{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "id": "934d7d97-1f21-4cf3-9d79-c8cc30d66837",
      "key": "BNETDIAG",
      "title": "Dual-stack network troubleshooting kit",
      "field": "Networking",
      "summary": "Diagnose address-family, packet-size, and routing failures in an authorized local lab.",
      "context": "A fictional desktop sync client works on one office network but intermittently fails on another. Application retries hide whether DNS, IPv6, or transport limits are responsible.",
      "stack": [
        "TypeScript",
        "Packet trace fixtures",
        "HTTP"
      ],
      "prerequisites": [
        "Author synthetic packet traces and local IPv4/IPv6 endpoint doubles; use no third-party scanning or captured personal traffic."
      ],
      "developerValue": "Practice layered network diagnosis and reproducible troubleshooting.",
      "companyValue": "Produce precise support diagnostics that distinguish application defects from connectivity conditions.",
      "delivery": "Deliver an offline trace analyzer and local diagnostic workflow with explicit platform limits.",
      "phases": [
        {
          "id": "observe",
          "title": "Observe network stages",
          "goal": "Normalize safe diagnostics and establish controlled cases."
        },
        {
          "id": "diagnose",
          "title": "Diagnose failure families",
          "goal": "Separate resolution, address selection, and transport behavior."
        },
        {
          "id": "handoff",
          "title": "Make diagnosis repeatable",
          "goal": "Evaluate fallback and produce safe support artifacts."
        }
      ],
      "tickets": [
        {
          "id": "f116d752-b86a-4dfd-9750-2d5f65068f7c",
          "key": "BNETDIAG-101",
          "title": "Define a sanitized connection-attempt diagnostic record",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "observe",
          "dependsOn": [],
          "scenario": "Support receives raw traces containing request payloads and personal hostnames.",
          "acceptanceCriteria": [
            "Record stage, address family, duration, and safe error category.",
            "Exclude payloads, credentials, and user identifiers.",
            "Mark unavailable measurements explicitly."
          ],
          "implementationNotes": [
            "Use synthetic traces only."
          ],
          "verification": [
            "Represent a successful local connection.",
            "Scan a seeded sensitive trace and verify excluded fields."
          ],
          "deliverables": [
            "Diagnostic schema."
          ],
          "rollout": "Adopt minimal records before collecting more detail.",
          "skills": [
            "Network diagnostics",
            "Privacy"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 50
            },
            {
              "field": "Privacy engineering",
              "percentage": 50
            }
          ],
          "patterns": []
        },
        {
          "id": "0a477436-0b32-47f9-8f99-a8850bd691b0",
          "key": "BNETDIAG-102",
          "title": "Correlate DNS answers with selected connection addresses",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 120,
          "phaseId": "observe",
          "dependsOn": [
            "BNETDIAG-101"
          ],
          "scenario": "The client log shows resolved addresses but not which one it attempted.",
          "acceptanceCriteria": [
            "Bind attempts to their resolution result identity.",
            "Record selected family and address classification.",
            "Detect attempts outside the recorded answer set."
          ],
          "implementationNotes": [
            "Store only approved synthetic addresses."
          ],
          "verification": [
            "Trace selection from a dual-stack answer.",
            "Flag a connection address absent from the result."
          ],
          "deliverables": [
            "Resolution-to-connection correlation."
          ],
          "rollout": "Enable in local diagnostic mode first.",
          "skills": [
            "DNS",
            "Observability"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 70
            },
            {
              "field": "Site reliability",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "cfcab83a-679b-4567-9ed2-0d29bef8fdb3",
          "key": "BNETDIAG-103",
          "title": "Implement bounded address-family fallback in the client fixture",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "diagnose",
          "dependsOn": [
            "BNETDIAG-102"
          ],
          "scenario": "An unreachable IPv6 address delays a working IPv4 connection until a long timeout.",
          "acceptanceCriteria": [
            "Race or sequence families under a declared bounded policy.",
            "Cancel losing attempts and release sockets.",
            "Preserve meaningful final errors when both fail."
