Operations docs move out of git entirely rather than being sanitized. They
stay on disk for local use and are gitignored, so the Phase 6 export (which
takes HEAD) can never carry them. 15 files: the fleet runbook, hotfix
process, node inventories, internal trackers, session handoffs, the key
rotation/signing-posture records, and the open-source plan itself.
For the docs that remain public, infra identifiers are replaced with things
that are better documentation rather than placeholders: curl examples now
use `archipelago.local`, the product's own mDNS name, so a reader can run
them as-is instead of substituting an address that was never theirs.
Deliberately NOT scrubbed, both verified as functional rather than leaked:
- `tx1138.com` is the shipped default block explorer (DEFAULT_TX_EXPLORER in
useTxExplorer.ts, surfaced in WalletSettingsModal). Product behavior.
- `git.tx1138.com` in core/container/{image_policy,registry}.rs is a retired-
registry constant the code matches on to strip stale entries from legacy
node configs. Removing it would break migration for older nodes.
- `192.168.1.254` in bulletproof-containers.md is the LAN gateway in a podman
bug description, and `192.168.1.x` in user-walkthrough.md is already generic.
Whether a personal domain should be the shipped explorer default in a public
product is a separate product question, not a security one.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
docs/archive — historical records
Documents here are finished history: completed session logs, handovers, point-in-time status snapshots, security audits of past versions, and design docs whose feature has since shipped. They are kept for provenance and are not maintained — nothing in this directory describes the current system.
For current state, start at:
docs/UNIFIED-TASK-TRACKER.md— what's open, priority-ordereddocs/PRODUCTION-MASTER-PLAN.md— north star and workstream narrativedocs/architecture.md— as-built system architecturedocs/ROADMAP.md— public-facing roadmap
| File | What it was | Why archived |
|---|---|---|
SESSION-1.8.0-OTA-PROGRESS.md |
Session narrative of the 1.8.0 OTA work | Superseded by the unified task tracker |
HANDOVER-2026-07-02-iso-feedback.md |
One-shot handover for the ISO feedback bug-bash | All fixes merged |
rust-orchestrator-migration.md |
Design for migrating container lifecycle from bash to Rust | Migration complete — prod_orchestrator.rs + boot_reconciler.rs are the live system |
demo-deployment-design.md |
Design for the public demo sandbox | Demo shipped; docs/demo-build-info.md is the live ops doc |
app-registry-status-2026-06-21.md |
Per-app migration snapshot from node .228 @ v1.7.99-alpha | Point-in-time snapshot; headline findings (immich legacy, meshtastic present) no longer true |
security-code-audit-2026-03.md |
March 2026 security audit of v0.1.0 (33 findings) | Historical record; top findings since remediated (Argon2id, persisted sessions, image verification) |
architecture-review.html |
Generated interactive architecture guide (2026-03) | Stale generated artifact; describes an early crate/app layout |
lora-functionality.html |
Generated LoRa/mesh guide (2026-04) | Predates X3DH/double-ratchet, Reticulum transport, and mesh AI |
INSTALL-SCREENS-DESIGN.md |
Installer screen design solicitation | Installer implemented in image-recipe/ |
three-mode-ui-design.md |
Design for the Pro/Easy/Chat three-mode UI | Fully implemented (stores/uiMode.ts, EasyHome.vue, Chat.vue, goals system) |