{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "id": "50db3076-1599-4748-a194-24385125bd18",
      "key": "BIDENT",
      "title": "Workload identity credential rotation",
      "field": "Cloud infrastructure",
      "summary": "Replace static service credentials with bounded workload identity and tested rotation.",
      "context": "A fictional export worker shares a long-lived object-store credential across environments. The team needs a provider-neutral identity boundary with safe expiry and revocation.",
      "stack": [
        "TypeScript",
        "JWT",
        "HTTP"
      ],
      "prerequisites": [
        "Create a local identity issuer and object-store double using generated test-only keys; no cloud account or production secret."
      ],
      "developerValue": "Practice workload identity, audience restrictions, and credential lifecycle failures.",
      "companyValue": "Produce a migration path that narrows credential scope and makes revocation observable.",
      "delivery": "Deliver local identity contracts and rotation rehearsals; deploy no live trust policy.",
      "phases": [
        {
          "id": "trust",
          "title": "Define trust scope",
          "goal": "Bind identities to workloads and resources."
        },
        {
          "id": "issue",
          "title": "Issue bounded credentials",
          "goal": "Validate tokens, caching, and provider failures."
        },
        {
          "id": "rotate",
          "title": "Rehearse lifecycle changes",
          "goal": "Test rotation, revocation, and migration recovery."
        }
      ],
      "tickets": [
        {
          "id": "c7f2bad1-0743-456d-a2c5-4e82aaac6cb5",
          "key": "BIDENT-101",
          "title": "Inventory the export worker's required storage operations",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "trust",
          "dependsOn": [],
          "scenario": "The worker credential permits listing and deleting unrelated storage objects.",
          "acceptanceCriteria": [
            "List operations required for one export lifecycle.",
            "Separate read, write, and cleanup authority.",
            "Identify unnecessary permissions."
          ],
          "implementationNotes": [
            "Use synthetic object namespaces."
          ],
          "verification": [
            "Complete an export with the proposed operation list.",
            "Deny an unrelated bucket-list request."
          ],
          "deliverables": [
            "Least-privilege operation matrix."
          ],
          "rollout": "Review scope before issuing replacement credentials.",
          "skills": [
            "Least privilege"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 80
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "af570982-1105-44dd-a380-218d881572fc",
          "key": "BIDENT-102",
          "title": "Bind workload assertions to issuer, audience, and environment",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "trust",
          "dependsOn": [
            "BIDENT-101"
          ],
          "scenario": "A staging assertion is accepted by the production-class storage adapter.",
          "acceptanceCriteria": [
            "Validate issuer and exact audience.",
            "Bind workload and environment identity.",
            "Reject unknown signing keys and algorithms."
          ],
          "implementationNotes": [
            "Use generated local test keys only."
          ],
          "verification": [
            "Accept a matching assertion.",
            "Reject wrong audience, environment, and algorithm fixtures."
          ],
          "deliverables": [
            "Assertion verifier."
          ],
          "rollout": "Fail closed on unresolved trust configuration.",
          "skills": [
            "Identity",
            "JWT validation"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 80
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "4f8c4481-3463-4cfe-acd5-2f46b99b7b8e",
          "key": "BIDENT-103",
          "title": "Issue short-lived storage grants with exact resource scope",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "issue",
          "dependsOn": [
            "BIDENT-102"
          ],
          "scenario": "A workload token grants access to every export instead of one operation.",
          "acceptanceCriteria": [
            "Bind grant to resource and allowed operation.",
            "Enforce expiry and unique grant identity.",
            "Prevent the caller from widening scope."
          ],
          "implementationNotes": [
            "Grant fields derive from authorized server state."
          ],
          "verification": [
            "Write the intended synthetic export.",
            "Reject a different resource or operation under the same grant."
          ],
          "deliverables": [
            "Scoped grant issuer."
          ],
          "rollout": "Start with one export path; retain no broad fallback credential.",
          "skills": [
            "Capability security"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 70
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "71a2e5c5-3277-4e99-8d55-70bb8745db26",
          "key": "BIDENT-104",
          "title": "Refresh credentials before expiry without creating a refresh storm",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "issue",
          "dependsOn": [
            "BIDENT-103"
          ],
          "scenario": "Every concurrent request refreshes the same expiring credential.",
          "acceptanceCriteria": [
            "Coalesce equivalent in-flight refreshes.",
            "Refresh within a declared bounded window.",
            "Avoid caching failed or mismatched grants."
          ],
          "implementationNotes": [
            "Cache keys include workload, resource scope, and audience."
          ],
          "verification": [
            "Share one refresh across concurrent requests.",
            "Reject cross-scope cache reuse and retry a failed refresh safely."
          ],
          "deliverables": [
            "Credential cache."
          ],
          "rollout": "Use short cache lifetimes; clear affected entries on validation failure.",
          "skills": [
            "Caching",
            "Concurrency"
          ],
          "fieldMix": [
            {
              "field": "Performance engineering",
              "percentage": 50
            },
            {
              "field": "Security",
              "percentage": 30
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "b6c477ce-4f97-4b08-8632-c8db10b3a388",
          "key": "BIDENT-105",
          "title": "Keep clock skew from extending grant lifetime indefinitely",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 120,
          "phaseId": "issue",
          "dependsOn": [
            "BIDENT-102",
            "BIDENT-104"
          ],
          "scenario": "A large token leeway makes expired credentials valid far longer than intended.",
          "acceptanceCriteria": [
            "Bound allowed skew explicitly.",
            "Reject impossible issue and expiry ordering.",
            "Report clock-related failures without token contents."