          ],
          "implementationNotes": [
            "Use deterministic timers and loopback doubles."
          ],
          "verification": [
            "Reach IPv4 when the IPv6 fixture stalls.",
            "Fail both families without leaked attempts."
          ],
          "deliverables": [
            "Address-family fallback policy."
          ],
          "rollout": "Compare with the previous policy under identical traces before adoption.",
          "skills": [
            "IPv6",
            "Connection management"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 70
            },
            {
              "field": "Performance engineering",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "8d9d381a-306b-4ca9-b9a7-1abca267870a",
          "key": "BNETDIAG-104",
          "title": "Detect a packet-size black-hole pattern in synthetic traces",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "diagnose",
          "dependsOn": [
            "BNETDIAG-101"
          ],
          "scenario": "Small requests succeed while larger uploads stall without an application response.",
          "acceptanceCriteria": [
            "Identify the declared retransmission and size pattern.",
            "Distinguish a hypothesis from confirmed cause.",
            "Suggest one bounded local verification step."
          ],
          "implementationNotes": [
            "Do not infer path MTU from an arbitrary single failed request."
          ],
          "verification": [
            "Analyze a synthetic size-dependent failure.",
            "Keep a generic timeout trace inconclusive."
          ],
          "deliverables": [
            "Packet-size diagnostic rule."
          ],
          "rollout": "Use advisory findings only; require the verification step before configuration changes.",
          "skills": [
            "Transport analysis"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 100
            }
          ],
          "patterns": []
        },
        {
          "id": "b332474a-7990-42ee-b315-d03f9e9d09e2",
          "key": "BNETDIAG-105",
          "title": "Separate proxy interception from origin TLS failure",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "diagnose",
          "dependsOn": [
            "BNETDIAG-101",
            "BNETDIAG-102"
          ],
          "scenario": "Certificate failures on one network are blamed on the origin service.",
          "acceptanceCriteria": [
            "Compare expected peer identity with observed chain metadata.",
            "Record proxy configuration source safely.",
            "Keep unknown interception explicitly unresolved."
          ],
          "implementationNotes": [
            "Never recommend disabling TLS verification."
          ],
          "verification": [
            "Identify the modeled local proxy certificate.",
            "Distinguish a wrong-origin certificate from an unreachable origin."
          ],
          "deliverables": [
            "TLS path diagnostic."
          ],
          "rollout": "Keep failed connections closed while investigating trust configuration.",
          "skills": [
            "TLS",
            "Network troubleshooting"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "8f7fc050-b648-4bc7-b2fa-d64d9f11d26d",
          "key": "BNETDIAG-106",
          "title": "Detect split-horizon DNS differences without leaking private zones",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "diagnose",
          "dependsOn": [
            "BNETDIAG-102"
          ],
          "scenario": "The same service name maps differently in two authorized network contexts.",
          "acceptanceCriteria": [
            "Compare labeled resolver-context results.",
            "Report family, record class, and policy differences.",
            "Redact private names from shareable output."
          ],
          "implementationNotes": [
            "Use synthetic zone data and no external DNS queries."
          ],
          "verification": [
            "Compare two intentional split-horizon fixtures.",
            "Detect an unexpected public-context answer."
          ],
          "deliverables": [
            "Resolver comparison report."
          ],
          "rollout": "Review private results locally; share only the sanitized projection.",
          "skills": [
            "DNS",
            "Privacy"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 60
            },
            {
              "field": "Privacy engineering",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "325c5d20-c3f3-43be-a8d6-1bef19019cc4",
          "key": "BNETDIAG-107",
          "title": "Bound diagnostic retries independently of application retries",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "diagnose",
          "dependsOn": [
            "BNETDIAG-103"
          ],
          "scenario": "Running the diagnostic tool triggers the client's normal retry loop and floods the local test endpoint.",
          "acceptanceCriteria": [
            "Use a separate fixed diagnostic attempt budget.",
            "Disable application retry chaining.",
            "Stop immediately on explicit cancellation."
          ],
          "implementationNotes": [
            "Targets must match the authorized local allowlist."
