Quality model

Quality is not one command. It is a set of checks matched to the risk they protect.

The repositories do not need identical scripts, but they should share the same model: source checks, Hugo checks, generated-output checks, runtime checks, and Cloudflare configuration review.

Rule#

Use the cheapest check that proves the behaviour, and add stronger checks when a public claim or shared contract depends on it.

Check layers#

LayerProves
Source checksMarkdown, spelling, structured data, front matter, and config
Hugo checksTemplates, content mounts, relref, pages, feeds, and rendering
Generated-output checksURLs, aliases, localized paths, static files, and shipped output
Runtime checksWorker behaviour, analytics dispatch, forms, redirects, scripts
Configuration reviewCloudflare Access, WAF, bot controls, rate limits, dashboard gaps

Public claims need tests#

Add or strengthen checks when documentation claims:

  • assets are self-hosted
  • analytics is privacy-first
  • third-party runtime code is disclosed
  • pages are bilingual
  • links are stable
  • protected paths are actually protected
  • JavaScript is local and intentional

Accessibility checks#

Accessibility principles belong in Foundations. Component behaviour belongs in Components. Test mechanics can live under Site implementation when the tooling is ready.

This page owns the governance expectation: accessibility is part of quality, not a late visual review.

Cloudflare configuration#

Some Cloudflare settings live outside repository code today. Until those settings are automated, keep expected configuration documented, dated, and reviewable. Terraform or OpenTofu can become the implementation later; the governance rule is that dashboard-only protections still need evidence.