{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "id": "97317aee-e1c4-41f7-bcde-f99b09237912",
      "key": "AIMAGE",
      "title": "Harden a service image build and promotion workflow",
      "field": "Platform engineering",
      "summary": "Produce reproducible service images and promote exact artifacts with inspectable provenance.",
      "context": "A fictional reporting API is rebuilt separately for staging and production. Different dependency resolutions and mutable tags make incident rollback unreliable.",
      "stack": [
        "OCI image tools",
        "TypeScript",
        "CI"
      ],
      "prerequisites": [
        "Create a tiny local HTTP service and nonprivileged image build.",
        "Use synthetic registries or provider fixtures; no production deployment."
      ],
      "developerValue": "Practice artifact identity, least privilege and reproducible delivery.",
      "companyValue": "Review whether deployed bytes can be traced and rolled back reliably.",
      "delivery": "Ten scoped tickets across three phases. Build a synthetic local service or select a ticket after recreating its prerequisites; estimates exclude setup.",
      "phases": [
        {
          "id": "build",
          "title": "Constrain image construction",
          "goal": "Pin inputs and limit build context."
        },
        {
          "id": "promote",
          "title": "Promote exact artifacts",
          "goal": "Validate artifacts and preserve provenance."
        },
        {
          "id": "recover",
          "title": "Recover artifact failures",
          "goal": "Retain usable revisions and rehearse rollback."
        }
      ],
      "tickets": [
        {
          "id": "0daa63a2-2047-4d10-b97c-e19a35e1747f",
          "key": "AIMAGE-101",
          "title": "Exclude local credentials and bulky artifacts from the image context",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 75,
          "phaseId": "build",
          "dependsOn": [],
          "scenario": "A developer notices an environment file and test recordings copied into the service image.",
          "acceptanceCriteria": [
            "Allow only required source and build inputs into context.",
            "Exclude environment files, VCS metadata and generated recordings.",
            "Add a safe inspection command that lists included paths."
          ],
          "implementationNotes": [
            "Create fake secrets for tests; never scan or print real secret values."
          ],
          "verification": [
            "Build a minimal synthetic service context.",
            "Add a fake credential file and verify it is absent from context and image."
          ],
          "deliverables": [
            "Context allowlist and image-content check"
          ],
          "rollout": "Apply before the next image build; discard affected disposable images.",
          "skills": [
            "Container builds",
            "Secrets handling"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 50
            },
            {
              "field": "Platform engineering",
              "percentage": 30
            },
            {
              "field": "Developer tooling",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "7360f402-6854-494e-8fc8-549bfa128991",
          "key": "AIMAGE-102",
          "title": "Pin service build inputs to immutable identities",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "build",
          "dependsOn": [
            "AIMAGE-101"
          ],
          "scenario": "A rebuild of an old commit picks up a newer base image and no longer reproduces the original runtime.",
          "acceptanceCriteria": [
            "Pin the base image digest and dependency lockfile.",
            "Record compiler and build-tool versions.",
            "Fail the build when frozen dependency resolution changes the lockfile."
          ],
          "implementationNotes": [
            "Document the update procedure rather than permanently freezing vulnerabilities."
          ],
          "verification": [
            "Build twice from identical named inputs and compare artifact metadata.",
            "Change a pinned input and require a new provenance record."
          ],
          "deliverables": [
            "Pinned build definition"
          ],
          "rollout": "Introduce pinned builds for new artifacts; retain old digest references for rollback.",
          "skills": [
            "Reproducibility",
            "Dependency management"
          ],
          "fieldMix": [
            {
              "field": "Platform engineering",
              "percentage": 70
            },
            {
              "field": "Developer tooling",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "0c0c6fab-6b30-4218-bd67-c52281681287",
          "key": "AIMAGE-103",
          "title": "Run the service image as an unprivileged user with a read-only root",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "build",
          "dependsOn": [
            "AIMAGE-101",
            "AIMAGE-102"
          ],
          "scenario": "The API image starts as root and writes temporary report files into the application directory.",
          "acceptanceCriteria": [
            "Use a non-root runtime user.",
            "Keep the base filesystem read-only with an explicit temporary directory.",
            "Reject startup when required writable storage is unavailable."
          ],
          "implementationNotes": [
            "No privileged mode, host mounts, host networking or container-engine socket."
