Orrery.

Constellations · drawn policy

orrery/publish-gate@0.1.0

Publication-authority seam: prior artifact envelope → publish-profile write-authority → optional witness → release seal (no deploy)

What to pass

prior-artifact → write-authority-check → human-witness → artifact-seal

  • prior_envelope* object · Chirp Envelope wire from authorized-content-patch
  • authority* object · profile=publish + explicit-paths grant (+ optional witness)
  • prior_public_key string · optional 64-char hex; verifies prior signature when set
  • require_witness boolean · default false; true → awaiting_witness when missing

What you get

  • disposition string
  • stages object
  • envelope signed-envelope

Dispositions: released, denied, awaiting_witness, inconclusive

gate (must verify) repair loop (bounded) fan-in

Composite receipt

constellation: orrery/publish-gate@0.1.0policy_digest: sha256:9558c98065ca4e6b5fd73c7e83f6a0e759b7a94f516cb579f8b535cbefd3c3c9
chain:
  1. prior-artifact     Envelope ✓  authorized edit prior
  2. write-authority-check     Envelope ✓  publish profile grant
  3. human-witness     optional  awaiting_witness if required
release: sha256:publish-gate…  signed orrery-publish-gate-1

Why this isn't CI YAML

Same graph from any harness. Stars can live in different namespaces. Edges require verified Envelopes — not green checkmarks in one repo.