{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "id": "88f4d00d-8c24-464f-b798-acd1dc739870",
      "key": "BEGRESS",
      "title": "Restricted outbound fetch gateway",
      "field": "Networking",
      "summary": "Fetch approved external resources through a bounded provider-neutral network boundary.",
      "context": "A fictional content-import service accepts document URLs. The team needs explicit destination approval, redirect handling, and response limits before enabling imports.",
      "stack": [
        "TypeScript",
        "HTTP",
        "DNS fixtures"
      ],
      "prerequisites": [
        "Create a local HTTP destination simulator and DNS double with authorized address cases; contact no real external hosts."
      ],
      "developerValue": "Practice URL interpretation, network policy enforcement, and resource controls.",
      "companyValue": "Provide a reusable fetch boundary that makes destination authority and failure behavior inspectable.",
      "delivery": "Deliver a local gateway contract and authorized lab tests; no unrestricted internet proxy.",
      "phases": [
        {
          "id": "policy",
          "title": "Define destination policy",
          "goal": "Normalize URLs and bind approved destinations."
        },
        {
          "id": "fetch",
          "title": "Enforce bounded fetching",
          "goal": "Check resolution, redirects, and response limits."
        },
        {
          "id": "operate",
          "title": "Review policy lifecycle",
          "goal": "Handle policy changes, exceptions, and operational diagnostics."
        }
      ],
      "tickets": [
        {
          "id": "21671c49-1621-4fa1-a77f-3d94701896ea",
          "key": "BEGRESS-101",
          "title": "Define the approved destination contract for imports",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "policy",
          "dependsOn": [],
          "scenario": "The importer accepts any URL beginning with a trusted-looking string.",
          "acceptanceCriteria": [
            "Specify allowed scheme, hostname, port, and path scope.",
            "Represent exact hosts separately from subdomain rules.",
            "Reject unknown policy entries."
          ],
          "implementationNotes": [
            "Use fictional destinations mapped only inside the local simulator."
          ],
          "verification": [
            "Accept an exact approved destination.",
            "Reject a lookalike hostname and unapproved port."
          ],
          "deliverables": [
            "Destination policy schema."
          ],
          "rollout": "Default to deny until a reviewed policy exists.",
          "skills": [
            "Network policy"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Networking",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "c60c5ccb-7e30-4c95-935e-b66ecbb838e5",
          "key": "BEGRESS-102",
          "title": "Normalize import URLs without changing their authority",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "policy",
          "dependsOn": [
            "BEGRESS-101"
          ],
          "scenario": "User-info syntax and encoded separators confuse destination checks.",
          "acceptanceCriteria": [
            "Parse URLs with a single canonical parser.",
            "Reject credentials, ambiguous encodings, and unsupported schemes.",
            "Compare normalized authority against policy."
          ],
          "implementationNotes": [
            "Do not perform a request during validation."
          ],
          "verification": [
            "Normalize an approved URL deterministically.",
            "Reject user-info and authority-confusion fixtures."
          ],
          "deliverables": [
            "URL validation boundary."
          ],
          "rollout": "Run validation before queueing any fetch.",
          "skills": [
            "URL security"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 80
            },
            {
              "field": "Networking",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "e0ed4d00-674c-4aba-ba8a-ab54af466810",
          "key": "BEGRESS-103",
          "title": "Bind resolved addresses to the approved hostname policy",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "fetch",
          "dependsOn": [
            "BEGRESS-102"
          ],
          "scenario": "An approved hostname resolves to an address outside the permitted destination range.",
          "acceptanceCriteria": [
            "Validate every candidate address against policy.",
            "Reject private or special ranges unless explicitly authorized in the lab policy.",
            "Pin the validated resolution for the connection."
          ],
          "implementationNotes": [
            "The local test harness explicitly maps approved loopback fixtures; production defaults remain deny."
          ],
          "verification": [
            "Connect using an approved simulated resolution.",
            "Change resolution to an unapproved range and deny the request."
