PIPE_WEBSITE_2026-07-29.md

pipelines/PIPE_WEBSITE_2026-07-29.md

PIPE_WEBSITE — humanityrpg.com marketing site + press-kit lane (ZERO-GPU)

Scope: the owned web presence per docs/MARKETING_WEB_PROGRAM.md. Title on every outward surface =

HUMANITY FORGOTTEN. Go-live RULED at first real captures. Domain registered, Cloudflare Registrar,

zone parked, 0 records. Email Routing DEFERRED — not re-offered anywhere below.

Every claim marked [V] carries a fetched source URL; anything I could not confirm is marked

UNVERIFIED and excluded from the primary path.

1. THE VERIFIED STACK

JobPRIMARYLicenceSourceFALLBACK
Static generatorAstro 7.1 (7.0 2026-06-22; 7.1 2026-07-16) [V]MIT, © Fred K. Schott + contributors [V]https://astro.build/blog/ · https://astro.build/blog/astro-7/ · https://github.com/withastro/astro/blob/main/LICENSEPin Astro 6.4 (2026-05-28) [V] if 7.x's Rust compiler's strict-HTML break bites
Runtime floorNode ≥22.12 for Astro 7 [V, secondary]; box has Node v24.15.0 / npm 11.12.1 (verified locally)search: Astro 7 Node requirement
HostCloudflare Workers static assets — "Requests to static assets are free and unlimited" [V]; 20,000 files Free / 100,000 Paid; 25 MiB per file; script 3 MB gz Free [V]Cloudflare ToShttps://developers.cloudflare.com/workers/static-assets/billing-and-limitations/ · https://developers.cloudflare.com/workers/platform/limits/Cloudflare Pages — same account, "Available on all plans", 20,000 files Free / 100,000 Paid, 25 MiB/file, 500 builds/mo, 1 concurrent build, 100 custom domains Free [V] (https://developers.cloudflare.com/pages/platform/limits/)
Host recommendationAstro's own Cloudflare deploy guide states verbatim: *"Cloudflare recommends using Cloudflare Workers for new projects. For existing Pages projects, refer to Cloudflare's migration guide"* [V] https://docs.astro.build/en/guides/deploy/cloudflare/HONESTY NOTE: I fetched /pages/, /pages/get-started/ and the Pages→Workers migration guide directly and found no Cloudflare-authored deprecation or maintenance banner. "Pages is in maintenance mode" is third-party blog characterization — do not repeat it as fact. Pages stays a first-class fallback.
CI / deployWorkers Builds — Git-connected (GitHub/GitLab), 3,000 build-min/mo Free (1 concurrent) / 6,000 Paid + $0.005/min, 20-min build timeout, per-PR preview deployment [V]Cloudflare ToShttps://developers.cloudflare.com/workers/ci-cd/builds/limits-and-pricing/GitHub Actions + cloudflare/wrangler-action v4, dual Apache-2.0 / MIT [V], needs apiToken + accountId secrets — https://github.com/cloudflare/wrangler-action
VideoCloudflare Stream — $5 / 1,000 min stored, $1 / 1,000 min delivered, no stated minimum [V] https://developers.cloudflare.com/stream/pricing/Cloudflare ToSR2 + our own <video> — $0.015/GB-mo standard, egress free, free tier 10 GB-mo + 1M Class A + 10M Class B [V] https://developers.cloudflare.com/r2/pricing/
Bulk downloads (press-kit ZIP, 4K stills)R2 public bucket on a custom domain — requires the zone in the same Cloudflare account (it is) [V]; Cloudflare Cache applies [V] https://developers.cloudflare.com/r2/buckets/public-buckets/Cloudflare ToS
AnalyticsCloudflare Web Analytics — verbatim: *"We don't use any client-side state (like cookies or localStorage) for analytics purposes"*; *"we consider 'fingerprinting' even more intrusive than cookies"*; *"our analytics is free."* [V] https://blog.cloudflare.com/privacy-first-web-analytics/Cloudflare ToSNone. Known limit: no funnels, weak UTM decode. Adding any third-party script re-introduces a consent banner → that is a new brief, not a default.
i18n routingAstro built-in i18n (defaultLocale · locales · routing.prefixDefaultLocale · fallback + fallbackType) [V] https://docs.astro.build/en/guides/internationalization/ — it does NOT emit in-page hreflang; a hand-built <Hreflang> component is required [V]MIT
hreflang / sitemap@astrojs/sitemap i18n: {defaultLocale, locales} emits <xhtml:link rel="alternate" hreflang=…> per URL [V] https://docs.astro.build/en/guides/integrations-guide/sitemap/MITGoogle rules [V]: self-reference, bidirectional or the tags are ignored, ISO 639-1 + ISO 3166-1 Alpha-2 only, fully-qualified URLs, x-default — https://developers.google.com/search/docs/specialty/international/localized-versions
Imagesastro:assets + sharp (default service), <Picture /> emits multi-format + srcset, AVIF and WebP outputs, transformed at build for prerendered pages [V] https://docs.astro.build/en/guides/images/MIT (sharp: Apache-2.0, licence read at install)AVIF ≈94-95% / WebP ≈97% global support, caniuse Mar-Apr 2026 [V, secondary]AVIF→WebP→JPEG ladder holds; no AVIF-only
Canon→site contentAstro Content Layerglob() + file() loaders, file() takes a parser for .csv, plus custom loaders for any API/DB [V] https://docs.astro.build/en/guides/content-collections/MITthis is the bridge onto registries/**/*.csv — no new format, no second copy of canon
Visual QAPlaywright 1.57.0, Apache-2.0 (© Microsoft) [V, secondary]Apache-2.0search: Playwright licence 2026
Perf/a11y budgetLighthouse CI action, Apache-2.0 [V, secondary] treosh/lighthouse-ci-actionApache-2.0search: Lighthouse CI action licence
Press kitpresskit() / dopresskit.com is DEAD as a tool — PHP 5 + FTP + manual XML [V] https://dopresskit.com/ · https://github.com/ramiismail/dopresskit. Adopt its STRUCTURE only (factsheet · description · history · features · videos · images · logo+icon · awards · quotes · links · contact) as an Astro route.our own MIT-free contentpresskit.gg / Press Kitty exist [V] but are REJECTED: third-party hosting, we own the domain and the data
Framework fallback (second vendor)Eleventy 3.1.6, Node ≥18, i18n + Image plugins exist [V] https://www.11ty.dev/docs/ — LICENCE NOT CONFIRMED this pass (the docs page does not state it). Licence read REQUIRED before any adoption.UNVERIFIEDnot on the primary path

