{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "id": "27823903-8b56-4675-865e-2f00111503b6",
      "key": "BMTLS",
      "title": "Mutual TLS certificate lifecycle",
      "field": "Networking",
      "summary": "Operate authenticated service connections through expiry, rotation, and trust changes.",
      "context": "A fictional internal report exporter uses mutual TLS. Certificates are renewed manually, and operators cannot distinguish peer identity failures from network outages.",
      "stack": [
        "TypeScript",
        "TLS",
        "Local certificate fixtures"
      ],
      "prerequisites": [
        "Generate disposable test-only certificate authorities and leaf certificates for loopback services; use no production keys."
      ],
      "developerValue": "Practice transport identity, trust-store changes, and certificate failure diagnosis.",
      "companyValue": "Provide repeatable rotation and recovery behavior for authenticated service communication.",
      "delivery": "Deliver local TLS checks and lifecycle rehearsals; modify no real trust stores.",
      "phases": [
        {
          "id": "identity",
          "title": "Define peer identity",
          "goal": "Specify certificate and name constraints."
        },
        {
          "id": "connect",
          "title": "Enforce transport trust",
          "goal": "Validate peers and handle connection lifecycle."
        },
        {
          "id": "rotate",
          "title": "Rehearse certificate changes",
          "goal": "Test overlap, expiry, revocation, and recovery."
        }
      ],
      "tickets": [
        {
          "id": "f4d534fd-159e-4013-8e49-287c7ba5fc54",
          "key": "BMTLS-101",
          "title": "Define expected service names and certificate usage",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "identity",
          "dependsOn": [],
          "scenario": "A certificate signed by the internal CA is accepted for any service name.",
          "acceptanceCriteria": [
            "List expected subject alternative names per peer.",
            "Declare client and server usage requirements.",
            "Separate trust-chain validity from service identity."
          ],
          "implementationNotes": [
            "Use reserved local names and test certificates."
          ],
          "verification": [
            "Match the intended service identity.",
            "Reject a valid-chain certificate for another service."
          ],
          "deliverables": [
            "TLS identity contract."
          ],
          "rollout": "Review identities before enabling peer authentication.",
          "skills": [
            "TLS fundamentals"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 70
            },
            {
              "field": "Networking",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "60a5f622-c9ae-4259-854a-0417f18562e2",
          "key": "BMTLS-102",
          "title": "Validate certificate chains without disabling hostname checks",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "identity",
          "dependsOn": [
            "BMTLS-101"
          ],
          "scenario": "A workaround accepts self-signed certificates by disabling all verification.",
          "acceptanceCriteria": [
            "Trust only the configured test CA set.",
            "Verify peer names and intended usage.",
            "Reject expired, incomplete, and unknown chains."
          ],
          "implementationNotes": [
            "No permissive verification bypass is allowed."
          ],
          "verification": [
            "Connect with the authorized test chain.",
            "Reject wrong-name and untrusted certificates."
          ],
          "deliverables": [
            "Strict TLS configuration."
          ],
          "rollout": "Fail closed and expose safe diagnostic categories.",
          "skills": [
            "Certificate validation"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 70
            },
            {
              "field": "Networking",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "b3bd1e34-3e4c-466b-a723-2d0fae968bb9",
          "key": "BMTLS-103",
          "title": "Separate certificate expiry alerts from connection failure rates",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 120,
          "phaseId": "connect",
          "dependsOn": [
            "BMTLS-102"
          ],
          "scenario": "Renewal is noticed only when connections begin failing.",
          "acceptanceCriteria": [
            "Report remaining certificate lifetime.",
            "Distinguish leaf and trust-anchor expiry.",
            "Keep expiry observations separate from availability outcomes."
          ],
          "implementationNotes": [
            "Avoid private-key or full certificate dumps in generic logs."
          ],
          "verification": [
            "Observe a near-expiry leaf certificate.",
            "Show an expired CA distinctly from an unreachable peer."
