Generated CI contract
What every pipeline written by entwine setup guarantees, whatever the provider.
See deployment for the provider details.
Behavior
- A pull or merge request changing
docs/**runsentwine checkand fails on Entwine validation errors only. Recommended-knowledge gaps are warnings. - A change to
docs/**on the default branch runsentwine check, thenentwine build, then publishes the artifact that build produced, without rebuilding differently at deploy time. - Unrelated source changes do not trigger documentation builds.
- Pull and merge requests are never published.
Safety
- Least privilege: on GitHub only the deploy job can write Pages or request an OIDC token.
- No credential appears in any generated file. Bitbucket's token is a secured provider variable.
- Generation is deterministic and idempotent; existing files are never replaced.
- The default branch comes from the provider where it exposes one.
Non-goals
No entwine publish, no hosted service, and no code-to-documentation drift
detection. These are tracked in the roadmap.