LICENCE VERDICT for this lane: clean. Every primary component is MIT / Apache-2.0 / a paid

Cloudflare service. No component taints shippable output; no non-commercial licence anywhere on

the path. The only unresolved licence is Eleventy's, which is why it is fallback-only.

Two corrections to repo docs (I am read-only; flagging for the director):

1. docs/MARKETING_WEB_PROGRAM.md:54 and handoff §5.4 say *"Pages ToS prohibits video files (512MB

cache cap)"*. The verified clause is in the Application Services service-specific terms, and

it covers the CDN on Free/Pro/Business, verbatim: *"Cloudflare reserves the right to disable

or limit your access to or use of the CDN … if you use or are suspected of using the CDN without

such Paid Services to serve video or a disproportionate percentage of pictures, audio files, or

other large files."* [V] https://www.cloudflare.com/service-specific-terms-application-services/

It is a reserve-the-right clause, not a flat prohibition; **512 MB is the CDN max cacheable file

size on Free/Pro/Business (5 GB Enterprise) [V, secondary], not** a Pages cap — the

Pages/Workers per-file cap is 25 MiB. Operational conclusion is unchanged: video → Stream/R2.

2. Handoff §5.4 names Pages as the host; the current recommendation for new projects is Workers

(quoted above). Same account, same zone, same bandwidth story — flip the primary, keep Pages named.

2. INSTALL PLAN

D-1 does not bind this lane. Zero CUDA, zero torch, zero container. **Native Windows, no WSL2,

no Docker** — stating it explicitly so nobody containerizes a static-site build for symmetry.

