# Inquiry Publishing Stack Human conceptual entrypoint: https://inquirystack.philohub.workers.dev/ Human Guide: https://github.com/ChongLiuPhil/AI-Assisted-Human-Inquiry-and-Creation-Protocol/blob/main/docs/HUMAN_GUIDE.md Machine/configuration entrypoint: https://inquirystack.philohub.workers.dev/agent/ Machine descriptor: https://inquirystack.philohub.workers.dev/agent/entry.json Machine-readable ecosystem: https://github.com/ChongLiuPhil/Inquiry-Publishing-Project-Starter/blob/main/ecosystem.yaml Canonical ecosystem: https://github.com/ChongLiuPhil/Inquiry-Publishing-Project-Starter/blob/main/docs/ECOSYSTEM.md Machine-readable ecosystem: https://github.com/ChongLiuPhil/Inquiry-Publishing-Project-Starter/blob/main/ecosystem.yaml Agent retrieval contract: https://github.com/ChongLiuPhil/Inquiry-Publishing-Project-Starter/blob/main/docs/AGENT_RETRIEVAL_CONTRACT.md Project provisioning contract: https://github.com/ChongLiuPhil/Inquiry-Publishing-Project-Starter/blob/main/docs/PROJECT_PROVISIONING_CONTRACT.md Project provisioning acceptance: https://github.com/ChongLiuPhil/Inquiry-Publishing-Project-Starter/blob/main/docs/PROJECT_PROVISIONING_ACCEPTANCE.md Cloudflare public-delivery migration: https://github.com/ChongLiuPhil/Inquiry-Publishing-Project-Starter/blob/main/docs/CLOUDFLARE_PUBLIC_DELIVERY_MIGRATION.md Cloudflare migration state: https://github.com/ChongLiuPhil/Inquiry-Publishing-Project-Starter/blob/main/templates/cloudflare-public-delivery.yaml Cloudflare operational guide: https://github.com/ChongLiuPhil/Inquiry-Publishing-Project-Starter/blob/main/docs/CONTINUOUS_WEB_CLOUDFLARE.md Trusted Secret Broker contract: https://github.com/ChongLiuPhil/Personal-Publishing-Framework/blob/main/docs/TRUSTED_SECRET_BROKER.md Private-project CI cost policy: https://github.com/ChongLiuPhil/Personal-Publishing-Framework/blob/main/docs/CI_COST_POLICY.md Current component: Inquiry Publishing Project Starter Role: composition, adoption, profile, project-provisioning orchestration, and upgrade layer. It is not a fourth normative framework. Public component homepages: - AHICP: https://inquirystack.philohub.workers.dev/ - PPF: https://inquirystack.philohub.workers.dev/ppf/ - Vault Interface: https://inquirystack.philohub.workers.dev/vault-interface/ - Starter: https://inquirystack.philohub.workers.dev/starter/ Default new-project baseline: full AHICP + full PPF + Vault Interface + project-owned content. Preferred ordinary new-project infrastructure profile: workers-builds-native. Default private-project CI cost profile: private-project-quota-saver. Default downstream GitHub owner: personal account ChongLiuPhil; owner type: user; repository visibility: private. The ordinary setup uses one human-assisted project bootstrap: create/confirm the private repository, authorize/connect it to Cloudflare Workers Builds, protect the Worker with Access, verify the first restricted deployment, then verify a second push without renewed authorization. Private downstream content-only changes do not start GitHub Actions; configuration PRs targeting main use one lightweight contract job; main pushes do not run a duplicate GitHub Web build; heavy GitHub workflows are manual; automatic success artifacts stay off and manual publication artifacts retain for one day; Cloudflare Workers Builds owns the automatic production Web build. Agents must batch edits/preflight instead of debugging through repeated Actions runs. CI tiers are ordinary private `private-project-quota-saver`, hardened external `external-ci-required`, and public-framework `full-validation`. Public release, source-repository publication, reader-audience expansion, domain/DNS authority, provider-scope expansion, paid-plan changes, and any decision to buy more Actions usage remain human-reserved. Provider credential plaintext must never enter model context. The default Workers Builds Native profile uses provider-managed credentials and does not require the Trusted Secret Broker. The PPF external-CI + Broker path remains an optional advanced profile; its Cloudflare granular-token issuer is still live-acceptance-pending. Privacy default: original or unpublished project source is private. Continuous Web may be enabled with restricted reader access. Do not retrieve private state without explicit human authorization. Never request or store passwords, API tokens, private keys, recovery codes, or other secrets in chat or Git. Agent instruction: From any component entrypoint, reconstruct the full ecosystem before cross-component configuration. Fresh-read the downstream stack and pinned upstream manifests. For Cloudflare actions, provide numbered operator steps, verification criteria, and rollback instructions. Public delivery policy: The owner approved the unified public Worker at https://inquirystack.philohub.workers.dev/ as the canonical site. GitHub remains canonical source. Former framework GitHub Pages sites have been retired; use the previous verified Worker version for rollback; previews remain disabled pending separate Access acceptance. Verified delivery state (canonical cutover accepted 2026-09-23): One unified website, one active Cloudflare Worker, four independent GitHub authorities. Human canonical path: /; machine canonical path: /agent/ on the same provider-native workers.dev hostname. The cutover is verified. Roll back through the previous verified Worker version or a reviewed revert; the former framework GitHub Pages sites are retired and are not rollback targets. Composition source lock: https://github.com/ChongLiuPhil/Inquiry-Publishing-Project-Starter/blob/main/site/sources.lock.json Approved architecture and boundaries: https://github.com/ChongLiuPhil/Inquiry-Publishing-Project-Starter/blob/main/docs/UNIFIED_PUBLIC_SITE.md Only Starter needs a Git integration grant for this build; other public upstream files are fetched at pinned SHAs without credentials. Canonical unified-site routes: / = AHICP-led human entry /agent/ = Starter machine entry /agent/entry.json = descriptor /build-info.json = source revisions and content hashes