{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "key": "DCI",
      "title": "Make pull-request CI trustworthy under load",
      "field": "DevOps",
      "summary": "Repair cache identity, cancellation, flaky checks, and feedback latency in a multi-package pipeline.",
      "context": "A fictional TypeScript monorepo has twelve packages and a local CI simulator. Pull requests wait for redundant work, stale caches occasionally pass broken changes, and superseded runs continue consuming executors. Create synthetic package graphs and fake check APIs; no hosted CI credentials or production repositories are supplied.",
      "stack": [
        "TypeScript",
        "pnpm",
        "Git",
        "CI simulator"
      ],
      "prerequisites": [
        "Dependency graphs",
        "Process exit codes",
        "Test isolation"
      ],
      "developerValue": "Practice treating CI as a versioned delivery system with correctness, latency, and recovery constraints.",
      "companyValue": "Review a pipeline that reduces wasted compute without allowing stale or skipped checks to approve changes.",
      "delivery": "Ten linked tickets across three phases. Use a local repository and fake providers; deliver workflow code, failure tests, a rollback rehearsal, and a concise runbook.",
      "phases": [
        {
          "id": "baseline",
          "title": "Make the delivery contract visible",
          "goal": "Replace implicit workflow assumptions with reviewable inputs and outcomes."
        },
        {
          "id": "control",
          "title": "Control change and failure",
          "goal": "Add bounded concurrency, authority checks, and restart-safe transitions."
        },
        {
          "id": "handoff",
          "title": "Operate and improve",
          "goal": "Measure the workflow, rehearse recovery, and document ownership."
        }
      ],
      "tickets": [
        {
          "id": "188f2761-111f-4302-9665-2e7202fae287",
          "key": "DCI-101",
          "title": "Pin the required-check contract before optimizing the pipeline",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "baseline",
          "dependsOn": [],
          "scenario": "Branch protection expects names that differ from the workflow after a recent rename, leaving one required check permanently pending.",
          "acceptanceCriteria": [
            "Declare stable check identities and their owning commands",
            "Map every protected check to exactly one terminal report",
            "Unknown or duplicated check names fail workflow validation"
          ],
          "implementationNotes": [
            "The local simulator must not call a real repository or modify branch protection."
          ],
          "verification": [
            "Complete every declared check and reconcile its final status.",
            "Rename and duplicate a check, then confirm validation blocks the workflow."
          ],
          "deliverables": [
            "Required-check manifest and consistency test"
          ],
          "rollout": "Publish the manifest before changing job topology.",
          "skills": [
            "CI contracts",
            "Configuration validation"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Developer tooling",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "4e632cae-be6f-45aa-8985-685b2b272332",
          "key": "DCI-102",
          "title": "Fail the pipeline when a command exits through a hidden pipe",
          "type": "BUG",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "baseline",
          "dependsOn": [],
          "scenario": "Test output is piped through a formatter; the formatter succeeds after the test process fails, so the job reports green.",
          "acceptanceCriteria": [
            "Job status reflects every command in the pipeline",
            "Original stdout and stderr remain available",
            "Signal termination and ordinary nonzero exit are distinguished"
          ],
          "implementationNotes": [
            "Do not parse human-readable output to determine success."
          ],
          "verification": [
            "Run successful tests through the formatter and retain readable logs.",
            "Fail the upstream process and verify the job reports its exact failure."
          ],
          "deliverables": [
            "Exit-status wrapper and pipeline regression"
          ],
          "rollout": "Apply first to test jobs, then audit every piped command.",
          "skills": [
            "Shell behavior",
            "Process status"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Quality engineering",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "297f79c8-d71d-4857-8ae4-2d1ce68a638e",
          "key": "DCI-103",
          "title": "Compute affected packages from both dependency directions",
          "type": "STORY",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "baseline",
          "dependsOn": [
            "DCI-101"
          ],
          "scenario": "Changing a shared type package runs its own tests but skips three consumers that compile against the changed contract.",
          "acceptanceCriteria": [
            "Changed packages and transitive consumers enter the affected set",
            "Deleted and renamed files map to their owning package",
            "Global configuration changes select the declared full set"
          ],
          "implementationNotes": [
            "Use the synthetic graph and explicit ownership rules; filename substring guesses are insufficient."
