Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -3,4 +3,5 @@ node_modules/
.env
.env.local
.env.*.local
CLAUDE.local.md
.DS_Store
2 changes: 1 addition & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ Apps go in `apps/`, shared code in `packages/` — extract a package only when t
- Add or update tests for important behavior.
- Never weaken tenant isolation, authorization, auditability, or data integrity for convenience.
- Never modify an existing applied database migration; add a new one.
- Sign off commits with `git commit -s` (Developer Certificate of Origin); pull requests opened by `quality-runtime[bot]` are exempt.
- Sign off commits with `git commit -s` (Developer Certificate of Origin). Commits authored as `quality-runtime[bot]` are not signed off — a bot cannot make the certification — and pull requests it opens are exempt from the check.

## Licensing

Expand Down
6 changes: 6 additions & 0 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -198,6 +198,12 @@ Additional services must not become mandatory without strong operational justifi

Cloud-provider-specific implementations live in deployment adapters, and the application must remain portable to other environments.

Hostnames are configuration. The runtime assumes no hosted service's domains; custom domains and their certificates belong to the deployment in front of it.

Public pages, when they exist, are server-rendered routes in `apps/server` answered only on a separate public origin the deployment configures, so nothing served there can use a session: they need no sign-in, set no session cookies, and render structured records, never tenant-supplied HTML or scripts. Printed addresses use immutable identifiers, so they survive a record's rename.

Anything that needs a sign-in, including an outside reviewer's read access, stays on the application's origin; a public page may link to it.

## Hosted product boundary

The public runtime contains functionality generally useful to anyone operating Quality Runtime themselves. Hosted-service concerns (billing, subscriptions, provisioning, usage metering, entitlements, internal cloud operations) stay outside it.
Expand Down
1 change: 1 addition & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
@@ -1 +1,2 @@
@AGENTS.md
@CLAUDE.local.md
Loading