          ],
          "implementationNotes": [
            "Use an injected clock for deterministic checks."
          ],
          "verification": [
            "Accept a token inside the declared skew window.",
            "Reject expired and future-issued tokens beyond the bound."
          ],
          "deliverables": [
            "Expiry boundary tests."
          ],
          "rollout": "Deploy with monitored clock assumptions; stop issuance if time authority is unavailable.",
          "skills": [
            "Time validation"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 80
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "dae1fb6d-0ebc-42c8-a091-8036f26cd552",
          "key": "BIDENT-106",
          "title": "Prevent identity-provider outages from selecting static credentials",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "issue",
          "dependsOn": [
            "BIDENT-104",
            "BIDENT-105"
          ],
          "scenario": "The adapter silently falls back to an old environment secret when token refresh fails.",
          "acceptanceCriteria": [
            "Remove implicit static fallback.",
            "Return a bounded unavailable state.",
            "Allow only already-valid scoped grants until expiry."
          ],
          "implementationNotes": [
            "Never log credentials in failure diagnostics."
          ],
          "verification": [
            "Continue with a valid unexpired grant.",
            "Fail closed after expiry during issuer outage."
          ],
          "deliverables": [
            "Provider failure behavior."
          ],
          "rollout": "Disable issuance cleanly on outage; restore only after trust validation succeeds.",
          "skills": [
            "Fail-closed design"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 50
            },
            {
              "field": "Site reliability",
              "percentage": 30
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "5a0aa8bc-d126-4688-b148-cc9e8fb8cdd9",
          "key": "BIDENT-107",
          "title": "Rotate signing keys with a bounded overlap window",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 210,
          "phaseId": "rotate",
          "dependsOn": [
            "BIDENT-105",
            "BIDENT-106"
          ],
          "scenario": "Immediate key replacement breaks in-flight exports while indefinite overlap preserves old authority.",
          "acceptanceCriteria": [
            "Publish new verification key before issuance switches.",
            "Bound old-key acceptance by policy and token expiry.",
            "Reject retired keys after the overlap."
          ],
          "implementationNotes": [
            "Private keys remain test-only runtime inputs."
          ],
          "verification": [
            "Complete an in-flight old-key export during overlap.",
            "Reject an old-key token after retirement."
          ],
          "deliverables": [
            "Key rotation rehearsal."
          ],
          "rollout": "Retain the previous public verifier only for the declared overlap.",
          "skills": [
            "Key lifecycle"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "88af240a-4f1c-4a52-a7f6-9965d2c1e668",
          "key": "BIDENT-108",
          "title": "Revoke one workload without disrupting unrelated exporters",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "rotate",
          "dependsOn": [
            "BIDENT-107"
          ],
          "scenario": "A broad emergency revocation stops every export worker.",
          "acceptanceCriteria": [
            "Scope revocation to workload identity and grant class.",
            "Check revocation before accepting cached authority.",
            "Preserve unrelated authorized workloads."
          ],
          "implementationNotes": [
            "Privileged revocations require append-only audit metadata."
          ],
          "verification": [
            "Revoke one synthetic worker.",
            "Verify its cached grant fails while another worker succeeds."
          ],
          "deliverables": [
            "Scoped revocation behavior."
          ],
          "rollout": "Test revocation before replacing the static credential path.",
          "skills": [
            "Revocation",
            "Authorization"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 80
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "c7952c01-6962-42cc-b58f-4aa985ed344e",
          "key": "BIDENT-109",
          "title": "Design the static-to-workload identity cutover",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "rotate",
          "dependsOn": [
            "BIDENT-106",
            "BIDENT-108"
          ],
          "scenario": "The team must migrate without leaving a forgotten permanent credential active.",
          "acceptanceCriteria": [
            "Inventory callers and staged cutover order.",
            "Define proof that no caller requires the old credential.",
            "Compare rollback availability against retained-secret risk."
          ],
          "implementationNotes": [
            "Do not restore broad credentials automatically on failure."
          ],
          "verification": [
            "Migrate two synthetic callers and revoke the old key.",
            "Detect a forgotten caller before declaring the migration complete."
          ],
          "deliverables": [
            "Identity migration decision record."
          ],
          "rollout": "Use a reviewed emergency path; retire the static key after verified caller migration.",
          "skills": [
            "Migration design",
            "Security tradeoffs"
          ],
          "fieldMix": [
            {
              "field": "System design",
              "percentage": 40
            },
            {
              "field": "Security",
              "percentage": 40
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "221f8b0f-4f32-44a2-a702-bf8cfb374847",
          "key": "BIDENT-110",
          "title": "Write credential-failure diagnostics without secret exposure",
          "type": "CHORE",
          "priority": "LOW",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "rotate",
          "dependsOn": [
            "BIDENT-109"
          ],
          "scenario": "Operators need to distinguish expiry, audience mismatch, and issuer failure.",
          "acceptanceCriteria": [
            "Define safe failure categories and request IDs.",
            "Document scoped recovery actions.",
            "Exclude tokens, private keys, and authorization headers."
          ],
          "implementationNotes": [
            "Use synthetic secret markers in verification."
          ],
          "verification": [
            "Diagnose an expired grant from safe metadata.",
            "Verify no seeded secret appears in logs or reports."
          ],
          "deliverables": [
            "Identity support runbook."
          ],
          "rollout": "Publish with the adapter and recheck after logging changes.",
          "skills": [
            "Operational security"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 50
            },
            {
              "field": "Site reliability",
              "percentage": 50
            }
          ],
          "patterns": []
        }
      ]
    }
  ]
}
