Compile a minimal preview configuration
Preview inherits production-like integrations and tries to send fixture events to undeclared external endpoints.
- Focused work estimate
- 1h 30m + prerequisites
- Priority in the scenario
- Medium
- Engineering practice
- Environment isolation · Configuration policy · Security
Estimated field mix
- DevOps60%
- Security40%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional product team creates local preview environments for pull requests. Names collide, fixtures copy more data than needed, failed provisioning leaks resources, and merged changes leave previews running. Build an infrastructure simulator with fake DNS, storage, and deployment providers; no cloud account or live domain is supplied.
Setup prerequisites
- Resource graphs
- Idempotency
- Tenant isolation
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
Acceptance criteria
- Preview configuration selects only fake or explicitly allowed providers
- Network policy defaults to deny and lists required local dependencies
- Secrets are references to preview-scoped fixtures
Implementation constraints
- No production credential, customer data, or public callback is permitted.
Verification to include
- Compile a preview using only declared fake providers.
- Reference an external endpoint and a production-like secret scope, then block compilation.
Deliverables
- Preview configuration policy and denial tests
Rollout and recovery
Require policy compilation before any resource plan.
Value of the work
For the engineer: Practice ephemeral environment lifecycle, scoped configuration, cleanup, quotas, and provider reconciliation.
For the team: Review changes in isolated representative environments while controlling leakage, resource growth, and abandoned infrastructure.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.