Files
runicgateway.com/CODE_OF_CONDUCT.md
wtclaude f2e59a2426
All checks were successful
PR checks / checks (pull_request) Successful in 9m46s
feat(delivery): phase 12 — the container, and the defect only a proxy could find
PLAN.md §13 phase 12, the last one. Four decisions of record, D54–D57, taking the
count to fifty-seven; recorded in §6, "How phase 12 delivered it".

A two-stage Dockerfile, a pull-only docker-compose.yml carrying both bind mounts,
.env.example, the workflow that publishes and deploys, CONTRIBUTING.md, the
community-health files this was the only repository of the ten to lack, and
DEPLOY.md.

D54 — a merge deploys, amending D6. build-image.yml pushes
runicgateway-site:latest and :sha-<7>, then rolls the container over on the
`rgcom` runner out of /opt/runicgateway.com, and waits for the container's own
healthcheck rather than for `up -d` to return.

D55 — the site runs on its own host behind a generic reverse proxy, so DEPLOY.md
states the four requirements rather than one worked example, and the container
binds 127.0.0.1 so the safe configuration is the default.

D56 — @astrojs/node derives the request protocol from req.socket.encrypted and
never reads x-forwarded-proto, so behind a TLS-terminating proxy the browser sends
Origin: https://… while the container computes http://… and Astro's CSRF check
compares them for equality. Every beta signup, from every visitor, was answered
403. serve.mjs now normalises both forwarded headers, unconditionally — the image
should deploy and work. Two assertions in test/headers.test.mjs hold both halves.

D57 — DEPLOY.md rather than a README section; SECURITY.md and CODE_OF_CONDUCT.md
are pointers to the org's copies rather than copies, because a copy would hard-code
the contact address D13 confines to brand.json.

Verified: npm run verify green (eleven checks, 36 unit tests, 7 served tests,
astro check 0 errors). The image was built and run with both mounts — a mounted
brand reached 51 files and all 50 search pages, /brand/* fell back per file, a
proxy-shaped signup reached the store, and the export CLI wrote both Play files to
the host mount. docker compose config caught a YAML trap in the healthcheck: a
block sequence reads the `: ` in `r.ok ? 0 : 1` as a mapping.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-25 16:54:38 -05:00

993 B

Code of Conduct

This repository is covered by the Runic Gateway organisation's Code of Conduct — the Contributor Covenant, v2.1 — which applies identically across all ten repositories:

RunicGateway/docs → CODE_OF_CONDUCT.md

It covers the standards expected of everyone taking part, the scope (project spaces and public spaces where somebody represents the project), the enforcement guidelines, and how to report unacceptable behaviour privately.

Reporting goes to the organisation maintainer. That document carries the address; this file deliberately does not, for the same reason SECURITY.md does not — D13 (PLAN.md §5) keeps the published contact address in one bind-mounted file so that changing it costs a file copy rather than a commit in ten repositories.

Reports are handled privately, and the reporter's identity is not shared with the person reported.