{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "id": "00bdbc24-f9ef-4819-b10c-5161124ff0a8",
      "key": "BARTIF",
      "title": "Artifact registry promotion controls",
      "field": "Cloud infrastructure",
      "summary": "Promote immutable application artifacts through environments with inspectable provenance.",
      "context": "A fictional application team deploys mutable image tags and cannot reliably identify the artifact running during an incident.",
      "stack": [
        "TypeScript",
        "OCI metadata",
        "JSON"
      ],
      "prerequisites": [
        "Author synthetic artifact manifests and a local registry double; do not pull or execute untrusted images."
      ],
      "developerValue": "Practice artifact identity, promotion policies, and release provenance.",
      "companyValue": "Provide reproducible deployments and a clear path to withdraw defective artifacts.",
      "delivery": "Deliver offline promotion checks and local registry-state rehearsals; perform no real deployment.",
      "phases": [
        {
          "id": "identify",
          "title": "Identify immutable artifacts",
          "goal": "Capture build identity and provenance."
        },
        {
          "id": "promote",
          "title": "Control promotion",
          "goal": "Validate artifact readiness and environment bindings."
        },
        {
          "id": "recover",
          "title": "Recover releases",
          "goal": "Handle withdrawal, retention, and rollback."
        }
      ],
      "tickets": [
        {
          "id": "afc5fb7f-1c66-49c4-8dcf-24065dace5a5",
          "key": "BARTIF-101",
          "title": "Resolve deployment references to immutable artifact digests",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "identify",
          "dependsOn": [],
          "scenario": "The same release tag points to different bytes across environments.",
          "acceptanceCriteria": [
            "Store the resolved digest with each deployment intent.",
            "Preserve the human-readable tag as metadata.",
            "Reject missing or ambiguous digest resolution."
          ],
          "implementationNotes": [
            "Synthetic registry manifests are sufficient."
          ],
          "verification": [
            "Resolve a stable release reference.",
            "Move its tag and detect changed identity."
          ],
          "deliverables": [
            "Artifact identity model."
          ],
          "rollout": "Introduce digest recording before enforcing immutable references.",
          "skills": [
            "Artifact integrity"
          ],
          "fieldMix": [
            {
              "field": "Developer tooling",
              "percentage": 40
            },
            {
              "field": "Security",
              "percentage": 40
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "fb479c12-9758-4023-a872-41832a45c1ab",
          "key": "BARTIF-102",
          "title": "Record build inputs without exposing build secrets",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "identify",
          "dependsOn": [
            "BARTIF-101"
          ],
          "scenario": "Provenance output includes all build environment variables.",
          "acceptanceCriteria": [
            "Record source revision, builder version, and declared inputs.",
            "Exclude secrets and workstation paths.",
            "Bind provenance to the exact artifact digest."
          ],
          "implementationNotes": [
            "Use allowlisted metadata rather than environment dumps."
          ],
          "verification": [
            "Verify a complete synthetic provenance record.",
            "Reject mismatched digest and detect seeded secret leakage."
          ],
          "deliverables": [
            "Provenance manifest."
          ],
          "rollout": "Block promotion when required provenance is missing.",
          "skills": [
            "Supply-chain integrity"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Developer tooling",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "6c73e81d-5b12-4648-bac1-fb23d9d85d85",
          "key": "BARTIF-103",
          "title": "Reject promotion of artifacts with unresolved policy findings",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "promote",
          "dependsOn": [
            "BARTIF-102"
          ],
          "scenario": "A failed scan is treated like a scan with no findings.",
          "acceptanceCriteria": [
            "Distinguish passed, failed, missing, and stale checks.",
            "Bind check results to artifact and policy versions.",
            "Keep unresolved required checks blocking."
          ],
          "implementationNotes": [
            "Fixture scan results are not real vulnerability evidence."
          ],
          "verification": [
            "Promote a fixture with complete checks.",
            "Reject unavailable or stale check results."
          ],
          "deliverables": [
            "Promotion policy evaluator."
