Appendix E30

Appendix E

2 min read Section 30 of 30

Appendix E. Primary sources

References were checked on 10 October 2026. They support specific tool behavior, not a claim that the proposed platform is already implemented. The architecture, exercises, and acceptance gates are original project design. Exact supported dependency versions must be verified when deploying the product. External pages can change after this edition.

S01. Jenkins Pipeline

Existing pipeline concepts and their supported behavior.

Official reference

S02. Jenkins controller isolation

Separating build authority from the controller.

Official reference

S03. Git submodules overview

Gitlink identity and separate repository history.

Official reference

S04. Git submodule command

Registration, recursive checkout, and update behavior.

Official reference

S05. Go multi-module workspaces

Local development across multiple modules.

Official reference

S06. Go Modules Reference

Module identity, versions, and workspace resolution.

Official reference

S07. PostgreSQL SELECT

Row locking and queue-style SKIP LOCKED consumption.

Official reference

S08. Docker Engine security

Daemon authority and container isolation boundaries.

Official reference

S09. BuildKit upstream project

Builder capabilities and operational configuration.

Official reference

S10. Docker cache backends

Registry cache and backend-dependent support.

Official reference

S11. Docker build secrets

Temporary build-secret mounts.

Official reference

S12. Angular Signals

Reactive state primitives.

Official reference

S13. Angular security

Untrusted content, sanitization, and trust bypass risks.

Official reference

S14. HTML server-sent events

Event stream format and reconnection behavior.

Official reference

S15. GitHub webhook validation

Raw-byte HMAC signature verification.

Official reference

S16. GitHub webhook practices

Delivery identity, HTTPS, and acknowledgement practices.

Official reference

S17. GitHub secure-use reference

Untrusted source, privileged contexts, and self-hosted execution.

Official reference

S18. PostgreSQL transaction isolation

Snapshot semantics and transaction retries.

Official reference

S19. OpenID Connect for workloads

Federation and short-lived credentials.

Official reference

S20. PostgreSQL backup and restore

Backup strategies and recovery planning.

Official reference

S21. GitHub Pages custom workflows

Build artifacts, deployment permissions, and environment setup.

Official reference

S22. GitHub Pages publishing source

Selecting GitHub Actions as the publication source.

Official reference

S23. Creative Commons Attribution 4.0

Book-content reuse and attribution conditions.

Official reference

S24. MIT License

Permission notice for original code.

Official reference

The complete legal code for the book-content license is available from Creative Commons. The local licensing files state the scope of the grant and include the full MIT notice for original code.

Aleksandar Popovic · Text CC BY 4.0 · Original code MIT. Licensing and attribution