          ],
          "verification": [
            "Change a leaf, shared library, and root configuration and compare selected packages.",
            "Create a dependency cycle fixture and fail analysis without silently dropping nodes."
          ],
          "deliverables": [
            "Affected-graph selector and graph fixtures"
          ],
          "rollout": "Run selection in report-only mode beside the current full pipeline.",
          "skills": [
            "Dependency graphs",
            "Change analysis"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 60
            },
            {
              "field": "Developer tooling",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "0f5ef932-2051-4f2b-a4e9-9e04cf4ba76b",
          "key": "DCI-104",
          "title": "Key build caches from every semantic input",
          "type": "CHORE",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "control",
          "dependsOn": [
            "DCI-103"
          ],
          "scenario": "A cache hit reuses generated clients after the schema changed because only source-directory files contribute to the key.",
          "acceptanceCriteria": [
            "Cache identity includes command, toolchain, environment contract, direct inputs, and dependency outputs",
            "Secrets and absolute workspace paths are excluded",
            "Restore verifies metadata before using outputs"
          ],
          "implementationNotes": [
            "A cache hit may improve speed but cannot waive required checks."
          ],
          "verification": [
            "Repeat an identical build and verify a safe hit.",
            "Change schema, compiler version, and an upstream output independently and require misses."
          ],
          "deliverables": [
            "Canonical cache manifest and invalidation tests"
          ],
          "rollout": "Enable read-only restore before allowing new cache writes.",
          "skills": [
            "Build caching",
            "Hashing",
            "Reproducibility"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Developer tooling",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "bb098876-2ae1-4714-907d-0ad95b9ca0e8",
          "key": "DCI-105",
          "title": "Cancel superseded pull-request runs without erasing evidence",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "control",
          "dependsOn": [
            "DCI-101",
            "DCI-102"
          ],
          "scenario": "A force-push starts a new run while the old run still publishes late check results under the branch name.",
          "acceptanceCriteria": [
            "Concurrency identity binds repository, pull request, and immutable revision",
            "New revision requests cancellation of older active runs",
            "Late results remain tied to their original revision and cannot satisfy the new one"
          ],
          "implementationNotes": [
            "Cancellation is cooperative and must not mark unfinished checks successful."
          ],
          "verification": [
            "Start two revisions and verify only the new one remains eligible.",
            "Deliver a late success from the old run and prove it cannot update the new revision."
          ],
          "deliverables": [
            "Revision-scoped concurrency controller and race test"
          ],
          "rollout": "Canary on the local simulator while recording saved executor time.",
          "skills": [
            "Concurrency control",
            "Immutable revisions"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 60
            },
            {
              "field": "Distributed systems",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "ff85dddf-ed40-42da-8d24-5270d223c7da",
          "key": "DCI-106",
          "title": "Quarantine a flaky test without making it optional forever",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "control",
          "dependsOn": [
            "DCI-101"
          ],
          "scenario": "A timing-sensitive test is retried until it passes, hiding a rising failure rate and extending every pull request.",
          "acceptanceCriteria": [
            "First-attempt and retry outcomes remain separate",
            "Quarantine has owner, reason, expiry, and tracking reference",
            "Expired quarantine fails the policy check"
          ],
          "implementationNotes": [
            "Do not classify a test as flaky from one failure; use the supplied deterministic failure history."
          ],
          "verification": [
            "Quarantine the documented test and keep its outcomes visible.",
            "Expire or omit ownership and confirm the pipeline blocks rather than silently skips."
          ],
          "deliverables": [
            "Quarantine registry, policy check, and trend fixture"
          ],
          "rollout": "Limit quarantine to named tests and review before expiry.",
          "skills": [
            "Flake management",
            "Policy as code",
            "Test analytics"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 60
            },
            {
              "field": "Quality engineering",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "1c7ec037-fade-4156-94de-4e005839fa9b",
          "key": "DCI-107",
          "title": "Prevent untrusted pull requests from receiving release secrets",
          "type": "STORY",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 360,
          "phaseId": "control",
          "dependsOn": [
            "DCI-101",
            "DCI-103"
          ],
          "scenario": "The same reusable workflow handles internal branches and external pull requests, and a broad token is present before trust is evaluated.",
          "acceptanceCriteria": [
            "Trust context is resolved before selecting credentials or privileged jobs",
            "Untrusted revisions receive read-only checkout and no protected environment",
            "Privileged continuation binds the reviewed immutable revision"
          ],
          "implementationNotes": [
            "Use fake secret handles and repository events; never place a credential value in fixtures or logs."