          ],
          "rollout": "Run advisory comparisons before enforcement.",
          "skills": [
            "Policy design"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 50
            },
            {
              "field": "Developer tooling",
              "percentage": 30
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "9fd22540-dd63-4243-b1bf-bdfb6e58cdbe",
          "key": "BARTIF-104",
          "title": "Keep environment-specific settings outside immutable application bytes",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "promote",
          "dependsOn": [
            "BARTIF-101",
            "BARTIF-102"
          ],
          "scenario": "The team rebuilds the same release for staging and production, making tested bytes differ from deployed bytes.",
          "acceptanceCriteria": [
            "Use one application digest across modeled environments.",
            "Bind runtime configuration separately.",
            "Validate required configuration without embedding secrets."
          ],
          "implementationNotes": [
            "No actual cloud deployment is required."
          ],
          "verification": [
            "Promote the same digest through two synthetic environments.",
            "Reject a configuration missing a required setting."
          ],
          "deliverables": [
            "Artifact/configuration boundary."
          ],
          "rollout": "Adopt on one service; retain previous configuration versions for recovery.",
          "skills": [
            "Deployment design"
          ],
          "fieldMix": [
            {
              "field": "Platform engineering",
              "percentage": 50
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 50
            }
          ],
          "patterns": []
        },
        {
          "id": "e377cc12-827d-49ad-ad20-c53b94ab69a0",
          "key": "BARTIF-105",
          "title": "Bind a promotion decision to current environment state",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "promote",
          "dependsOn": [
            "BARTIF-103",
            "BARTIF-104"
          ],
          "scenario": "Two simultaneous promotion requests overwrite each other's intended release.",
          "acceptanceCriteria": [
            "Require expected environment revision.",
            "Record one accepted transition atomically.",
            "Reject stale decisions without changing active identity."
          ],
          "implementationNotes": [
            "Use a local state store and explicit transition methods."
          ],
          "verification": [
            "Promote against the current revision.",
            "Race two decisions and verify one conflict."
          ],
          "deliverables": [
            "Optimistic promotion workflow."
          ],
          "rollout": "Start with serialized local promotion; preserve every prior revision.",
          "skills": [
            "Concurrency",
            "State transitions"
          ],
          "fieldMix": [
            {
              "field": "Platform engineering",
              "percentage": 50
            },
            {
              "field": "Database engineering",
              "percentage": 30
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "0b36aede-a446-4955-b80f-e28a82bc3ea4",
          "key": "BARTIF-106",
          "title": "Handle registry unavailability without changing artifact identity",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "promote",
          "dependsOn": [
            "BARTIF-105"
          ],
          "scenario": "A failed digest lookup falls back to the latest cached tag.",
          "acceptanceCriteria": [
            "Use cached data only for the exact verified digest.",
            "Return unavailable for unresolved references.",
            "Bound fetch retries and response size."
          ],
          "implementationNotes": [
            "Do not substitute another release during failure."
          ],
          "verification": [
            "Reuse a verified digest manifest.",
            "Fail tag resolution during outage without selecting latest."
          ],
          "deliverables": [
            "Registry failure handling."
          ],
          "rollout": "Keep current release running in the scenario; retry promotion explicitly.",
          "skills": [
            "Resilience",
            "Integrity"
          ],
          "fieldMix": [
            {
              "field": "Cloud infrastructure",
              "percentage": 40
            },
            {
              "field": "Site reliability",
              "percentage": 40
            },
            {
              "field": "Security",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "4bca9e85-acd1-44bb-917b-fbb915e61bb0",
          "key": "BARTIF-107",
          "title": "Withdraw a defective artifact without deleting incident history",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "recover",
          "dependsOn": [
            "BARTIF-105"
          ],
          "scenario": "Deleting a bad image makes historical deployment records impossible to inspect.",
          "acceptanceCriteria": [
            "Mark the digest withdrawn with reason and actor.",
            "Block new promotion of withdrawn artifacts.",
            "Preserve manifests and prior deployment references."
          ],
          "implementationNotes": [
            "Withdrawal is append-only state, not evidence deletion."
