{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "key": "DART",
      "title": "Build an artifact path that can defend what it publishes",
      "field": "DevOps",
      "summary": "Create reproducible packages, provenance, signing boundaries, retention, and compromise recovery.",
      "context": "A fictional command-line product publishes local package archives. Builds contain timestamps, checksums are copied without provenance, and cleanup can delete the only rollback artifact. Use generated source trees, ephemeral development signing keys, and local object storage; no public registry or production key is supplied.",
      "stack": [
        "TypeScript",
        "Tar",
        "S3-compatible adapter",
        "Ephemeral signing provider"
      ],
      "prerequisites": [
        "Content hashing",
        "Archive formats",
        "Release metadata"
      ],
      "developerValue": "Practice reproducible artifacts, provenance validation, signing-key isolation and retention safety.",
      "companyValue": "Review a supply path that can trace, verify, retain, and revoke artifacts without relying on mutable names.",
      "delivery": "Ten linked tickets across three phases. Use a local repository and fake providers; deliver workflow code, failure tests, a rollback rehearsal, and a concise runbook.",
      "phases": [
        {
          "id": "baseline",
          "title": "Make the delivery contract visible",
          "goal": "Replace implicit workflow assumptions with reviewable inputs and outcomes."
        },
        {
          "id": "control",
          "title": "Control change and failure",
          "goal": "Add bounded concurrency, authority checks, and restart-safe transitions."
        },
        {
          "id": "handoff",
          "title": "Operate and improve",
          "goal": "Measure the workflow, rehearse recovery, and document ownership."
        }
      ],
      "tickets": [
        {
          "id": "7c67f02e-cf7b-4b02-a19c-bb49324a9095",
          "key": "DART-101",
          "title": "Make archive bytes reproducible from the same source manifest",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "baseline",
          "dependsOn": [],
          "scenario": "Two builds from identical fixtures differ because archive order, timestamps, ownership, and path separators come from the host.",
          "acceptanceCriteria": [
            "Sort entries by canonical relative path",
            "Normalize declared timestamps, ownership, permissions, and separators",
            "Reject paths escaping or colliding after normalization"
          ],
          "implementationNotes": [
            "Use generated files only and do not archive the repository working tree."
          ],
          "verification": [
            "Build twice in different temporary roots and compare byte digests.",
            "Add traversal and normalization-collision paths and confirm rejection."
          ],
          "deliverables": [
            "Deterministic archive writer and reproducibility tests"
          ],
          "rollout": "Publish reproducibility metadata before replacing the current archive path.",
          "skills": [
            "Reproducible builds",
            "Archive safety"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Security",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "96fab8e1-c129-4fda-a909-d2b0b2d8f696",
          "key": "DART-102",
          "title": "Generate a dependency inventory from resolved inputs",
          "type": "BUG",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "baseline",
          "dependsOn": [
            "DART-101"
          ],
          "scenario": "The package manifest lists declared ranges, not the exact dependency versions bundled into the archive.",
          "acceptanceCriteria": [
            "Inventory records exact package, version, integrity, and relationship",
            "Generation uses the resolved lock and packaged output",
            "Unknown or duplicate identities fail the release gate"
          ],
          "implementationNotes": [
            "Do not contact public vulnerability or package services in the exercise."
          ],
          "verification": [
            "Generate a stable inventory for the fixture lockfile.",
            "Remove an integrity entry and add a duplicate package identity, then block publication."
          ],
          "deliverables": [
            "Dependency inventory generator and malformed-lock tests"
          ],
          "rollout": "Attach inventory to local artifacts before enforcing completeness.",
          "skills": [
            "SBOM",
            "Dependency management"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "29da159f-1060-42f8-8cc0-cf38252d1023",
          "key": "DART-103",
          "title": "Bind provenance to source, builder, and exact artifact",
          "type": "STORY",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "baseline",
          "dependsOn": [
            "DART-101",
            "DART-102"
          ],
          "scenario": "A provenance file names a commit but is copied beside a different archive without detection.",
          "acceptanceCriteria": [
            "Statement binds artifact digest, source revision, build recipe, and builder identity",
            "Verification recomputes the artifact digest",
            "Unknown statement fields are preserved or rejected by version policy"
          ],
          "implementationNotes": [
            "Builder identity is a synthetic workload identity, not a person or authorship claim."
