Quality model
Quality is not one command. It is a set of checks matched to the risk they protect.
The repositories do not need identical scripts, but they should share the same model: source checks, Hugo checks, generated-output checks, runtime checks, and Cloudflare configuration review.
Rule#
Use the cheapest check that proves the behaviour, and add stronger checks when a public claim or shared contract depends on it.
Check layers#
| Layer | Proves |
|---|---|
| Source checks | Markdown, spelling, structured data, front matter, and config |
| Hugo checks | Templates, content mounts, relref, pages, feeds, and rendering |
| Generated-output checks | URLs, aliases, localized paths, static files, and shipped output |
| Runtime checks | Worker behaviour, analytics dispatch, forms, redirects, scripts |
| Configuration review | Cloudflare Access, WAF, bot controls, rate limits, dashboard gaps |
Public claims need tests#
Add or strengthen checks when documentation claims:
- assets are self-hosted
- analytics is privacy-first
- third-party runtime code is disclosed
- pages are bilingual
- links are stable
- protected paths are actually protected
- JavaScript is local and intentional
Accessibility checks#
Accessibility principles belong in Foundations. Component behaviour belongs in Components. Test mechanics can live under Site implementation when the tooling is ready.
This page owns the governance expectation: accessibility is part of quality, not a late visual review.
Cloudflare configuration#
Some Cloudflare settings live outside repository code today. Until those settings are automated, keep expected configuration documented, dated, and reviewable. Terraform or OpenTofu can become the implementation later; the governance rule is that dashboard-only protections still need evidence.