chore: take vote-service out of the repository root
verify-and-publish / gate (push) Successful in 14m4s
verify-and-publish / publish (push) Has been skipped

Removes the Go source, Dockerfile, go.mod, and Kubernetes manifests. The
deployed service is untouched and the review desk still calls it over
window.SKILLS_REVIEW_VOTE_API; only the source leaves.

The runbook does not leave. vote-service/README.md moves to
docs/vote-service.md, because it carries the parts that are hard to
rediscover: why the ingress overwrites X-Forwarded-For and Caddy stamps
X-Client-IP instead, why the image is side-loaded into containerd rather
than pulled, and why the PVC pins the Deployment to one node.

This drops verify.mjs from 84 assertions to 83. The removed one read
vote-service/main.go for X-Forwarded-For and 'one active vote per skill'
-- the review desk's only anti-abuse control -- and there is no file left
to read. It is the first assertion this repository has ever lost.

Rather than lower the gate's floor and leave a bare number behind,
gate.sh now subtracts the number of entries in
.agents/context/assertion-removals.md from the baseline. A removal costs
a written reason in a tracked file, in the same commit, as a visible
diff. Tested at 82 assertions: still refused.

Also drops the 22 MB of PNG baselines under .agents/snapshots/before/ and
before-reduced-motion/. They pictured the hand-written site, which no
longer exists; visual-regression.mjs has no compare mode to diff them
against; and they are recoverable from d88d8b8.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Marcos Paulo
2026-09-06 08:59:45 +00:00
parent d88d8b89eb
commit 9015e7bd1d
96 changed files with 122 additions and 504 deletions
+7 -6
View File
@@ -47,7 +47,6 @@ const source = {
read('src/content/providers/gemini.json'),
].join('\n'),
starter: read('public/hands-on/starter/app.js'),
voteService: read('vote-service/main.go'),
ndoReview: read('src/content/reviews/ndo-repro.md'),
};
@@ -430,10 +429,12 @@ if (
!/\[aria-pressed=["']?true["']?\]/.test(builtCss)
)
throw new Error('review vote-widget CSS contract missing');
if (
!source.voteService.includes('X-Forwarded-For') ||
!source.voteService.includes('one active vote per skill')
)
throw new Error('vote-service missing IP-based one-vote-per-source contract');
// The `vote-service` one-vote-per-IP assertion was removed when the service's
// source left this repository. It read `vote-service/main.go` for
// `X-Forwarded-For` and `one active vote per skill`; there is no file left to
// read. The contract still matters -- it is the review desk's only anti-abuse
// control -- so it has to be re-asserted wherever the service now lives. This
// is the only assertion this repository has ever dropped, and the count
// baseline moved 84 -> 83 to record it.
console.log('built output verification passed');