          ],
          "verification": [
            "Verify the matching artifact and statement.",
            "Swap artifact and source identities independently and confirm failure."
          ],
          "deliverables": [
            "Versioned provenance statement and verifier"
          ],
          "rollout": "Require verified provenance for a single fixture channel first.",
          "skills": [
            "Provenance",
            "Supply-chain security"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "80244ca5-fdf1-439d-bef2-05603cf4ec64",
          "key": "DART-104",
          "title": "Keep signing keys outside the build workspace",
          "type": "CHORE",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "control",
          "dependsOn": [
            "DART-103"
          ],
          "scenario": "The build job receives an exportable private key file that any build script could read or include in the archive.",
          "acceptanceCriteria": [
            "Build produces an unsigned digest and signing request",
            "Signing provider accepts only authorized artifact metadata",
            "Private key bytes never enter workspace, logs, or artifacts"
          ],
          "implementationNotes": [
            "Use ephemeral local keys behind a provider interface; production key management remains unprovisioned."
          ],
          "verification": [
            "Sign and verify an authorized fixture artifact.",
            "Search outputs for a sentinel key and reject an unauthorized digest request."
          ],
          "deliverables": [
            "Signing-provider boundary and leak tests"
          ],
          "rollout": "Keep unsigned artifacts nonpromotable while the development signer is enabled.",
          "skills": [
            "Key isolation",
            "Provider interfaces",
            "Signing"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Security",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "b384a822-d3ec-400e-b76c-d39519209983",
          "key": "DART-105",
          "title": "Promote only artifacts whose evidence set reconciles",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "control",
          "dependsOn": [
            "DART-102",
            "DART-103",
            "DART-104"
          ],
          "scenario": "A package is promoted after signature verification even though its inventory belongs to an earlier build.",
          "acceptanceCriteria": [
            "Gate binds artifact, provenance, inventory, signature, and policy versions",
            "Every component references the same artifact digest",
            "Missing or conflicting metadata blocks promotion with exact reasons"
          ],
          "implementationNotes": [
            "This verifies release metadata, not candidate Outcome Evidence or ownership."
          ],
          "verification": [
            "Promote one complete matching fixture set.",
            "Mix inventory, signature, and provenance from neighboring builds and reject each case."
          ],
          "deliverables": [
            "Artifact evidence-set gate and mismatch matrix"
          ],
          "rollout": "Run the gate in report-only mode before making it mandatory.",
          "skills": [
            "Release gates",
            "Integrity",
            "Policy validation"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "43defb43-7152-401a-83f3-5e2ecf61fd64",
          "key": "DART-106",
          "title": "Prevent a mutable channel from changing an approved artifact",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "control",
          "dependsOn": [
            "DART-105"
          ],
          "scenario": "The beta channel is approved while pointing to one digest, then its mutable object is overwritten before clients resolve it.",
          "acceptanceCriteria": [
            "Approval binds channel, digest, and revision",
            "Channel update uses compare-and-set against observed revision",
            "Clients can resolve historical channel revisions"
          ],
          "implementationNotes": [
            "Channel is discovery metadata; the artifact remains content addressed and immutable."
          ],
          "verification": [
            "Advance beta from one approved digest to another.",
            "Race two channel updates and verify only one wins without overwriting history."
          ],
          "deliverables": [
            "Versioned channel pointer and concurrency test"
          ],
          "rollout": "Enable one nondefault fixture channel before broader use.",
          "skills": [
            "Optimistic concurrency",
            "Artifact channels"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Distributed systems",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "a645ef65-9999-462f-82a4-fef5060abe99",
          "key": "DART-107",
          "title": "Revoke a compromised signing identity without deleting history",
          "type": "STORY",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 360,
          "phaseId": "control",
          "dependsOn": [
            "DART-104",
            "DART-105"
          ],
          "scenario": "A development signing key is declared compromised, and the cleanup proposal deletes every artifact it signed, including investigation records.",
          "acceptanceCriteria": [
            "Revocation records key identity, effective scope, time, and reason",
            "Verification distinguishes signed-before, signed-after, and explicitly revoked artifacts",
            "Historical metadata remains inspectable and immutable"
          ],
          "implementationNotes": [
            "Use ephemeral fixture keys; do not claim real-world trust without a provisioned signer and policy."
