{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "key": "DENV",
      "title": "Keep environment configuration explicit and recoverable",
      "field": "DevOps",
      "summary": "Validate configuration, secret references, feature changes, and drift without copying sensitive values.",
      "context": "A fictional notification service uses environment files assembled by shell scripts. Defaults differ by machine, secret values appear in diagnostics, and emergency flags have no expiry. Build a typed local configuration compiler with fake secret references and synthetic environments; no real credentials or notification providers are supplied.",
      "stack": [
        "TypeScript",
        "JSON Schema",
        "Secret adapter",
        "Vitest"
      ],
      "prerequisites": [
        "Configuration precedence",
        "Schema validation",
        "Least privilege"
      ],
      "developerValue": "Practice configuration as a reviewed contract with safe diagnostics, provenance, and rollback.",
      "companyValue": "Review environment changes before deployment and reduce outages caused by missing, stale, or silently defaulted settings.",
      "delivery": "Ten linked tickets across three phases. Use a local repository and fake providers; deliver workflow code, failure tests, a rollback rehearsal, and a concise runbook.",
      "phases": [
        {
          "id": "baseline",
          "title": "Make the delivery contract visible",
          "goal": "Replace implicit workflow assumptions with reviewable inputs and outcomes."
        },
        {
          "id": "control",
          "title": "Control change and failure",
          "goal": "Add bounded concurrency, authority checks, and restart-safe transitions."
        },
        {
          "id": "handoff",
          "title": "Operate and improve",
          "goal": "Measure the workflow, rehearse recovery, and document ownership."
        }
      ],
      "tickets": [
        {
          "id": "50ae3a4a-f042-4401-b70e-448207316740",
          "key": "DENV-101",
          "title": "Define precedence without depending on process order",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "baseline",
          "dependsOn": [],
          "scenario": "Local, environment, and command-line values are merged in object iteration order, so the same inputs produce different ports in two scripts.",
          "acceptanceCriteria": [
            "Declare precedence for base, environment, and explicit override layers",
            "Each resolved value retains its source layer",
            "Duplicate keys within one layer fail parsing"
          ],
          "implementationNotes": [
            "Do not read the host process environment directly in domain tests."
          ],
          "verification": [
            "Resolve the same layers in shuffled input order and compare output.",
            "Provide duplicate keys and confirm no partial configuration is returned."
          ],
          "deliverables": [
            "Layered configuration resolver and precedence tests"
          ],
          "rollout": "Generate a report beside the current scripts before switching consumers.",
          "skills": [
            "Configuration modeling",
            "Determinism"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Platform engineering",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "fd85c697-6042-43c2-9517-e680ad0218fe",
          "key": "DENV-102",
          "title": "Reject missing required values before service startup",
          "type": "BUG",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "baseline",
          "dependsOn": [
            "DENV-101"
          ],
          "scenario": "The service starts with an empty callback base URL and fails only when the first delivery completes.",
          "acceptanceCriteria": [
            "Schema distinguishes required, optional, and defaulted values",
            "Validation reports all safe field errors together",
            "Invalid configuration prevents provider initialization"
          ],
          "implementationNotes": [
            "Defaults must be explicit in the versioned schema and safe for every environment that uses them."
          ],
          "verification": [
            "Validate complete development and production-like fixture configurations.",
            "Remove several required fields and confirm providers are never constructed."
          ],
          "deliverables": [
            "Typed configuration schema and startup tests"
          ],
          "rollout": "Run validation as a pre-deployment gate before enforcing it at startup.",
          "skills": [
            "Schema validation",
            "Fail-closed startup"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Quality engineering",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "cc79eaf8-c3d3-4af7-8a0e-09941862f440",
          "key": "DENV-103",
          "title": "Keep secret values out of configuration diffs",
          "type": "STORY",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "baseline",
          "dependsOn": [
            "DENV-102"
          ],
          "scenario": "A deployment preview serializes the fully resolved configuration, including a fake API token value, into the job log.",
          "acceptanceCriteria": [
            "Configuration stores secret references separately from ordinary values",
            "Diffs show reference identity and version without secret content",
            "Errors and snapshots redact values even when resolution fails"
          ],
          "implementationNotes": [
            "Use sentinel fake secrets and assert they never appear in output."
