- Replace the example issuer allowlist in
config/ledger.example.yml. - Set
LEDGER_SEC_USER_AGENTto a monitored organizational contact. - Decide whether local DuckDB is sufficient or BigQuery is required.
- Rename Terraform resources only through variables or
locals; do not hard-code personal names. - Define retention, data classification, and access policies before storing filing documents or derived text.
The reusable pattern is:
allowlisted entities -> fixture/live client -> raw preservation -> normalization -> dbt contracts -> governed marts
To adapt it:
- implement another client with the same fetch boundary
- replace
normalize_companyfactswith domain-specific normalization - preserve fixture parity
- keep stable raw and normalized contracts
- update dbt models and tests at the same grain
Never commit:
- cloud project IDs tied to private environments
- service-account keys
- personal email addresses or phone numbers
- API keys, cookies, tokens, or secrets
- production query results or unredacted logs
Use workload identity for CI and Secret Manager for runtime credentials.