          ],
          "deliverables": [
            "Resolution-aware fetch policy."
          ],
          "rollout": "Fail closed on resolution ambiguity or unavailable policy.",
          "skills": [
            "DNS",
            "Egress control"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 50
            },
            {
              "field": "Security",
              "percentage": 50
            }
          ],
          "patterns": []
        },
        {
          "id": "2010a492-1443-4578-b04d-9eb02d59e0b4",
          "key": "BEGRESS-104",
          "title": "Revalidate every redirect before following it",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "fetch",
          "dependsOn": [
            "BEGRESS-103"
          ],
          "scenario": "An approved endpoint redirects the importer to an unapproved destination.",
          "acceptanceCriteria": [
            "Validate each redirect target independently.",
            "Bound redirect count.",
            "Prevent credentials or sensitive headers crossing origins."
          ],
          "implementationNotes": [
            "Do not inherit destination approval from the first URL."
          ],
          "verification": [
            "Follow an approved same-policy redirect.",
            "Reject an unapproved target and a redirect loop."
          ],
          "deliverables": [
            "Redirect policy checks."
          ],
          "rollout": "Disable redirects by default until the policy is configured.",
          "skills": [
            "HTTP",
            "Trust boundaries"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Networking",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "7b1bc163-40a9-423c-9a5b-e997f81d6b5d",
          "key": "BEGRESS-105",
          "title": "Enforce response byte limits during streaming",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "fetch",
          "dependsOn": [
            "BEGRESS-104"
          ],
          "scenario": "A response exceeds memory limits before its declared size can be checked.",
          "acceptanceCriteria": [
            "Enforce streamed compressed and expanded byte limits.",
            "Abort when the configured bound is exceeded.",
            "Reject inconsistent length metadata safely."
          ],
          "implementationNotes": [
            "Never buffer an unbounded response."
          ],
          "verification": [
            "Fetch a small valid synthetic document.",
            "Abort an oversized or expanding response and release resources."
          ],
          "deliverables": [
            "Bounded response reader."
          ],
          "rollout": "Start with conservative document limits and explicit too-large errors.",
          "skills": [
            "Streaming",
            "Resource bounds"
          ],
          "fieldMix": [
            {
              "field": "Performance engineering",
              "percentage": 40
            },
            {
              "field": "Security",
              "percentage": 30
            },
            {
              "field": "Networking",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "36933a4f-3293-4b58-ac4d-daa93e1d9481",
          "key": "BEGRESS-106",
          "title": "Constrain total fetch time across DNS and redirects",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "fetch",
          "dependsOn": [
            "BEGRESS-103",
            "BEGRESS-104",
            "BEGRESS-105"
          ],
          "scenario": "Each redirect gets a fresh timeout, extending one import indefinitely.",
          "acceptanceCriteria": [
            "Use one total deadline for all stages.",
            "Propagate cancellation to owned operations.",
            "Settle even when a destination double ignores cancellation."
          ],
          "implementationNotes": [
            "No automatic retry after the total budget expires."
          ],
          "verification": [
            "Complete a multi-stage fetch within budget.",
            "Exhaust the deadline during redirects and verify cleanup."
          ],
          "deliverables": [
            "End-to-end fetch deadline."
          ],
          "rollout": "Return a retryable unavailable result only under the documented import policy.",
          "skills": [
            "Cancellation",
            "Timeout design"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 50
            },
            {
              "field": "Site reliability",
              "percentage": 30
            },
            {
              "field": "Backend",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "a0f985ec-6af8-47f4-a770-311c0b07f1e8",
          "key": "BEGRESS-107",
          "title": "Separate content-type validation from document parser selection",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "fetch",
          "dependsOn": [
            "BEGRESS-105"
          ],
          "scenario": "The importer trusts a response header and sends arbitrary bytes to the wrong parser.",
          "acceptanceCriteria": [
            "Allowlist supported content types.",
            "Check bounded content signatures where applicable.",
            "Reject disagreement instead of guessing a parser."
