nhi.sgit.ai / packs / static-publishing / publish-target

07 — The publish output

PackStatic Publishing, `sgit vault serve`, and the Publishing Matrix RoleRevised 19 Aug (three times): publish takes no target, copies no ciphertext, and its folder is plainly committable — the gitignore that matters guards key material Date17–19 August 2026 · pack v0 OriginArchitect-review agent, SGit-AI__CLI repo Sourceraw markdown · original on GitHub Captured19 August 2026, at commit a7fb3f5 — the raw file under src/ is byte-identical to that commit

Summary

The first version of this file was a rule policing where an output directory may live — the maintainer removed the question instead: sgit publish takes no target, writes .sg_vault/publish/ and nothing else on disk, and deployment is a separate act. Then r9 removed the last copy too: the output is the plaintext surface only — loader, cover, manifest, key file, optional API docs — and never contains ciphertext. The manifest enumerates the store (ids, sizes, sha256), so publishing is O(KB) regardless of vault size (measured: 5 files, ~5 KB, for a 22-object store), and re-publishing never churns a gigabyte store. The served root is composed at deployment — co-located (the one-repo pattern: serve the repo, zero copies) or assembled by a keyless copy of bare/ into place — and sgit vault serve composes virtually by routing. Invariant I1 becomes true by construction: what is served is the store. The two index.html files stay apart: the loader is generated plaintext, always sgit's template; the vault's own index.html is encrypted content — the decrypted page wins at expanded deployment. r10 then removes the folder's * self-ignore: in the canonical one-repo flow the folder must reach GitHub — it is what the Pages workflow deploys — and post-r9 it is a few KB of plaintext with nothing sensitive, so plain git add -A includes it. The gitignore that matters is the three-line repo-side set guarding key material.

Key concepts

Key ideas

Read the document

📄 Pack document · 07__publish-target.md · rendered from the raw markdown (the source of truth)