in the Docusaurus site — banners, colors, and implementation details.
Documents and validates every external domain that CI workflows access.
Approved plugin allowlist, principles for adding new plugins, and extension guidelines for the Docusaurus site.
Repository conventions, contribution expectations, and quality controls.
How the repository is structured, how work flows through it, and how automation enforces quality and consistency.
Tracks all secrets used in the repository with last rotation date and rotation policy.
Requirements and setup guide for GPG or SSH signed commits on all branches.
Formal threat model documenting attack surfaces, threat actors, blast radius, and mitigations for the engineering journal repository and site.
Formal process for reporting, triaging, and resolving security vulnerabilities in this repository.
Security headers, CSP, DNS hardening, and TLS configuration for chrisnewcomb.name via Cloudflare.