          ],
          "verification": [
            "Run the declared number of attempts.",
            "Cancel or supply an unapproved target and verify no further connections."
          ],
          "deliverables": [
            "Diagnostic execution guard."
          ],
          "rollout": "Default to offline analysis; require explicit local target configuration.",
          "skills": [
            "Resource bounds"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 50
            },
            {
              "field": "Developer tooling",
              "percentage": 30
            },
            {
              "field": "Site reliability",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "e2e21850-c6c4-48b1-ac6a-bbd71a5a07e3",
          "key": "BNETDIAG-108",
          "title": "Compare fallback latency without hiding failed attempts",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "handoff",
          "dependsOn": [
            "BNETDIAG-103",
            "BNETDIAG-104",
            "BNETDIAG-105",
            "BNETDIAG-107"
          ],
          "scenario": "A new connection policy appears faster because the report excludes failed IPv6 attempts.",
          "acceptanceCriteria": [
            "Use identical network-condition traces for both policies.",
            "Report end-to-end success, failure, latency, and extra connection work.",
            "Document simulated conditions and unverified real-network behavior."
          ],
          "implementationNotes": [
            "Do not rank policies solely by successful median latency."
          ],
          "verification": [
            "Compare healthy and one-family-failing cases.",
            "Expose additional connection cost and dual-family failure behavior."
          ],
          "deliverables": [
            "Fallback policy assessment."
          ],
          "rollout": "Adopt only for the modeled conditions and retain a configuration rollback.",
          "skills": [
            "Performance methodology",
            "Networking"
          ],
          "fieldMix": [
            {
              "field": "Performance engineering",
              "percentage": 60
            },
            {
              "field": "Networking",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "7409d699-460e-4f98-8aee-8f8b99a1f8fc",
          "key": "BNETDIAG-109",
          "title": "Generate a shareable network diagnosis bundle",
          "type": "STORY",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "handoff",
          "dependsOn": [
            "BNETDIAG-106",
            "BNETDIAG-108"
          ],
          "scenario": "Support needs a useful report without raw packet payloads.",
          "acceptanceCriteria": [
            "Include tool version, scenario, and safe stage observations.",
            "Link findings to sanitized trace identities.",
            "Bound bundle size and reject forbidden fields."
          ],
          "implementationNotes": [
            "Keep original synthetic trace data separate."
          ],
          "verification": [
            "Build a bundle for a known local failure.",
            "Seed credentials and verify they cannot enter the bundle."
          ],
          "deliverables": [
            "Sanitized diagnosis bundle."
          ],
          "rollout": "Review the bundle schema before any real support collection.",
          "skills": [
            "Diagnostics",
            "Data minimization"
          ],
          "fieldMix": [
            {
              "field": "Privacy engineering",
              "percentage": 50
            },
            {
              "field": "Networking",
              "percentage": 30
            },
            {
              "field": "Developer tooling",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "395985ea-05a3-48f1-bf79-d99a766adcf9",
          "key": "BNETDIAG-110",
          "title": "Write a troubleshooting decision tree with inconclusive exits",
          "type": "CHORE",
          "priority": "LOW",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "handoff",
          "dependsOn": [
            "BNETDIAG-109"
          ],
          "scenario": "Support scripts force every connection failure into a known cause.",
          "acceptanceCriteria": [
            "Separate DNS, connect, TLS, and HTTP branches.",
            "Include evidence needed for each next step.",
            "Provide an inconclusive result when observations are insufficient."
          ],
          "implementationNotes": [
            "Every active check stays inside the authorized local lab."
          ],
          "verification": [
            "Follow the tree for a modeled family failure.",
            "Stop inconclusively for missing telemetry."
          ],
          "deliverables": [
            "Network troubleshooting guide."
          ],
          "rollout": "Keep the guide tied to implemented diagnostics and declared limits.",
          "skills": [
            "Technical writing"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 70
            },
            {
              "field": "Site reliability",
              "percentage": 30
            }
          ],
          "patterns": []
        }
      ]
    }
  ]
}
