{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "id": "0b34c443-3e67-4369-8c00-5773c489b84f",
      "key": "BPROXY",
      "title": "Reverse-proxy connection reliability",
      "field": "Networking",
      "summary": "Correct proxy behavior for trusted forwarding, connection reuse, and streaming cancellation.",
      "context": "A fictional reporting API sits behind a reverse proxy. Clients see intermittent disconnects and incorrect origins after changes to keep-alive and forwarding headers.",
      "stack": [
        "TypeScript",
        "HTTP",
        "Local reverse proxy"
      ],
      "prerequisites": [
        "Create two loopback HTTP services and a local proxy with synthetic requests; no public scanning or external traffic."
      ],
      "developerValue": "Practice HTTP intermediaries, connection lifetimes, and network failure isolation.",
      "companyValue": "Provide a proxy contract that preserves request identity and releases resources predictably.",
      "delivery": "Deliver a local proxy configuration or adapter plus reproducible failure checks.",
      "phases": [
        {
          "id": "boundary",
          "title": "Define proxy trust",
          "goal": "Constrain forwarding and request interpretation."
        },
        {
          "id": "connections",
          "title": "Manage connections",
          "goal": "Handle reuse, timeouts, and cancellation."
        },
        {
          "id": "rollout",
          "title": "Verify proxy changes",
          "goal": "Measure behavior and rehearse configuration recovery."
        }
      ],
      "tickets": [
        {
          "id": "6a4b0d4c-7843-46b3-94d4-c765394a6fe7",
          "key": "BPROXY-101",
          "title": "Document the trusted proxy chain and public origin",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "boundary",
          "dependsOn": [],
          "scenario": "The application trusts forwarding headers from any caller.",
          "acceptanceCriteria": [
            "List trusted proxy hops and expected public origin.",
            "Define which hop sets each forwarding field.",
            "Reject ambiguous trust configuration."
          ],
          "implementationNotes": [
            "All modeled hops are local fixtures."
          ],
          "verification": [
            "Resolve origin through the trusted chain.",
            "Reject direct-client spoofed forwarding metadata."
          ],
          "deliverables": [
            "Proxy trust contract."
          ],
          "rollout": "Review the trust chain before changing application origin handling.",
          "skills": [
            "HTTP",
            "Trust boundaries"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Networking",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "f6ccd885-21d0-4f80-aba6-9a92e126231c",
          "key": "BPROXY-102",
          "title": "Normalize forwarded headers without accepting client spoofing",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "boundary",
          "dependsOn": [
            "BPROXY-101"
          ],
          "scenario": "A client-provided forwarded host changes generated callback URLs.",
          "acceptanceCriteria": [
            "Discard untrusted incoming forwarding fields.",
            "Set canonical forwarding metadata at the trusted boundary.",
            "Reject malformed or conflicting host values."
          ],
          "implementationNotes": [
            "Use an explicit allowed-origin list."
          ],
          "verification": [
            "Generate a callback for the allowed origin.",
            "Inject a spoofed forwarded host and verify rejection."
          ],
          "deliverables": [
            "Forwarding-header guard."
          ],
          "rollout": "Enable alongside the reviewed proxy chain; retain safe fixed-origin fallback.",
          "skills": [
            "Header security"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 70
            },
            {
              "field": "Networking",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "9889cdbd-dca2-4db6-a82d-56bdf2e1c8a8",
          "key": "BPROXY-103",
          "title": "Strip hop-by-hop headers before forwarding requests",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 120,
          "phaseId": "boundary",
          "dependsOn": [
            "BPROXY-102"
          ],
          "scenario": "Connection-specific headers are forwarded as if they were end-to-end metadata.",
          "acceptanceCriteria": [
            "Remove declared hop-by-hop fields.",
            "Honor fields named by the Connection header.",
            "Preserve required end-to-end headers."
          ],
          "implementationNotes": [
            "Parse header names case-insensitively and bound header size."