Disk placement (per the RULED layout): the site is a separate repoC:\dev\humanity-site\

on Slot 1 Gen5 (C:), beside C:\dev\humanity-forgotten and C:\dev\Humanity. Reasoning: it is a

git-hot, latency-bound small working tree, not a model store; the Gen4 "models/ComfyUI/projects

cache" role is for the GPU lanes. Redirect the bulk cache to Gen4 with npm_config_cache=D:\npm-cache

(the same env-var mechanism Stage 1.5 uses for HF_HOME/PIP_CACHE_DIR). Capture masters and

press-kit archives stage on Slot 4 (E:) with the soak/QA capture archives, and only web

derivatives ever enter the site repo. It must not live inside C:\dev\humanity-forgotten — a

package.json + node_modules inside the gate-enrolled canon tree collides with run_gates.py and

the fidelity baseline.

Order (each step verifiable before the next):

1. npm create astro@latest humanity-site -- --template minimal --typescript strict → confirm 7.1.x

2. npx astro add sitemap → configure i18n (defaultLocale en; ring: `en · zh-Hans · de · fr ·

es-419 · ja · ru, then ko · pt-BR), routing.prefixDefaultLocale: false, fallbacken`

3. hand-build <Hreflang> (self-ref + symmetric + x-default) — Astro does not emit it

4. CSS logical properties + dir wiring from commit 1 (free now, a rewrite later); Intl for all

dates/numbers

5. npm i -D @playwright/testnpx playwright install --with-deps chromium firefox webkit

6. npm i -D wrangler (v4) → wrangler.jsonc, static shape (Astro's own documented minimal

config): { "name": "humanity-site", "compatibility_date": "…", "assets": { "directory": "./dist" } }

no main, so no Worker script is invoked and every request is a free static-asset request

7. Lighthouse CI config + budget json

8. git init, push to a new GitHub repo, connect Workers Builds

Thursday-night download list (≈ sizes, honestly approximate — this is the smallest lane on the box):

skeleton built pre-box, today, on the current machine (Node 24.15.0 confirmed present).

3. THE INTEGRATION CONTRACT (DR-2 → web)

The site is a downstream consumer of canon ids. It is never a second home for assets.

presentation_tier_ref / decay_stage where the surface carries them). One build-time resolver —

an Astro Content Layer loader reading registries/**/*.csv via file({ parser }) plus the

assetgen columns — maps id → published web derivative. Zero content paths in page source.

DR-2 §1 holds verbatim on this side.

a placeholder*. The public site must not. Only generation_status = complete and QA-13

reviewed may publish. pending / in_progress / rejected / regeneration_required on a

referenced id fails the build — tooth T-WEB-STATUS.

generation_prompt_hash is part of the derivative filename, so a re-generation is automatically

cache-busted and a stale published asset is impossible to leave up silently.

ceiling; the House-of-Velheim pattern grep returns 0 on public routes (the standing reveal

discipline — invoked-and-negated agent-nouns leak too).

route fails the build. In-fiction world-name uses inside quoted lore prose are the declared

exception and must sit inside a <Lore> component so the tooth can scope. (tha ltd. holds US TM

"HUMANITY" in the game class, SN 88732793.)

HL_0043 clearance recorded, zero cassus load — docs/spine/DECISIONS_PENDING_JOSH.md:554). Internal

taxonomy nouns never surface: no verb classes (Direct/Environmental), no "mode", no care_tier, no

tier vocabulary (the no-mode-taxonomy ruling).

spec-class rule (ENGINE_OPTIMIZATION_DOCTRINE.md §1.2 / U-35) generalized to the whole site.

web derivatives AVIF + WebP + JPEG via <Picture>. Video: Stream (adaptive, AVIF poster,

click-to-play facade, never autoplay a full trailer); any self-hosted clip ships the AV1 + HEVC +

H.264 ladder (Safari's AV1 hardware gap — never AV1-only). Press kit: a ZIP in an **R2 public

bucket on assets.humanityrpg.com — mandatory, because a real 4K press ZIP exceeds the 25 MiB**

static-asset cap and would also run into the 512 MB CDN cache ceiling. Captures double-serve as QA

evidence: same frames, two consumers.