          ],
          "verification": [
            "Withdraw a synthetic defective artifact.",
            "Reject new promotion while retaining historical reads."
          ],
          "deliverables": [
            "Artifact withdrawal workflow."
          ],
          "rollout": "Withdraw before cleanup; use a separate approved retention policy.",
          "skills": [
            "Lifecycle management"
          ],
          "fieldMix": [
            {
              "field": "Platform engineering",
              "percentage": 40
            },
            {
              "field": "Security",
              "percentage": 40
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "61ac0d80-9acb-46f3-9f5b-bad1a0e3cdd7",
          "key": "BARTIF-108",
          "title": "Protect rollback artifacts from registry retention cleanup",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "recover",
          "dependsOn": [
            "BARTIF-107"
          ],
          "scenario": "A cleanup job deletes the last known usable release.",
          "acceptanceCriteria": [
            "Retain artifacts referenced by active and rollback revisions.",
            "Evaluate cleanup from current authoritative references.",
            "Produce a dry-run deletion set."
          ],
          "implementationNotes": [
            "Use only local synthetic artifacts."
          ],
          "verification": [
            "Identify unreferenced eligible artifacts.",
            "Keep an older digest referenced by a rollback plan."
          ],
          "deliverables": [
            "Reference-aware retention policy."
          ],
          "rollout": "Run dry-run review before local deletion.",
          "skills": [
            "Retention",
            "Recovery"
          ],
          "fieldMix": [
            {
              "field": "Storage systems",
              "percentage": 40
            },
            {
              "field": "Site reliability",
              "percentage": 30
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "7fb9c773-690c-497b-aefa-9d0be1446f71",
          "key": "BARTIF-109",
          "title": "Assess rollback compatibility beyond selecting an older digest",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "recover",
          "dependsOn": [
            "BARTIF-104",
            "BARTIF-108"
          ],
          "scenario": "An older image starts successfully but cannot read data written by the new release.",
          "acceptanceCriteria": [
            "Bind rollback candidates to schema and configuration compatibility.",
            "Rehearse representative read/write behavior locally.",
            "Compare rollback with forward repair when compatibility fails."
          ],
          "implementationNotes": [
            "Artifact availability alone does not prove recoverability."
          ],
          "verification": [
            "Restore a compatible synthetic release.",
            "Reject an incompatible candidate despite its valid digest."
          ],
          "deliverables": [
            "Rollback compatibility assessment."
          ],
          "rollout": "Keep compatible artifacts and configuration together; choose forward repair when required.",
          "skills": [
            "Release recovery",
            "Compatibility"
          ],
          "fieldMix": [
            {
              "field": "Site reliability",
              "percentage": 40
            },
            {
              "field": "Database engineering",
              "percentage": 30
            },
            {
              "field": "Platform engineering",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "9122ab79-876a-4f54-b86f-115a1623ad88",
          "key": "BARTIF-110",
          "title": "Write an artifact incident lookup guide",
          "type": "CHORE",
          "priority": "LOW",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "recover",
          "dependsOn": [
            "BARTIF-109"
          ],
          "scenario": "On-call staff need to identify source, checks, and prior release from one deployed digest.",
          "acceptanceCriteria": [
            "Show lookup from environment revision to artifact.",
            "Link provenance and policy results by identity.",
            "Document withdrawn and missing-artifact behavior."
          ],
          "implementationNotes": [
            "Do not include registry credentials in examples."
          ],
          "verification": [
            "Trace one synthetic deployment to source inputs.",
            "Handle a withdrawn artifact without losing history."
          ],
          "deliverables": [
            "Artifact investigation guide."
          ],
          "rollout": "Store with promotion tooling and update when manifest schema changes.",
          "skills": [
            "Runbooks"
          ],
          "fieldMix": [
            {
              "field": "Site reliability",
              "percentage": 50
            },
            {
              "field": "Developer tooling",
              "percentage": 30
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 20
            }
          ],
          "patterns": []
        }
      ]
    }
  ]
}