          ],
          "implementationNotes": [
            "Parsing runs only through the authorized document-processing boundary."
          ],
          "verification": [
            "Accept a matching synthetic text document.",
            "Reject mislabeled binary content and unsupported types."
          ],
          "deliverables": [
            "Content validation contract."
          ],
          "rollout": "Keep unsupported imports rejected with clear user guidance.",
          "skills": [
            "Input validation"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 70
            },
            {
              "field": "Backend",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "c9e280b5-1b65-40c0-b948-1f446770b0b4",
          "key": "BEGRESS-108",
          "title": "Revoke destination approval for queued and cached imports",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "operate",
          "dependsOn": [
            "BEGRESS-106",
            "BEGRESS-107"
          ],
          "scenario": "An endpoint is removed from policy but previously queued work still fetches it.",
          "acceptanceCriteria": [
            "Recheck current policy before dispatch.",
            "Bind cached fetch authority to policy revision.",
            "Invalidate revoked destinations without serving stale private content."
          ],
          "implementationNotes": [
            "Cached bytes cannot authorize a new network operation."
          ],
          "verification": [
            "Dispatch an unchanged approved import.",
            "Revoke the host and deny queued work before connection."
          ],
          "deliverables": [
            "Policy revocation handling."
          ],
          "rollout": "Pause affected work and preserve safe operation metadata.",
          "skills": [
            "Authorization",
            "Lifecycle"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 70
            },
            {
              "field": "Networking",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "a13dfcf0-a578-4e24-abb5-8dcdf5682757",
          "key": "BEGRESS-109",
          "title": "Assess proxy deployment versus embedded fetch enforcement",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "operate",
          "dependsOn": [
            "BEGRESS-103",
            "BEGRESS-108"
          ],
          "scenario": "The team must decide whether every service implements egress checks or shares a constrained gateway.",
          "acceptanceCriteria": [
            "Compare enforcement consistency, latency, failure domain, and operations burden.",
            "Model bypass risks and explicit provider boundaries.",
            "Choose the smallest design satisfying the scenario."
          ],
          "implementationNotes": [
            "Do not add microservices without a demonstrated need; a local module may be sufficient."
          ],
          "verification": [
            "Trace an authorized import through the chosen boundary.",
            "Show how direct unapproved network access is prevented in the model."
          ],
          "deliverables": [
            "Egress architecture decision record."
          ],
          "rollout": "Keep the gateway unavailable until enforcement and bypass assumptions are verified.",
          "skills": [
            "Network architecture",
            "Tradeoffs"
          ],
          "fieldMix": [
            {
              "field": "System design",
              "percentage": 50
            },
            {
              "field": "Networking",
              "percentage": 30
            },
            {
              "field": "Security",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "32fe8fc8-36da-4b08-b6c6-9c58ba6104c4",
          "key": "BEGRESS-110",
          "title": "Write a destination-exception review with expiry",
          "type": "CHORE",
          "priority": "LOW",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "operate",
          "dependsOn": [
            "BEGRESS-109"
          ],
          "scenario": "A temporary import source should not become a permanent wildcard allowlist entry.",
          "acceptanceCriteria": [
            "Require exact destination, owner, reason, and expiry.",
            "Document required negative checks.",
            "Preserve exception history after removal."
          ],
          "implementationNotes": [
            "Exceptions cannot disable response or time bounds."
          ],
          "verification": [
            "Approve a narrow synthetic exception.",
            "Reject expired and wildcard-wide exceptions."
          ],
          "deliverables": [
            "Egress exception guide."
          ],
          "rollout": "Review exceptions before policy publication and remove expired authority.",
          "skills": [
            "Policy governance"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 70
            },
            {
              "field": "Networking",
              "percentage": 30
            }
          ],
          "patterns": []
        }
      ]
    }
  ]
}