light/dark × the launch locales, read by a fresh-context image critic exactly as game-side work is

verified; plus Lighthouse budget assertions and an a11y pass. **A page is not done until it is

screenshot-proven.**

4. THE AUTONOMY CONTRACT

registries — e.g. rows with generation_status=complete + a web_publish flag → one showcase page

each, one locale set each. Content authoring and site code both fan out at the top Opus tier,

model set explicitly; the director does integration and contested adjudication only.

green, (c) the Playwright matrix is captured and read clean by a fresh critic, (d) the

Lighthouse budget is met. Demote: any red → the page keeps its draft flag, drops out of the

sitemap and the hreflang cluster (a one-sided hreflang link is worse than none — Google ignores the

whole pair), and the previous deploy stands.

preview deploys on branches, R2 uploads. Attended (director or Josh): the first production

deploy to the apex domain, any wrangler.jsonc route/custom_domain change, tagline and

store-facing transcreated copy, and go-live itself.

≈4-8 GB RAM and ~4 cores (Astro 7 + sharp AVIF encode + a 3-engine Playwright run). It shares

nothing with the GPU lanes, but it must not run concurrently with a UE cook or lighting build

those are the CPU-core/RAM/NVMe-bound jobs HARDWARE_DECISION names, and this lane writes to the same

Gen5 drive. Run it in the UE-idle window, or nice it. It never waits on model budget.

5. JOSH-MINIMUM (his hands or his account only)

long-lived API token: it is one OAuth authorization and no secret ever enters our repo. (The

alternative, if he prefers repo-controlled CI: mint a scoped API token — Account:Workers

Scripts:Edit + Zone:DNS:Edit + Zone:Workers Routes:Edit, scoped to humanityrpg.com only — and

place it in GitHub secrets. His hands; agents never handle tokens.)

action). If gh is already authed on the box (runbook J5), he can instead just say go and I run

gh repo create.

Worker deploys with custom_domain = true, and the zone is already in the right account [V] — so

his part is only the initial authorization; after that I do it via wrangler. **No manual DNS

record typing is required of him.**

Email Routing is DEFERRED and is not being re-offered; this is simply "which existing address

goes on the page," or "defer the contact block to go-live." A decision, not a task.

he says go.

item), and the defensive-variant re-check at go-live.

capture wiring, every QA gate, every preview deploy. That is all mine.

6. BENCHMARK-DAY QUESTIONS (measured before the final picks)

1. Astro 7.1 vs pinned 6.4 — build wall-clock on the real page count × 7 locales, and does the

Rust compiler's strict-HTML behaviour (no auto-close, no tag reordering, JSX whitespace) break

anything we author? The 15-61% build-time claim is Astro's; measure ours.

2. AVIF encode cost — sharp AVIF wall-clock and output size on a real 4K UE capture at q50/q60/q70.

Where is the AVIF-vs-WebP size crossover for *our* art (high-detail 3D renders, not photos)?

3. The 20-minute Workers Builds timeout — does image generation × locales fit? If not: move to

GitHub Actions, or pre-encode derivatives into R2 and let the build only reference them. This is a

hard pass/fail number, not a preference.

4. File and size counts vs the caps — 7 locales × N pages × M image variants against **20,000

files Free / 100,000 Paid and 25 MiB per file**. Count before choosing Free vs Paid.

5. Stream vs R2-self-hosted delivery cost at a realistic launch-week view count ($1/1,000 min

delivered vs free R2 egress plus our own player and our own ABR ladder). Needs real trailer

durations, so it is a post-capture measurement.

6. Playwright matrix wall-clock on the 9950X3D (breakpoints × themes × locales × pages) — does

the full matrix fit inside a UE-idle window, or does it need sharding?

7. Real LCP on mid-range mobile over 4G with the hero AVIF — and only after that number exists may

any performance statement appear on a public surface (T-WEB-CLAIM).

Generated by harness/site/structure_site.py — the URL path is the repo path. review root