          ],
          "verification": [
            "Run trusted and untrusted event fixtures and compare granted capabilities.",
            "Change the revision after approval and confirm privileged jobs refuse to start."
          ],
          "deliverables": [
            "CI trust-boundary policy and event matrix"
          ],
          "rollout": "Fail closed for ambiguous event provenance.",
          "skills": [
            "CI security",
            "Least privilege",
            "Supply chain"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "3d29f13f-2f66-4bac-8cf2-9e62e0073c36",
          "key": "DCI-108",
          "title": "Measure queue and execution delay separately",
          "type": "CHORE",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "handoff",
          "dependsOn": [
            "DCI-103",
            "DCI-104",
            "DCI-105"
          ],
          "scenario": "The team calls CI slow from total duration, but most delay occurs before an executor starts during the morning burst.",
          "acceptanceCriteria": [
            "Record created, queued, started, and completed timestamps",
            "Report queue, setup, execution, and artifact phases separately",
            "Percentiles retain workload and executor-class dimensions only"
          ],
          "implementationNotes": [
            "Use bounded synthetic dimensions and state the observation window."
          ],
          "verification": [
            "Reconcile phase durations for a mixed local workload.",
            "Omit a timestamp and confirm the run is marked incomplete rather than assigned zero delay."
          ],
          "deliverables": [
            "CI latency model and workload report"
          ],
          "rollout": "Use the baseline before changing runner count or job structure.",
          "skills": [
            "Observability",
            "Latency analysis"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Performance engineering",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "78f78167-a5b2-4761-97d8-b9e4b72bf857",
          "key": "DCI-109",
          "title": "Resume reporting after the checks API loses a response",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 360,
          "phaseId": "handoff",
          "dependsOn": [
            "DCI-105",
            "DCI-108"
          ],
          "scenario": "The fake checks API accepts a final status and drops the response; the reporter retries by creating a second check with conflicting output.",
          "acceptanceCriteria": [
            "One deterministic external-check identity exists per run and check",
            "Retry reconciles remote state before creating anything",
            "Conflicting terminal state becomes visible and stops automation"
          ],
          "implementationNotes": [
            "Provider calls occur outside database transactions and use the local controllable adapter."
          ],
          "verification": [
            "Publish each terminal status once and replay reporting safely.",
            "Drop the response after acceptance and verify reconciliation finds the existing result."
          ],
          "deliverables": [
            "Idempotent check reporter and lost-response drill"
          ],
          "rollout": "Enable for one check family while retaining the prior reporter for rollback.",
          "skills": [
            "Idempotency",
            "API reconciliation",
            "Distributed failure"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 60
            },
            {
              "field": "Integrations",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "0de0c979-9785-4ffb-8199-7d200463f5d8",
          "key": "DCI-110",
          "title": "Hand off CI ownership with a safe degraded mode",
          "type": "BUG",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "handoff",
          "dependsOn": [
            "DCI-106",
            "DCI-107",
            "DCI-108",
            "DCI-109"
          ],
          "scenario": "When the cache or check provider is unavailable, maintainers do not know which failures can fall back and which must block merging.",
          "acceptanceCriteria": [
            "Runbook names owners, dependencies, alerts, and escalation conditions",
            "Cache outage falls back to uncached required checks",
            "Check-reporting uncertainty blocks eligibility while preserving local results"
          ],
          "implementationNotes": [
            "Do not claim merge protection changes; the exercise documents the intended integration contract."
          ],
          "verification": [
            "Rehearse cache loss and complete an uncached run.",
            "Lose final check acknowledgement and follow the block-and-reconcile path."
          ],
          "deliverables": [
            "CI runbook and two recovery rehearsals"
          ],
          "rollout": "Review the runbook with a second engineer before adopting the workflow.",
          "skills": [
            "Runbooks",
            "Degraded operation",
            "Ownership handoff"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Site reliability",
              "percentage": 30
            }
          ],
          "patterns": []
        }
      ],
      "id": "e29698dd-99c6-4977-a933-bae9330a03d6"
    }
  ]
}