          ],
          "verification": [
            "Serve a request under the restricted runtime configuration.",
            "Attempt a write to the application directory and verify denial."
          ],
          "deliverables": [
            "Restricted runtime definition and filesystem probe"
          ],
          "rollout": "Canary the restricted image locally; stop rollout if required writes lack an explicit temporary path.",
          "skills": [
            "Least privilege",
            "Container hardening"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Platform engineering",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "11d2cd84-cb79-472f-9d45-6389f1d0dd89",
          "key": "AIMAGE-104",
          "title": "Record image provenance without embedding build credentials",
          "type": "STORY",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 180,
          "phaseId": "promote",
          "dependsOn": [
            "AIMAGE-102",
            "AIMAGE-103"
          ],
          "scenario": "Operations can see a tag but cannot trace it to source revision, dependency lock hash or build run.",
          "acceptanceCriteria": [
            "Record source revision, input hashes and final image digest.",
            "Associate provenance with the exact artifact digest.",
            "Exclude environment values and registry tokens."
          ],
          "implementationNotes": [
            "Use a local provenance document for this exercise."
          ],
          "verification": [
            "Resolve a built digest to its source and lockfile hashes.",
            "Alter provenance digest and reject the mismatch."
          ],
          "deliverables": [
            "Artifact provenance manifest and verification command"
          ],
          "rollout": "Attach provenance to new builds; refuse promotion when it cannot be verified.",
          "skills": [
            "Supply chain",
            "Provenance"
          ],
          "fieldMix": [
            {
              "field": "Platform engineering",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "1c57c2a6-183e-4c2e-b0ef-34b66486e5b4",
          "key": "AIMAGE-105",
          "title": "Promote the tested digest instead of rebuilding for each environment",
          "type": "STORY",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 210,
          "phaseId": "promote",
          "dependsOn": [
            "AIMAGE-104"
          ],
          "scenario": "The staging build passes, but production rebuilds the same commit with different transitive dependencies.",
          "acceptanceCriteria": [
            "Promotion selects the exact tested digest.",
            "Separate runtime configuration from artifact construction.",
            "Reject a tag that resolves to a different digest at promotion."
          ],
          "implementationNotes": [
            "Model registries through a testable provider interface."
          ],
          "verification": [
            "Promote a tested synthetic digest through two environments.",
            "Move a mutable tag and verify promotion rejects the changed artifact."
          ],
          "deliverables": [
            "Digest promotion command and tag-race regression"
          ],
          "rollout": "Canary promotion metadata; restore the previously selected digest if validation fails.",
          "skills": [
            "Artifact promotion",
            "Identity checks"
          ],
          "fieldMix": [
            {
              "field": "Platform engineering",
              "percentage": 100
            }
          ],
          "patterns": []
        },
        {
          "id": "666182ae-8ae2-4236-a224-5c6ad0f163fa",
          "key": "AIMAGE-106",
          "title": "Stop promotion when required security scan results are missing",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "promote",
          "dependsOn": [
            "AIMAGE-104",
            "AIMAGE-105"
          ],
          "scenario": "A scan service times out and the build pipeline treats absence of findings as a clean result.",
          "acceptanceCriteria": [
            "Represent passed, failed and unavailable scan states distinctly.",
            "Require scan policy and artifact digest to match.",
            "Unavailable required results block promotion with a retry path."
          ],
          "implementationNotes": [
            "Use synthetic scan responses; do not claim current vulnerability coverage."
          ],
          "verification": [
            "Promote with matching passed policy results.",
            "Timeout or return a different digest and verify promotion remains blocked."
          ],
          "deliverables": [
            "Scan-result gate and unavailable-state tests"
          ],
          "rollout": "Run the gate before environment selection; retry scans without rebuilding the artifact.",
          "skills": [
            "Fail-closed gates",
            "Supply-chain checks"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Platform engineering",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "0e18f148-54a6-48ec-80fc-a21f8aead519",
          "key": "AIMAGE-107",
          "title": "Make artifact promotion idempotent across lost CI responses",
          "type": "BUG",
          "priority": "MEDIUM",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "promote",
          "dependsOn": [
            "AIMAGE-105",
            "AIMAGE-106"
          ],
          "scenario": "A CI runner loses the promotion response and retries, creating competing rollout records for one digest.",
          "acceptanceCriteria": [
            "Use a stable promotion key bound to environment and digest.",
            "Retries resolve one durable promotion record.",
            "Changed digest under the same key returns conflict."
