SteonMod
View as Markdown

0005: The content hub is a signed static folder of our own

Date: 2026-10-04

Context

Before Steam, Fusion needs a place where players find routers, scenarios and addons (VISION.md §7.6) that doesn't depend on Steam (§2 rule 1). BUILD.md 6.3 named two candidates: mod.io (a hosted mod service with an API, for games on and off Steam) and a small hub of our own (a signed index file listing packages, with the files on a CDN or GitHub Releases).

The risk to design against is being taken down (§2 rule 1): a host acting on a notice against Fusion as a whole, or against one router. Other constraints: routers are always free (§2 rule 4), no money to spend without the user, and the user hasn't chosen where Fusion is hosted (§15).

Decision

A hub of our own, as a static folder: index.toml and feed.toml, each with an official signature, and packages/<id>-<version>.fusion. Any static host serves it: a website, GitHub Pages, a CDN, a LAN share, a USB stick. Fusion reads it as one more content source (fusion_core::hub).

  • Integrity doesn't depend on the host. The index is signed by an official key; each entry pins the package's sha256, size and signer; the package carries its author's signature over its files. A host (or anyone in between) can withhold files, never change them unnoticed.
  • Moving after a takedown is copying a folder and pointing players' settings (or the next release's default) at the new address. Several hubs can be listed at once.
  • The kill switch is the signed feed.toml next to the index (ADR-free detail in docs/trust.md): it travels with the hub, and players keep the newest copy they've seen, so it still applies when the hub is unreachable.
  • Publishing is fusion-cli hub add HUB PACKAGE --key OFFICIAL.key on the operator's PC: it refuses unsigned packages, a second author taking over an id, and a changed file under an old version number; older versions stay for rollback.
  • Proposed changes travel as signed .fusion-proposal files (fusion_core::proposal) sent to the router's author; a hub can list them later.

Rejected

  • mod.io as the only hub: hosted and convenient, but its rules for tools that inject into other games are a takedown risk we don't control, the whole catalog would leave with one decision, and its API ties every client to one service. It can still be added later as one more Source, like the Steam Workshop (M8).
  • A server with accounts and uploads now: more to run and secure before there are users; the static folder needs nothing but a host.

Consequences

  • Uploading is manual for v0 (the operator adds packages); a web form or a CI job can call the same hub add later.
  • Discovery is a list, not search or ratings; fine for the first release's size.
  • The default hub address is empty until the user picks a host (settings::DEFAULT_HUB).