Skip to main content

Document metadata

Status
Review candidate
Approval
Pending
Version
1.0
Classification
PUBLIC
Owner
Lightning IT Documentation Maintainers
Approver
Lightning IT Product Owners
Audience
documentation architects, maintainers, reviewers
Last reviewed
Next review
(Annual)

Documentation platform current-state assessment

This assessment records the verified repository state at commit 918add1c6b94463780e2240b78300a534ccbdd20. It does not infer production, approval, certification, control effectiveness, or private-source facts.

Verified baseline

AreaVerified current stateEvidence
RepositoryPublic Docusaurus repository; develop integration and main stable branchARCHITECTURE.md, RELEASE.md, .lit/repository.yml
ApplicationStatic Docusaurus 3.10.2 site with TypeScript and explicit sidebarspackage.json, docusaurus.config.ts, sidebars.ts
Runtime toolchainNode 24.18.0, npm 11.x, locked dependencies.node-version, package.json, package-lock.json
BuildStatic build/ output, deployment marker, CSP hashes, noticespackage.json, scripts/generate-deployment-marker.mjs
SearchPagefind 1.5.2 indexes rendered public output locallypackage.json, src/components/Search.tsx
ContentProduct and cross-product pages exist; portfolio naming is inconsistent with the proposed targetdocs/, AGENTS.md, docs/architecture/product-documentation-standard.md
NavigationExplicit sidebar covers products, architecture, security, compliance, governance, reference, releases, support, contributingsidebars.ts
GovernanceClassification boundary, metadata baseline, single-maintainer exception, exact-digest approval mechanismAGENTS.md, CODEX_EXECUTION_GUIDE.md, evidence/document-approval-*.json
ValidationFormat, lint, spelling, type, metadata, links, licenses, audit, build, site, browser, accessibility, Lighthousepackage.json, .github/workflows/documentation-ci.yml
Supply chainLockfile, pinned workflow actions, CodeQL, dependency review, SBOM commandspackage-lock.json, .github/workflows/, package.json
MigrationAggregate initial migration evidence and a public-safe Platform Governance & Evidence planevidence/migration-*, evidence/platform-governance-evidence-migration-inventory.json
DeploymentArchitecture and workflows describe Cloudflare Pages; repository evidence alone does not prove every route or current revision in productionARCHITECTURE.md, .github/workflows/, issue #40
ReleaseRepository classification says no packaged release artifact; static-site promotion still uses protected branchesRELEASE.md, .lit/repository.yml
EvidenceGenerated validation records exist locally or in workflows; complete public Evidence Center is not establishedevidence/, issue #30

Goal #15 traceability

Goal scopeCurrent dispositionGap classPlanned owner
Current-state and gap assessmentthis documentcomplete when accepted#23
Governance, release, licensing reconciliationsource files contain tensionspartial#24
Target platform and repository architectureARCHITECTURE.md is useful but incomplete as a governed target packagepartial#25
Information architecture, site map, navigationsidebar exists; complete governed model absentpartial#26
Metadata, lifecycle, versioningbaseline and validators exist; full state model absentpartial#27
Templates and reusable componentsaccepted target standard and product templateimplemented planning artifact#28
Trust Centersecurity and governance pages exist; canonical center model absentmissing#29
Evidence Center and retentionevidence files exist; governed center and retention model absentpartial#30
Compliance mappingone BSI page exists; extensible framework model absentpartial#31
Public/private security architectureaccepted planning artifactimplemented planning artifact#32
Localization and searchEnglish static search exists; bilingual governance and version-aware strategy absentpartial#33
GitHub lifecycle traceabilityworkflows and issue links exist; end-to-end model absentpartial#34
CI/CD and Cloudflare architectureimplementation exists in parts; complete accepted handoff absentpartial/unverified#35
Migration inventory and planinitial aggregate evidence plus product planpartial#36
Dependency graph and implementation breakdownabsentmissing#37
Integrated architecture approvalabsent; implementation remains blockedblocked#38
Production acceptancebase site evidence exists; product-specific acceptance absentunverified#40

Prioritized gaps

PriorityGapImpactDependencyRecommended disposition
P0Governance and target taxonomy contradict current repository statementsambiguous authority and unsafe automated remediation#23decide in #24 and integrate in #38
P0Integrated architecture lacks explicit maintainer approvalimplementation prohibited#24–#37complete #38
P0Platform Governance & Evidence route and exact-digest approval absent#115 cannot publish#28, #32, #36–#38, #2implement only after gate
P1Target architecture and directory ownership are incompletefuture work can duplicate or cross trust boundaries#24complete #25
P1Metadata, evidence, Trust and Compliance models are incompleteclaims and lifecycle may be inconsistent#25–#30complete #27, #29–#31
P1CI/CD and production handoff lacks one accepted architecturedeployment decisions may be inferred#25, #30, #34complete #35
P2Localization and version-aware search are not governedstale or ambiguous results#26, #27complete #33
P2GitHub-derived traceability lacks one deterministic contractincomplete or stale generated claims#25, #27, #30, #31complete #34

Inconsistencies and stale or unproven statements

  • AGENTS.md and docs/architecture/index.md describe four peer products, while the accepted #28 target proposes five sellable products and ModuLix as a foundation. The current model remains effective until #38 decides.
  • Goal #15 uses both AIO and older product terminology. Naming changes require a governed target decision and later implementation, not silent rewriting.
  • RELEASE.md says release evidence is disabled for packaged artifacts, while the static site still requires deployment and approval evidence. #24 must distinguish package release evidence from documentation publication evidence.
  • Repository configuration and workflows demonstrate designed deployment behavior, not the current production revision or route-level acceptance.
  • Existing approval evidence covers its recorded document set and digest only; it does not approve future architecture or product documents.
  • Generated files under evidence/generated/ are build outputs and do not by themselves prove external production behavior.

Explicit unknowns

Public repository evidence does not establish restricted Cloudflare identifiers, private source mappings, customer data, detailed risks, credential state, or private approval records. Those facts remain outside this assessment. Production claims require external verification and a safe evidence record through #40.