Rehearse artifact compromise from block to recovery
The response plan says rotate and rebuild but does not identify affected channels, compatible rollback artifacts, or how clients learn the block.
- Focused work estimate
- 2h 30m + prerequisites
- Priority in the scenario
- Medium
- Engineering practice
- Incident response · Supply-chain recovery · Runbooks
Estimated field mix
- DevOps70%
- Site reliability30%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional command-line product publishes local package archives. Builds contain timestamps, checksums are copied without provenance, and cleanup can delete the only rollback artifact. Use generated source trees, ephemeral development signing keys, and local object storage; no public registry or production key is supplied.
Setup prerequisites
- Content hashing
- Archive formats
- Release metadata
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
- DART-101 · Make archive bytes reproducible from the same source manifest
- DART-102 · Generate a dependency inventory from resolved inputs
- DART-103 · Bind provenance to source, builder, and exact artifact
- DART-104 · Keep signing keys outside the build workspace
- DART-105 · Promote only artifacts whose evidence set reconciles
- DART-107 · Revoke a compromised signing identity without deleting history
- DART-106 · Prevent a mutable channel from changing an approved artifact
- DART-108 · Retain rollback artifacts while bounding storage growth
- DART-109 · Recover publication after object storage acknowledges late
Acceptance criteria
- Runbook traces key, artifact, channel, environment, and consumer relationships
- Rehearsal blocks promotion and selects a verified compatible artifact
- Recovery publishes a new identity without rewriting compromised history
Implementation constraints
- The scenario uses fictional artifacts and ephemeral keys only.
Verification to include
- Complete a synthetic compromise and restore a safe channel.
- Remove the expected rollback artifact and follow the documented blocked path.
Deliverables
- Artifact incident runbook and tabletop transcript
Rollout and recovery
Review findings before treating the workflow as ready for an external registry.
Value of the work
For the engineer: Practice reproducible artifacts, provenance validation, signing-key isolation and retention safety.
For the team: Review a supply path that can trace, verify, retain, and revoke artifacts without relying on mutable names.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.