FCIS · SOURCE ESTATE · PUBLISHED PROJECTION

134 — EstatePublisher Is the Publication Authority

Chapter summary: EstatePublisher is the sole governed promotion boundary from reviewed local estate bytes to a remote Fountain Coach public projection. It joins route identity, the direct-static template, Store authority, owner approval, typed read-back, and public HTTPS proof without becoming a second content or runtime authority.

A reviewed route crosses EstatePublisher from local FountainStore through approval into remote Store and public read-back

Principal illustration — the publication boundary. It describes the governed path; it is not itself a receipt, a release, or proof that a route is live.

The decision

The Fountain Coach estate has one publication authority. Codex may author and inspect complete static routes, and the local FountainStore may hold the reviewed projection, but only the native EstatePublisher CLI may promote bytes for a host declared by estate/projection-manifest.json.

This is a boundary of responsibility. The Publication Core owns the page’s identity, navigation, accessibility, metadata, and visual language. FountainStore owns the admitted projection. SecretStore and the approval session authorize the effect. The remote Store and its HTTPS edge provide the deployed projection and its read-back witness.

The publishing path

complete route in estate/
  → native preview and AX/VRT acceptance
  → explicit local FountainStore
  → EstatePublisher / estate.publication.sync
  → scoped approval and opaque lease
  → authenticated remote FountainStore
  → typed manifest/path read-back
  → public HTTPS and matching digest

A route request names one canonical host and one normalized path prefix. Route-scoped publication is the default; whole-estate synchronization requires explicit whole-estate intent. The CLI discovers its operation from its typed command catalog and fails before mutation when the bundle, scope, approval, or source identity is incomplete.

What is not authority

  • The direct-static HTML is the reviewed content projection, not a deployment mechanism.
  • The local browser preview and its illustration establish design and semantic evidence, not production state.
  • Git records provenance and recovery; it does not replace Store synchronization.
  • Caddy, copied directories, generic HTTP wrappers, and retired shell helpers are not admitted publication paths.
  • Book Library import, MIDI catalog publication, and social posting remain separate systems with their own boundaries.

Acceptance boundary

Promotion is complete only when one correlated operation proves the selected route patch, signed/scoped authorization, typed remote manifest and selected-path read-back, atomic current-record evidence, public HTTPS reachability, and a matching local/remote/public digest. A successful local preview is necessary preparation, never promotion proof.

If any one of those witnesses is absent, the result is BLOCKED — publication proof incomplete. The system must preserve the reviewed source and stop at the failed seam rather than choosing another publisher.

Rules

  1. EstatePublisher is the only publication client for hosts declared in the estate manifest.
  2. Publication is the Store-to-Store operation estate.publication.sync.
  3. Bounded route intent names exactly one canonical host and normalized path prefix.
  4. Approval is scoped, expiring, replay-protected, and never reconstructed from a receipt.
  5. Credential material remains in SecretStore and never crosses the CLI bundle or public evidence.
  6. Local preview, AX/VRT, and illustrations prove preparation; they do not prove promotion.
  7. Remote read-back and public HTTPS verification are part of the terminal proof.
  8. Legacy estate write helpers fail closed and may not become a second authority.
  9. Every accepted claim is bound to source revision, governance revision, manifest, route, and digest.
  10. Separate publication systems retain their own explicit scope and must not be silently folded into EstatePublisher.

Governing sentence

Author the route in the governed template, admit it to the local Store, and let EstatePublisher be the one signed, scoped, read-back-proven passage to the public estate.