My website. cameron.stream
website docs public-knowledge.md
13 kB

Public Knowledge #

Public Knowledge is the Markdown-backed knowledge section on cameron.stream. It opens on NOW, then connects that daily synthesis to durable entries, saved links, and annotations. It is not an export of The Coil.

Storage boundary #

Knowledge entries are canonical local Markdown documents rendered by this site. Every reviewed published entry is also projected as site.standard.content.markdown under a dedicated Knowledge publication whose preferences.showInDiscover value is explicitly false.

Standard.site and Cameron's Leaflet publication are reserved for blog posts and writing Cameron publishes personally. Semble links and Margin annotations remain protocol-native records because those systems own their public object models.

Do not restore the earlier records under Cameron's main Leaflet publication or attach Knowledge to that publication by analogy. The dedicated Knowledge publication is a protocol mirror, not another editor. Its discovery preference is consumer-honored metadata rather than a universal anti-indexing guarantee.

knowledge/atproto-manifest.json binds each projected URI and CID to the exact reviewed content and review-receipt digests. New records use lexicon-valid TID record keys while the manifest preserves their stable slug-to-URI mapping. Existing records retain their historical keys. A missing source never means automatic deletion. Withdrawal requires a separate explicit operation.

Historical document records with pre-TID keys remain manifest-owned and use a narrow compatibility path when their content changes. The worker sends only those CID-guarded updates in validation-disabled batches. New records and TID-keyed updates keep server validation enabled.

Source layout #

The pipeline has three file surfaces:

  1. Private source: allowlisted notes in The Coil.
  2. Staged draft: ignored Markdown under knowledge/staged/.
  3. Published source: reviewed Markdown under knowledge/published/.

The production image copies only knowledge/published/. .dockerignore keeps general Markdown out of the image and explicitly includes that directory. Staged and private notes therefore cannot enter production through a broad build context.

Knowledge entries keep a stable slug as their repository, graph, manifest, and ATProto record identity. An optional nested route, such as language-models/gemini, places the public page under a subject namespace without changing that identity. The Standard.site mirror uses the same nested path. When route differs from slug, /knowledge/<slug> remains a permanent compatibility redirect to the canonical route.

Knowledge routes resolve only against the local published graph. Unknown routes return 404; the site does not probe Cameron's PDS for a fallback document.

Landing map #

/knowledge is the front door to a wiki intended to grow well beyond a small set of featured entries. It has four stable sections:

  1. one-sentence orientation;
  2. broad knowledge areas with links to their best overview pages;
  3. a curated Start here set;
  4. recently updated pages, search, and the complete index.

NOW is a separate top-level navigation destination at /knowledge/now. The rolling synthesis remains part of the public Knowledge corpus, but it is not embedded ahead of the landing map because temporal synthesis should not displace wiki orientation and navigation.

The landing page remains short as the corpus grows. Areas with roughly 8–12 substantive pages should gain their own map-of-content entry. Search and the complete index own exhaustive discovery; the landing map owns orientation and editorial judgment.

Metadata and entry presentation #

Frontmatter carries the editorial contract:

  • public identity: title, stable slug, optional nested route, summary, kind, and status;
  • claim handling: claimMode, perspectiveOwner, confidence, and sources;
  • graph structure: topics and related;
  • provenance: aiAssisted, generatedBy, and optional sourceDigest;
  • review state: reviewStatus, reviewBasis, exact-review or implementation-review provenance, timestamps, reviewed content digest, and route-scoped receipt digest;
  • technical publication authorization, when used: authorizer, scope, exact route, exactRenderReviewed: false, tracked receipt path, and receipt digest.

That metadata is for validation, not page decoration. Public entry pages show the title, summary, Markdown body, useful links, sources, connections, and correction route. They do not repeat claim mode, confidence, AI provenance, review state, or protocol links in a metadata slab. The Knowledge index carries one concise notice that the section is AI-maintained.

Native chart references #

Knowledge Markdown may place a repository-owned chart on its own line with the exact form {{chart:stable-chart-id}}. The reference is not an HTML escape hatch. src/knowledge-charts/registry.ts owns a strict discriminated schema, the chart's source and method notes, its stable DOM identity, and an explicit allowlist of entry slugs that may use it. Unknown, malformed, duplicate, unauthorized, or invalid references fail graph loading deterministically.

Every Knowledge body, including the overview and NOW excerpts on /knowledge, renders in the Markdown renderer's safe mode: arbitrary HTML, SVG, scripts, event handlers, and executable URL protocols remain inert. A chart reference is split before Markdown rendering and dispatched server-side to the shared typed SVG components. The result includes an accessible SVG title and description, a keyboard-accessible HTML data table, and source/method notes. Chart pages load public/charts.css without adding a client-side chart runtime. The Standard.site projection expands the same validated spec into portable Markdown tables and provenance text rather than publishing a site-private directive that other readers cannot interpret.

The reviewed content digest includes the digest of every referenced registry spec. Changing chart data, provenance, method notes, allowed entry scope, or encoding therefore invalidates the owning page's review digest even when the Markdown marker itself does not change. Chart-bearing updates use the same staged promotion gate as prose updates.

Declassification and review #

knowledge/policy.json is default-deny. A source mapping permits staging and inspection, not publication.

The publication gate removes private paths, unresolved wikilinks, conversations, health, relationships, finances, housing, unpublished plans, internal company context, and mosaic disclosures. People are denied by default; Cameron's factual entry is the only current person exception.

