0005: The content hub is a signed static folder of our own
Date: 2026-10-04
Context¶
Before Steam, Fusion needs a place where players find routers, scenarios and addons (VISION.md §7.6) that doesn't depend on Steam (§2 rule 1). BUILD.md 6.3 named two candidates: mod.io (a hosted mod service with an API, for games on and off Steam) and a small hub of our own (a signed index file listing packages, with the files on a CDN or GitHub Releases).
The risk to design against is being taken down (§2 rule 1): a host acting on a notice against Fusion as a whole, or against one router. Other constraints: routers are always free (§2 rule 4), no money to spend without the user, and the user hasn't chosen where Fusion is hosted (§15).
Decision¶
A hub of our own, as a static folder: index.toml and feed.toml, each with an official signature, and packages/<id>-<version>.fusion. Any static host serves it: a website, GitHub Pages, a CDN, a LAN share, a USB stick. Fusion reads it as one more content source (fusion_core::hub).
- Integrity doesn't depend on the host. The index is signed by an official key; each entry pins the package's sha256, size and signer; the package carries its author's signature over its files. A host (or anyone in between) can withhold files, never change them unnoticed.
- Moving after a takedown is copying a folder and pointing players' settings (or the next release's default) at the new address. Several hubs can be listed at once.
- The kill switch is the signed
feed.tomlnext to the index (ADR-free detail indocs/trust.md): it travels with the hub, and players keep the newest copy they've seen, so it still applies when the hub is unreachable. - Publishing is
fusion-cli hub add HUB PACKAGE --key OFFICIAL.keyon the operator's PC: it refuses unsigned packages, a second author taking over an id, and a changed file under an old version number; older versions stay for rollback. - Proposed changes travel as signed
.fusion-proposalfiles (fusion_core::proposal) sent to the router's author; a hub can list them later.
Rejected¶
- mod.io as the only hub: hosted and convenient, but its rules for tools that inject into other games are a takedown risk we don't control, the whole catalog would leave with one decision, and its API ties every client to one service. It can still be added later as one more
Source, like the Steam Workshop (M8). - A server with accounts and uploads now: more to run and secure before there are users; the static folder needs nothing but a host.
Consequences¶
- Uploading is manual for v0 (the operator adds packages); a web form or a CI job can call the same
hub addlater. - Discovery is a list, not search or ratings; fine for the first release's size.
- The default hub address is empty until the user picks a host (
settings::DEFAULT_HUB).