          ],
          "verification": [
            "Verify artifacts on both sides of a declared rotation under policy.",
            "Present an artifact signed after compromise and confirm promotion denial without deletion."
          ],
          "deliverables": [
            "Signing revocation policy and temporal tests"
          ],
          "rollout": "Block new promotion first, then review already promoted fixture artifacts.",
          "skills": [
            "Key revocation",
            "Temporal policy",
            "Audit"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 65
            },
            {
              "field": "Security",
              "percentage": 35
            }
          ],
          "patterns": []
        },
        {
          "id": "f6faa569-728e-4161-9b8f-990aced24191",
          "key": "DART-108",
          "title": "Retain rollback artifacts while bounding storage growth",
          "type": "CHORE",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "handoff",
          "dependsOn": [
            "DART-105",
            "DART-106"
          ],
          "scenario": "Age-only cleanup removes the last compatible rollback artifact for a supported release line.",
          "acceptanceCriteria": [
            "Retention protects active, rollback, held, and investigation-referenced digests",
            "Deletion plan is deterministic and reviewable before mutation",
            "Partial deletion resumes by immutable digest"
          ],
          "implementationNotes": [
            "Use local object storage and synthetic artifact bytes; never delete undeclared objects."
          ],
          "verification": [
            "Plan and execute cleanup while retaining every protected digest.",
            "Interrupt halfway and replay; add an unknown reference and keep it unresolved."
          ],
          "deliverables": [
            "Artifact retention planner and interrupted cleanup drill"
          ],
          "rollout": "Run plan-only mode before enabling scoped fixture deletion.",
          "skills": [
            "Retention",
            "Object storage",
            "Recovery"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 60
            },
            {
              "field": "Storage systems",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "151556f6-1594-4f48-bb78-0a50300eb470",
          "key": "DART-109",
          "title": "Recover publication after object storage acknowledges late",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 360,
          "phaseId": "handoff",
          "dependsOn": [
            "DART-103",
            "DART-105",
            "DART-108"
          ],
          "scenario": "The object store commits an archive but the upload times out; retry creates a differently named duplicate and publishes only one metadata set.",
          "acceptanceCriteria": [
            "Object key derives from verified content digest",
            "Retry reconciles size, digest, and metadata before upload",
            "Conflicting existing content is quarantined and never overwritten"
          ],
          "implementationNotes": [
            "Treat storage metadata as untrusted until content identity is verified."
          ],
          "verification": [
            "Upload and replay an identical artifact idempotently.",
            "Lose the response after commit and preplace conflicting bytes under the expected key."
          ],
          "deliverables": [
            "Content-addressed publisher and ambiguous-upload tests"
          ],
          "rollout": "Enable for one artifact class while retaining the prior publisher for rollback.",
          "skills": [
            "Object storage",
            "Idempotency",
            "Integrity"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Storage systems",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "f6f08239-1f6a-48de-af61-93fee1ca5387",
          "key": "DART-110",
          "title": "Rehearse artifact compromise from block to recovery",
          "type": "BUG",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "handoff",
          "dependsOn": [
            "DART-107",
            "DART-108",
            "DART-109"
          ],
          "scenario": "The response plan says rotate and rebuild but does not identify affected channels, compatible rollback artifacts, or how clients learn the block.",
          "acceptanceCriteria": [
            "Runbook traces key, artifact, channel, environment, and consumer relationships",
            "Rehearsal blocks promotion and selects a verified compatible artifact",
            "Recovery publishes a new identity without rewriting compromised history"
          ],
          "implementationNotes": [
            "The scenario uses fictional artifacts and ephemeral keys only."
          ],
          "verification": [
            "Complete a synthetic compromise and restore a safe channel.",
            "Remove the expected rollback artifact and follow the documented blocked path."
          ],
          "deliverables": [
            "Artifact incident runbook and tabletop transcript"
          ],
          "rollout": "Review findings before treating the workflow as ready for an external registry.",
          "skills": [
            "Incident response",
            "Supply-chain recovery",
            "Runbooks"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Site reliability",
              "percentage": 30
            }
          ],
          "patterns": []
        }
      ],
      "id": "c842c7e6-cc1c-4fda-93b0-ef2c10224911"
    }
  ]
}