          ],
          "verification": [
            "Forward a valid request unchanged semantically.",
            "Verify Connection-nominated fields do not reach upstream."
          ],
          "deliverables": [
            "Header forwarding tests."
          ],
          "rollout": "Deploy to the local proxy fixture first and inspect resulting headers.",
          "skills": [
            "HTTP semantics"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 80
            },
            {
              "field": "API design",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "95089183-5f4f-47be-a0ca-4a0510371d47",
          "key": "BPROXY-104",
          "title": "Align keep-alive lifetimes between proxy and upstream",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "connections",
          "dependsOn": [
            "BPROXY-103"
          ],
          "scenario": "The proxy reuses sockets just after the upstream has closed them.",
          "acceptanceCriteria": [
            "Document idle-timeout relationships.",
            "Retire idle connections before unsafe reuse under the chosen policy.",
            "Classify stale-connection failures separately."
          ],
          "implementationNotes": [
            "Use controlled local timeout fixtures."
          ],
          "verification": [
            "Reuse a valid connection.",
            "Expire upstream idle state and verify bounded recovery."
          ],
          "deliverables": [
            "Connection lifetime configuration."
          ],
          "rollout": "Change one timeout at a time; retain previous values for comparison.",
          "skills": [
            "Connection pooling"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 60
            },
            {
              "field": "Performance engineering",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "5543888b-e2e2-414b-b20d-7affc60c0a96",
          "key": "BPROXY-105",
          "title": "Limit upstream connections per service without unbounded waiting",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "connections",
          "dependsOn": [
            "BPROXY-104"
          ],
          "scenario": "A slow upstream creates an unlimited queue behind a finite connection pool.",
          "acceptanceCriteria": [
            "Set finite active and waiting limits.",
            "Return explicit overload responses when waiting is full.",
            "Remove cancelled waiters."
          ],
          "implementationNotes": [
            "Keep limits service-scoped and observable."
          ],
          "verification": [
            "Serve within the configured pool.",
            "Overflow the wait queue and verify no resource leak."
          ],
          "deliverables": [
            "Bounded upstream pool."
          ],
          "rollout": "Start conservatively; tune only from recorded workload behavior.",
          "skills": [
            "Backpressure"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 50
            },
            {
              "field": "Performance engineering",
              "percentage": 30
            },
            {
              "field": "Site reliability",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "7431849c-0083-4838-a9c3-3222ff2b748c",
          "key": "BPROXY-106",
          "title": "Propagate downstream disconnects through streamed responses",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "connections",
          "dependsOn": [
            "BPROXY-105"
          ],
          "scenario": "A cancelled report download continues consuming upstream bandwidth.",
          "acceptanceCriteria": [
            "Abort the owned upstream request on disconnect.",
            "Stop buffering and release stream resources.",
            "Preserve completion metrics distinct from cancellation."
          ],
          "implementationNotes": [
            "Use bounded synthetic report streams."
          ],
          "verification": [
            "Finish a small streamed response.",
            "Disconnect mid-stream and verify upstream cancellation."
          ],
          "deliverables": [
            "Streaming cancellation fix."
          ],
          "rollout": "Adopt on one streaming route; retain traces of safe lifecycle events.",
          "skills": [
            "Streams",
            "Cancellation"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 50
            },
            {
              "field": "Backend",
              "percentage": 30
            },
            {
              "field": "Performance engineering",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "c61bf0c8-7cf5-46ef-94b8-af7993f836ed",
          "key": "BPROXY-107",
          "title": "Avoid unsafe automatic replay after partial request transmission",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "connections",
          "dependsOn": [
            "BPROXY-104",
            "BPROXY-106"
          ],
          "scenario": "The proxy retries a POST after its connection breaks, potentially duplicating a write.",
          "acceptanceCriteria": [
            "Distinguish retryable methods and declared idempotent operations.",
            "Track whether request transmission may have occurred.",
            "Return unknown outcome when safe replay cannot be established."