          ],
          "deliverables": [
            "Certificate health metrics."
          ],
          "rollout": "Run read-only checks before wiring operational alerts.",
          "skills": [
            "Observability"
          ],
          "fieldMix": [
            {
              "field": "Site reliability",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 20
            },
            {
              "field": "Networking",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "95618661-2048-4357-aaae-9eccb5884382",
          "key": "BMTLS-104",
          "title": "Refresh connection pools after client-certificate rotation",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "connect",
          "dependsOn": [
            "BMTLS-102",
            "BMTLS-103"
          ],
          "scenario": "Long-lived connections keep using the old client identity after new credentials are loaded.",
          "acceptanceCriteria": [
            "Bind pools to certificate generation.",
            "Stop assigning new requests to retired pools.",
            "Drain existing connections within a declared deadline."
          ],
          "implementationNotes": [
            "Do not terminate healthy requests without the documented drain policy."
          ],
          "verification": [
            "Rotate while a request is active.",
            "Verify new connections use the new certificate generation."
          ],
          "deliverables": [
            "Certificate-aware pool lifecycle."
          ],
          "rollout": "Roll out with a bounded overlap; preserve prior public trust during drain.",
          "skills": [
            "Connection lifecycle"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 50
            },
            {
              "field": "Security",
              "percentage": 30
            },
            {
              "field": "Site reliability",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "9abacd1d-6b31-4252-b00b-9836c93b100d",
          "key": "BMTLS-105",
          "title": "Keep TLS errors from exposing peer secrets or request payloads",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 120,
          "phaseId": "connect",
          "dependsOn": [
            "BMTLS-103"
          ],
          "scenario": "Handshake errors include large diagnostic objects containing sensitive material.",
          "acceptanceCriteria": [
            "Map failures to bounded safe categories.",
            "Include correlation and expected peer class.",
            "Exclude private keys, tokens, and request bodies."
          ],
          "implementationNotes": [
            "Use seeded synthetic secret markers."
          ],
          "verification": [
            "Diagnose hostname and expiry failures.",
            "Verify secret markers never appear in logs."
          ],
          "deliverables": [
            "Safe TLS error mapping."
          ],
          "rollout": "Replace broad error serialization before expanding diagnostics.",
          "skills": [
            "Operational security"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 50
            },
            {
              "field": "Site reliability",
              "percentage": 30
            },
            {
              "field": "Networking",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "843931c0-7a2e-4fa5-a70e-383fffd6b110",
          "key": "BMTLS-106",
          "title": "Rehearse leaf renewal under an unchanged trust anchor",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "rotate",
          "dependsOn": [
            "BMTLS-104",
            "BMTLS-105"
          ],
          "scenario": "Routine renewal should not require every client to restart simultaneously.",
          "acceptanceCriteria": [
            "Issue a new leaf with the same declared identity.",
            "Overlap old and new leaves within policy.",
            "Verify old-leaf retirement after draining."
          ],
          "implementationNotes": [
            "Generated keys remain local temporary test assets."
          ],
          "verification": [
            "Renew without interrupting the declared local request flow.",
            "Reject the expired prior leaf after overlap."
          ],
          "deliverables": [
            "Leaf renewal rehearsal."
          ],
          "rollout": "Renew before expiry and retain a bounded rollback window.",
          "skills": [
            "Certificate operations"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 50
            },
            {
              "field": "Networking",
              "percentage": 30
            },
            {
              "field": "Site reliability",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "a2972e5f-f7a5-481a-a5b6-8263b3ac51d5",
          "key": "BMTLS-107",
          "title": "Rotate trust anchors without accepting unrelated authorities",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 210,
          "phaseId": "rotate",
          "dependsOn": [
            "BMTLS-106"
          ],
          "scenario": "Adding a new CA to the trust store accidentally imports every certificate from a shared bundle.",
          "acceptanceCriteria": [
            "Allowlist exact old and new test anchors.",
            "Stage verifier trust before switching issuers.",
            "Remove the old anchor after the declared overlap."
