Current state
Ownership boundary
Wiki publication is serialized by the publisher’s own global lock plus the Flowmaster heavy lock. The shared Quartz engine is owned through build.sh; a foreign --serve preview process holds only a process-local mutex and is not a publisher. Tiny never stops, signals, or reconfigures that preview, and never bypasses the publisher. If the publisher ever refuses (lock held or preflight failure), that refusal is the blocker.
What is shipped versus pending
- The tool registry
tools.jsondrives both the generated wiki index and the application dock. - This wiki is published by the locked publisher (
build.sh tiny, heavy lock) with rendered titles verified and no leaked frontmatter. - The application is built: static shell with a daisyUI 5 bottom dock (pinned Tailwind 4.3.3 / daisyUI 5.7.46, committed lockfile), Terracraft mounted at
/t/terracraft/with vendored Preact 10.19.2 / HTM 3.1.1. The c2 headless-Chrome run passed 6/6 cases at 390 and 1280 widths: dock navigation, 16 textures, place, right-click rotation, R rotation, 512 × 512 PNG export, reload persistence, no iframe, zero console errors, zero third-party requests. This is local loopback proof, never public proof. - Nginx vhosts and certificates are Gatekeeper-only. Prepared configs and a handoff README wait in
/home/loca/dev/tiny/deploy/; both public hosts still fail TLS hostname validation and are recorded asingress: prepared, awaiting Gatekeeper. - README claims are not runtime evidence. The old address
http://0rk.de:55333/is stale; the source export button exists, X is not implemented in the inspected handler.
Public deployment contract
- Application host
tiny.loca.zone: nginx static root/home/loca/dev/tiny/dist, no Node service. - Wiki host
wiki.tiny.loca.zone: one public content tree, publisher-managedcurrentartifact root. - Wiki config disables external font loading, analytics, comments, and private/unlisted plugins.
- Exact-host TLS certificates (one per host) via certbot webroot
/var/www/html, applied by Gatekeeper.
flowchart LR Registry[tools.json] --> Generator[wiki generator] Registry --> Dock[Shell dock build] Generator --> Index[Public wiki index] Index --> Publish[Locked publisher] Publish --> Wiki[Public wiki] Dock --> App[Static dist] App --> Proof[Local browser proof] Proof --> Ingress[Gatekeeper vhosts and certs]
Evidence boundary
Mission evidence lives in /home/loca/dev/tiny/evidence/ (original round and -c2 continuation). Browser interaction proof (place, rotate, PNG export, dock navigation, no CDN requests) is recorded per round; public HTTPS acceptance is recorded separately from local proof and must never be inferred from it.
Current URL / state
| Surface | URL | Current state |
|---|---|---|
| Tiny application | https://tiny.loca.zone/ | built and locally proven; ingress: prepared, awaiting Gatekeeper |
| Terracraft mounted tool | https://tiny.loca.zone/t/terracraft/ | built and locally proven; ingress: prepared, awaiting Gatekeeper |
| Public wiki | https://wiki.tiny.loca.zone/ | published via locked publisher; ingress: prepared, awaiting Gatekeeper |
| Terracraft quickstart | https://wiki.tiny.loca.zone/terracraft | published via locked publisher; ingress: prepared, awaiting Gatekeeper |
| Adding tools workflow | https://wiki.tiny.loca.zone/adding-tools | published via locked publisher; ingress: prepared, awaiting Gatekeeper |
| Current state | https://wiki.tiny.loca.zone/state | published via locked publisher; ingress: prepared, awaiting Gatekeeper |