          ],
          "implementationNotes": [
            "Persist selection and audit metadata atomically."
          ],
          "verification": [
            "Drop a response after commit and retry the same selection.",
            "Reuse a promotion key for another digest and retain the original selection."
          ],
          "deliverables": [
            "Idempotent promotion command"
          ],
          "rollout": "Enable for synthetic environments; pause conflicting promotions and retain their audit records.",
          "skills": [
            "Idempotency",
            "Transactions"
          ],
          "fieldMix": [
            {
              "field": "Platform engineering",
              "percentage": 60
            },
            {
              "field": "Database engineering",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "07dbd5ab-f596-4a10-82ec-3e5baf53bc4f",
          "key": "AIMAGE-108",
          "title": "Retain rollback images without deleting active environment digests",
          "type": "CHORE",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "recover",
          "dependsOn": [
            "AIMAGE-105",
            "AIMAGE-107"
          ],
          "scenario": "Registry cleanup removes an image still running in a quiet environment because its tag is old.",
          "acceptanceCriteria": [
            "Retention protects every active and explicitly retained rollback digest.",
            "Compute deletion candidates before executing cleanup.",
            "Recheck references immediately before removal."
          ],
          "implementationNotes": [
            "Use exact digest references rather than tag age alone."
          ],
          "verification": [
            "Expire an unreferenced synthetic image.",
            "Add an active reference after planning and verify deletion is skipped."
          ],
          "deliverables": [
            "Digest retention planner and race test"
          ],
          "rollout": "Dry-run retention first; stop cleanup if environment inventory is unavailable.",
          "skills": [
            "Retention",
            "Resource safety"
          ],
          "fieldMix": [
            {
              "field": "Platform engineering",
              "percentage": 60
            },
            {
              "field": "Storage systems",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "f00f704e-7f88-4376-aa4d-5a591ac207e9",
          "key": "AIMAGE-109",
          "title": "Rehearse rollback when the new image cannot read existing data",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "EXPERT",
          "estimateMinutes": 360,
          "phaseId": "recover",
          "dependsOn": [
            "AIMAGE-107",
            "AIMAGE-108"
          ],
          "scenario": "A new runtime starts successfully but fails on records created by the previous release.",
          "acceptanceCriteria": [
            "Declare compatibility expectations for stored data.",
            "Route back to the retained old digest without rebuilding.",
            "Identify any irreversible schema step that blocks binary rollback."
          ],
          "implementationNotes": [
            "Use a synthetic compatibility fixture and local runtime only."
          ],
          "verification": [
            "Roll out a compatible image and restore its predecessor.",
            "Trigger a schema incompatibility and stop automatic rollback with an explicit recovery decision."
          ],
          "deliverables": [
            "Rollback drill and compatibility matrix"
          ],
          "rollout": "Run the drill before promotion; block releases without a viable declared recovery path.",
          "skills": [
            "Release engineering",
            "Compatibility"
          ],
          "fieldMix": [
            {
              "field": "Platform engineering",
              "percentage": 60
            },
            {
              "field": "Database engineering",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "f416ee2f-ba7f-4d7d-a1f7-54f7de74409d",
          "key": "AIMAGE-110",
          "title": "Publish a release inventory that resolves environments to exact bytes",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "recover",
          "dependsOn": [
            "AIMAGE-104",
            "AIMAGE-108",
            "AIMAGE-109"
          ],
          "scenario": "Incident responders receive three different tag names for what appears to be the same release.",
          "acceptanceCriteria": [
            "List environment, selected digest and provenance identity.",
            "Show requested selection separately from observed running digest.",
            "Mark missing observations as unknown."
          ],
          "implementationNotes": [
            "Omit registry credentials and private build output."
          ],
          "verification": [
            "Resolve two aliases to the same artifact digest.",
            "Remove runtime observation and display unknown rather than deployed."
          ],
          "deliverables": [
            "Release inventory projection"
          ],
          "rollout": "Publish read-only inventory first; repair stale observations without changing selections.",
          "skills": [
            "Operational visibility",
            "Artifact identity"
          ],
          "fieldMix": [
            {
              "field": "Platform engineering",
              "percentage": 60
            },
            {
              "field": "Site reliability",
              "percentage": 40
            }
          ],
          "patterns": []
        }
      ]
    }
  ]
}