          ],
          "verification": [
            "Diff two configurations with changed secret references.",
            "Make resolution fail with a sentinel value in the provider error and verify redaction."
          ],
          "deliverables": [
            "Secret-reference model and log-leak tests"
          ],
          "rollout": "Remove full resolved-config logging before connecting any nonfixture provider.",
          "skills": [
            "Secret handling",
            "Redaction",
            "Data minimization"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "a22eb550-482f-4483-ba88-095fb3c617dd",
          "key": "DENV-104",
          "title": "Validate cross-field configuration invariants",
          "type": "CHORE",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "control",
          "dependsOn": [
            "DENV-102"
          ],
          "scenario": "Retries are enabled while the idempotency store is disabled, creating duplicate notification attempts after timeouts.",
          "acceptanceCriteria": [
            "Cross-field rules run after individual field validation",
            "Retry requires a compatible idempotency mode and positive deadline",
            "Errors identify involved settings without exposing values"
          ],
          "implementationNotes": [
            "Keep invariants centralized and versioned rather than scattered among service constructors."
          ],
          "verification": [
            "Validate supported retry and store combinations.",
            "Enable retry with no store and with a shorter operation deadline than backoff."
          ],
          "deliverables": [
            "Configuration invariant set and combination matrix"
          ],
          "rollout": "Evaluate current environment fixtures and resolve all violations before enforcement.",
          "skills": [
            "Invariant design",
            "Configuration testing"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Distributed systems",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "e32acfa6-f854-48c9-838f-0a07a42325d0",
          "key": "DENV-105",
          "title": "Require expiry and ownership for emergency feature overrides",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "control",
          "dependsOn": [
            "DENV-101",
            "DENV-103"
          ],
          "scenario": "A disable-delivery flag added during a rehearsal remains set for weeks because its reason and owner exist only in chat.",
          "acceptanceCriteria": [
            "Override records owner, reason, scope, creation, and expiry",
            "Expired override fails compilation instead of remaining active",
            "Normal configuration remains visible beneath the override"
          ],
          "implementationNotes": [
            "Use synthetic operator identities; flags do not bypass authorization or audit."
          ],
          "verification": [
            "Apply an active scoped override and show its provenance.",
            "Compile expired and ownerless overrides and confirm blocking errors."
          ],
          "deliverables": [
            "Expiring override registry and policy tests"
          ],
          "rollout": "Introduce reporting before rejecting legacy unowned fixture flags.",
          "skills": [
            "Feature flags",
            "Operational governance",
            "Time modeling"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Site reliability",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "7a53d86d-61aa-4611-acd4-d51cd73b3028",
          "key": "DENV-106",
          "title": "Promote configuration by immutable revision",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "control",
          "dependsOn": [
            "DENV-103",
            "DENV-104"
          ],
          "scenario": "A mutable environment file changes after approval but before deployment, so the applied settings were never reviewed.",
          "acceptanceCriteria": [
            "Compilation produces canonical content and immutable revision hash",
            "Approval and deployment bind the exact revision",
            "Any source-layer change produces a new revision"
          ],
          "implementationNotes": [
            "Exclude secret values while binding secret reference identities and schema version."
          ],
          "verification": [
            "Approve and deploy one unchanged revision.",
            "Edit a source layer after approval and verify deployment refuses the stale authorization."
          ],
          "deliverables": [
            "Immutable configuration revision and approval-binding tests"
          ],
          "rollout": "Use revision identities in the local deployment simulator before removing mutable file reads.",
          "skills": [
            "Content hashing",
            "Immutable configuration",
            "Authorization"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Security",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "0f479a4a-f9ef-4f79-bac3-b24fc8210b37",
          "key": "DENV-107",
          "title": "Resolve secret rotation without restarting into a mixed revision",
          "type": "STORY",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 360,
          "phaseId": "control",
          "dependsOn": [
            "DENV-103",
            "DENV-106"
          ],
          "scenario": "Two secret references rotate independently while workers reload, leaving some requests signed with mismatched key and certificate versions.",
          "acceptanceCriteria": [
            "Dependent secret references resolve as one declared bundle revision",
            "Reload publishes only a fully validated immutable snapshot",
            "In-flight work retains its starting snapshot until completion"
          ],
          "implementationNotes": [
            "Fake secret material stays inside the local adapter and is never included in generic configuration hashes."