          ],
          "implementationNotes": [
            "Never trust an arbitrary system bundle for this private service boundary."
          ],
          "verification": [
            "Complete a staged CA rotation.",
            "Reject a third unrelated CA throughout the overlap."
          ],
          "deliverables": [
            "Trust-anchor rotation procedure."
          ],
          "rollout": "Keep overlap short and reviewed; fail closed on unexpected trust material.",
          "skills": [
            "Trust management"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 70
            },
            {
              "field": "Networking",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "ccbd4534-8033-4264-bcc1-0c68fe098ecf",
          "key": "BMTLS-108",
          "title": "Enforce peer revocation on reused connections",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 210,
          "phaseId": "rotate",
          "dependsOn": [
            "BMTLS-104",
            "BMTLS-107"
          ],
          "scenario": "A revoked peer retains a long-lived authenticated connection.",
          "acceptanceCriteria": [
            "Define revocation checks and maximum connection lifetime.",
            "Stop new requests for revoked peer identity.",
            "Close or drain existing connections according to the incident policy."
          ],
          "implementationNotes": [
            "Revocation policy must state its bounded enforcement delay."
          ],
          "verification": [
            "Revoke an idle authenticated peer.",
            "Attempt reuse and verify denial within the declared bound."
          ],
          "deliverables": [
            "Revocation enforcement tests."
          ],
          "rollout": "Rehearse revocation before relying on certificate identity for sensitive operations.",
          "skills": [
            "Revocation",
            "Networking"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Networking",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "3768e95b-a596-477c-b424-c678934f469b",
          "key": "BMTLS-109",
          "title": "Compare certificate overlap availability against retained trust risk",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "rotate",
          "dependsOn": [
            "BMTLS-107",
            "BMTLS-108"
          ],
          "scenario": "A long overlap helps slow clients but extends acceptance of old credentials.",
          "acceptanceCriteria": [
            "Model client refresh distribution and enforcement delay.",
            "Compare bounded overlap options.",
            "Document unknown client behavior and recovery implications."
          ],
          "implementationNotes": [
            "The local rehearsal cannot prove organization-wide certificate rollout coverage."
          ],
          "verification": [
            "Evaluate fast and delayed synthetic clients.",
            "Reject an overlap proposal without an explicit old-trust retirement point."
          ],
          "deliverables": [
            "TLS lifecycle decision record."
          ],
          "rollout": "Choose a measurable overlap and track lagging clients before retirement.",
          "skills": [
            "Security tradeoffs",
            "Reliability"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 50
            },
            {
              "field": "Site reliability",
              "percentage": 30
            },
            {
              "field": "Networking",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "2ec6280e-6ad2-4a31-993d-3d184c37947a",
          "key": "BMTLS-110",
          "title": "Write a certificate-expiry incident handoff",
          "type": "CHORE",
          "priority": "LOW",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "rotate",
          "dependsOn": [
            "BMTLS-109"
          ],
          "scenario": "On-call staff need a safe response when one peer fails certificate validation.",
          "acceptanceCriteria": [
            "Identify failing peer class and certificate generation.",
            "Show approved renewal and trust-check steps.",
            "Explain when to stop retries and escalate ownership."
          ],
          "implementationNotes": [
            "Never recommend disabling certificate verification."
          ],
          "verification": [
            "Resolve a synthetic expired leaf using the guide.",
            "Keep an unknown-CA failure closed."
          ],
          "deliverables": [
            "TLS support runbook."
          ],
          "rollout": "Store with the service identity inventory and rotation schedule.",
          "skills": [
            "Runbooks"
          ],
          "fieldMix": [
            {
              "field": "Site reliability",
              "percentage": 50
            },
            {
              "field": "Security",
              "percentage": 30
            },
            {
              "field": "Networking",
              "percentage": 20
            }
          ],
          "patterns": []
        }
      ]
    }
  ]
}