The ordinary path is exact rendered review by Cameron. Promotion records reviewBasis: exact-render-review, reviewedBy, reviewedAt, the canonical public-content digest, and an opaque route-scoped review receipt digest.

The technical-artifact exception is different. It authorizes implementation and publication through the supported workflow without claiming exact Cameron review. That path records reviewBasis: technical-publication-authorization, Co's implementation review, and a tracked route-scoped authorization receipt whose metadata says exactRenderReviewed: false. The promotion command verifies the receipt bytes, fields, route, and digest before writing approved Markdown. It rejects technical authorization carrying exact-review fields.

Any body or content-bearing metadata change changes the content digest. A chart spec change also changes the digest of every page that references it.

knowledge:check fails on graph errors, privacy-policy findings, unsupported people, unsourced factual entries, zero-link entries, and published Markdown whose content no longer matches its reviewed digest.

Current understanding #

knowledge/published/now.md is the current public synthesis. knowledge/published/daily-YYYY-MM-DD.md files are dated archives.

NOW is Cameron's current public understanding as reconstructed from public evidence and maintained by Co. It is a rolling, revisable model rather than a daily activity report. Its authoritative inputs include the existing public knowledge graph, Cameron's public posts, public code and talks, and Semble or Margin records. Recent activity is evidence only when it changes, strengthens, or complicates the model.

Each update should distinguish explicit public claims from Co's attributed inference, retain live contradictions, and name an unresolved edge when one is real. It should preserve durable understanding across days instead of replacing the page with whichever post happened most recently. It is never a redaction of the private daily note, a project-status ledger, or a social-feed recap. Passing is better than manufacturing movement.

NOW uses plain technical English for an intelligent reader who has not followed the underlying projects. State one current thesis first. Keep the page to three to five short paragraphs and usually 180–260 words. Each sentence should carry one idea; define necessary terms on first use and remove internal vocabulary that the page does not explain. Run the technical-writing opener, pronoun, sentence-length, filler, and LLM-tell passes before promotion. The target is clarity without discarding technical precision.

The daily editorial schedule runs at 00:47 America/Los_Angeles and delegates to the publishing-public-knowledge skill. Its standing authorization covers only the NOW and dated-archive artifact class. Repository-to-runtime deployment and ATProto projection are separate and delegate to the syncing-public-site-content skill after reviewed Markdown reaches main.

Each successful pass must:

  1. reconstruct the current model from the public graph and supporting public signals;
  2. compare it with the prior NOW and revise only what the evidence changes;
  3. write or update the reviewed NOW and dated archive Markdown sources;
  4. run the policy, graph, link, and reviewed-digest checks;
  5. build a production image and verify both files are bundled;
  6. leave the reviewed source ready for the repository sync worker.

The sync worker then deploys the current Git source, reconciles all reviewed Knowledge records with CID compare-and-swap, records receipts, and verifies the live routes. The editorial pass does not duplicate those mechanics.

Commands #

# Stage an allowlisted source. This never publishes.
pnpm knowledge:stage "$HOME/Documents/The Coil/lessons/example.md" \
  --summary "Public summary" \
  --source "Primary source=https://example.com"

# Validate staged and published Markdown and print content digests.
pnpm knowledge:check --include-drafts

# Preview staged pages locally under noindex headers.
KNOWLEDGE_INCLUDE_DRAFTS=1 pnpm dev

# Promote after exact rendered approval and a route-scoped receipt.
pnpm knowledge:promote example \
  --review-basis exact-render-review \
  --reviewed-by Cameron \
  --content-digest sha256:... \
  --review-receipt-digest sha256:... \
  --confirm-public

# Promote an explicitly authorized technical artifact without fabricating exact review.
pnpm knowledge:promote example \
  --review-basis technical-publication-authorization \
  --implementation-reviewed-by Co \
  --authorized-by Cameron \
  --authorization-recorded-at 2026-07-26T04:49:49Z \
  --authorization-route example \
  --authorization-receipt-path knowledge/receipts/technical-publication/example.json \
  --content-digest sha256:... \
  --review-receipt-digest sha256:... \
  --confirm-public

# Deploy and reconcile reviewed source through the credential-provisioned unit.
systemctl --user start cameron-site-content-sync.service
systemctl --user show cameron-site-content-sync.service \
  --property=ActiveState,SubState,Result,ExecMainStatus --no-pager

# Preview one projected record or the complete reviewed collection.
pnpm knowledge:sync --slug public-knowledge
pnpm knowledge:sync --all

Standard.site mirroring remains a different operation from Markdown promotion and review. It is automatic only after the source has entered clean Git main. The shell script behind the systemd service is an implementation detail. Direct invocation requires the complete private worker environment; a normal shell can otherwise complete the Fly deployment and then stop at the missing PDS credential, leaving a partial run for the service to recover. The same boundary applies to knowledge:sync --apply: use the service for writes, and keep direct CLI calls credential-free and read-only.

The service uses ~/.local/share/cameron-site/deploy-checkout, a dedicated clone that no human or agent edits. This prevents local development commits, worktree changes, or an ahead main in the development clone from blocking automatic deployment. deploy/systemd/install-content-sync-worker.sh installs the stable runner and user units but deliberately does not start a deployment.

The service does not expose the PDS credential to dependency installation, tests, Git, or Fly. It passes the credential only to the bounded About and Knowledge apply subprocesses after the credential-dark plans and checks pass.