          ],
          "verification": [
            "Rotate a complete bundle while old and new operations overlap.",
            "Withhold one member and confirm no worker selects the partial revision."
          ],
          "deliverables": [
            "Secret-bundle reload protocol and overlap test"
          ],
          "rollout": "Keep restart-based rotation available until snapshot reload is proven.",
          "skills": [
            "Secret rotation",
            "Atomic publication",
            "Concurrency"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 65
            },
            {
              "field": "Security",
              "percentage": 35
            }
          ],
          "patterns": []
        },
        {
          "id": "d18f6f9d-bb43-4a43-8eb2-b1b9106a65fa",
          "key": "DENV-108",
          "title": "Detect environment drift without copying secret data",
          "type": "CHORE",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "handoff",
          "dependsOn": [
            "DENV-106"
          ],
          "scenario": "A local environment's retry count is changed outside the compiler, but drift reports are disabled because teams fear dumping secrets.",
          "acceptanceCriteria": [
            "Compare ordinary canonical values and secret reference identities",
            "Report missing, extra, and changed paths with provenance",
            "Secret values and provider error bodies are never serialized"
          ],
          "implementationNotes": [
            "Observed configuration comes from a bounded fake runtime projection."
          ],
          "verification": [
            "Detect changes in an ordinary value and a secret reference version.",
            "Return a sentinel secret in observed input and prove it cannot enter the report."
          ],
          "deliverables": [
            "Redacted drift detector and fixture report"
          ],
          "rollout": "Begin in read-only mode and resolve unexplained differences before automation.",
          "skills": [
            "Drift detection",
            "Redaction",
            "Reconciliation"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Platform engineering",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "3484f07b-c47f-49d6-bb40-ed42bb62829e",
          "key": "DENV-109",
          "title": "Roll back configuration without rolling back application code",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 360,
          "phaseId": "handoff",
          "dependsOn": [
            "DENV-106",
            "DENV-107",
            "DENV-108"
          ],
          "scenario": "A new timeout revision overloads the fake provider, but the only recovery script redeploys the entire previous application artifact.",
          "acceptanceCriteria": [
            "Rollback selects a prior compatible configuration revision",
            "Compatibility is checked against the current application contract",
            "History retains failed and restored revisions plus observed outcome"
          ],
          "implementationNotes": [
            "Rollback never mutates a historical revision or reuses its approval for another environment."
          ],
          "verification": [
            "Deploy a bad timeout revision and restore the prior compatible configuration.",
            "Choose a revision requiring an older schema and block rollback with an actionable result."
          ],
          "deliverables": [
            "Configuration rollback command and recovery rehearsal"
          ],
          "rollout": "Maintain one known-compatible revision for each simulated environment.",
          "skills": [
            "Configuration rollback",
            "Compatibility",
            "Incident recovery"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 60
            },
            {
              "field": "Site reliability",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "9a0fc31a-43b5-49bb-b19c-c7a37c31d4c4",
          "key": "DENV-110",
          "title": "Publish the environment contract for service owners",
          "type": "BUG",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "handoff",
          "dependsOn": [
            "DENV-105",
            "DENV-108",
            "DENV-109"
          ],
          "scenario": "New owners know variable names but not which settings can change independently, which require restart, or how failure appears.",
          "acceptanceCriteria": [
            "Reference lists type, source, default, sensitivity, reload behavior, and owner",
            "Cross-field invariants and rollback compatibility are linked",
            "Examples use synthetic values and secret references only"
          ],
          "implementationNotes": [
            "Generated reference comes from the same schema used by validation."
          ],
          "verification": [
            "Generate and review documentation for every current field.",
            "Add an undocumented schema field and make the consistency test fail."
          ],
          "deliverables": [
            "Generated environment reference and owner runbook"
          ],
          "rollout": "Require schema and documentation consistency in CI.",
          "skills": [
            "Documentation generation",
            "Service ownership"
          ],
          "fieldMix": [
            {
              "field": "DevOps",
              "percentage": 70
            },
            {
              "field": "Developer tooling",
              "percentage": 30
            }
          ],
          "patterns": []
        }
      ],
      "id": "ba88d4b3-eed6-4979-9779-616d422eccc6"
    }
  ]
}