          ],
          "implementationNotes": [
            "Do not infer idempotency from an empty response."
          ],
          "verification": [
            "Retry a safe read after a stale connection.",
            "Break a write after transmission and prevent blind replay."
          ],
          "deliverables": [
            "Proxy retry policy."
          ],
          "rollout": "Disable automatic write retries until application identity semantics are explicit.",
          "skills": [
            "HTTP retries",
            "Consistency"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 40
            },
            {
              "field": "API design",
              "percentage": 30
            },
            {
              "field": "Distributed systems",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "3c504c51-bdb4-41fa-a7fb-405c9880582b",
          "key": "BPROXY-108",
          "title": "Compare buffering and streaming under bounded memory",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "rollout",
          "dependsOn": [
            "BPROXY-105",
            "BPROXY-106",
            "BPROXY-107"
          ],
          "scenario": "Buffering simplifies upstream retries but large reports exhaust proxy memory.",
          "acceptanceCriteria": [
            "Compare identical synthetic response sizes and client rates.",
            "Measure memory, time-to-first-byte, completion, and cancellation.",
            "Explain retry and partial-response tradeoffs."
          ],
          "implementationNotes": [
            "Record machine limits and do not generalize local throughput."
          ],
          "verification": [
            "Run fast and slow clients under both policies.",
            "Expose the memory or partial-response failure boundary."
          ],
          "deliverables": [
            "Proxy buffering decision record."
          ],
          "rollout": "Select route-specific policy with explicit byte limits and rollback configuration.",
          "skills": [
            "Performance analysis",
            "Network design"
          ],
          "fieldMix": [
            {
              "field": "Performance engineering",
              "percentage": 60
            },
            {
              "field": "Networking",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "9ace06f2-5dec-46bf-9f91-aadf73c690ed",
          "key": "BPROXY-109",
          "title": "Reload proxy configuration without dropping healthy in-flight requests",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 210,
          "phaseId": "rollout",
          "dependsOn": [
            "BPROXY-108"
          ],
          "scenario": "Configuration reloads close active report streams immediately.",
          "acceptanceCriteria": [
            "Validate new configuration before activation.",
            "Drain existing connections within a bounded deadline.",
            "Reject invalid reloads while retaining the prior configuration."
          ],
          "implementationNotes": [
            "Use only locally owned processes."
          ],
          "verification": [
            "Reload during an active stream.",
            "Submit invalid configuration and verify the old proxy remains usable."
          ],
          "deliverables": [
            "Graceful reload behavior."
          ],
          "rollout": "Keep a tested prior configuration and an explicit drain timeout.",
          "skills": [
            "Operational networking"
          ],
          "fieldMix": [
            {
              "field": "Networking",
              "percentage": 60
            },
            {
              "field": "Site reliability",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "8ac5eb33-3fab-47a8-bf68-9743bacd25f4",
          "key": "BPROXY-110",
          "title": "Write a proxy incident checklist by connection stage",
          "type": "CHORE",
          "priority": "LOW",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "rollout",
          "dependsOn": [
            "BPROXY-109"
          ],
          "scenario": "Operators need to distinguish header rejection, pool waiting, and upstream disconnects.",
          "acceptanceCriteria": [
            "Map safe failure categories to checks.",
            "Include current timeout and pool settings.",
            "Document bounded rollback and drain commands."
          ],
          "implementationNotes": [
            "Do not capture request bodies or credentials."
          ],
          "verification": [
            "Diagnose a synthetic stale connection.",
            "Distinguish pool overload from upstream application failure."
          ],
          "deliverables": [
            "Proxy support runbook."
          ],
          "rollout": "Ship with configuration changes and verify it during local rehearsal.",
          "skills": [
            "Runbooks"
          ],
          "fieldMix": [
            {
              "field": "Site reliability",
              "percentage": 50
            },
            {
              "field": "Networking",
              "percentage": 50
            }
          ],
          "patterns": []
        }
      ]
    }
  ]
}
