# noCV engineering task library

Content version 5

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.

## AIMAGE — Harden a service image build and promotion workflow

A fictional reporting API is rebuilt separately for staging and production. Different dependency resolutions and mutable tags make incident rollback unreliable.

**Field:** Platform engineering. **Suggested stack:** OCI image tools, TypeScript, CI.

**Engineer value:** Practice artifact identity, least privilege and reproducible delivery.

**Company value:** Review whether deployed bytes can be traced and rolled back reliably.

**Delivery agreement:** Ten scoped tickets across three phases. Build a synthetic local service or select a ticket after recreating its prerequisites; estimates exclude setup.

### Setup prerequisites

- Create a tiny local HTTP service and nonprivileged image build.

- Use synthetic registries or provider fixtures; no production deployment.

### Constrain image construction

Pin inputs and limit build context.

#### AIMAGE-101 — Exclude local credentials and bulky artifacts from the image context

**Bug · High priority · Foundational**

noCV practice brief v5 · AIMAGE-101 · Harden a service image build and promotion workflow

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Constrain image construction. Depends on: No preceding ticket.

Difficulty: Foundational. Estimated focused work: 75 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 50% · Platform engineering 30% · Developer tooling 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A developer notices an environment file and test recordings copied into the service image.

Acceptance criteria

- Allow only required source and build inputs into context.

- Exclude environment files, VCS metadata and generated recordings.

- Add a safe inspection command that lists included paths.

Implementation constraints

- Create fake secrets for tests; never scan or print real secret values.

Verification

- Build a minimal synthetic service context.

- Add a fake credential file and verify it is absent from context and image.

Deliverables

- Context allowlist and image-content check

Rollout and recovery: Apply before the next image build; discard affected disposable images.

Project prerequisites: Create a tiny local HTTP service and nonprivileged image build. Use synthetic registries or provider fixtures; no production deployment.

Engineer value: Practice artifact identity, least privilege and reproducible delivery.

Company value: Review whether deployed bytes can be traced and rolled back reliably.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AIMAGE-102 — Pin service build inputs to immutable identities

**Task · Medium priority · Foundational**

noCV practice brief v5 · AIMAGE-102 · Harden a service image build and promotion workflow

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Constrain image construction. Depends on: AIMAGE-101.

Difficulty: Foundational. Estimated focused work: 90 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Platform engineering 70% · Developer tooling 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A rebuild of an old commit picks up a newer base image and no longer reproduces the original runtime.

Acceptance criteria

- Pin the base image digest and dependency lockfile.

- Record compiler and build-tool versions.

- Fail the build when frozen dependency resolution changes the lockfile.

Implementation constraints

- Document the update procedure rather than permanently freezing vulnerabilities.

Verification

- Build twice from identical named inputs and compare artifact metadata.

- Change a pinned input and require a new provenance record.

Deliverables

- Pinned build definition

Rollout and recovery: Introduce pinned builds for new artifacts; retain old digest references for rollback.

Project prerequisites: Create a tiny local HTTP service and nonprivileged image build. Use synthetic registries or provider fixtures; no production deployment.

Engineer value: Practice artifact identity, least privilege and reproducible delivery.

Company value: Review whether deployed bytes can be traced and rolled back reliably.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AIMAGE-103 — Run the service image as an unprivileged user with a read-only root

**Task · Medium priority · Intermediate**

noCV practice brief v5 · AIMAGE-103 · Harden a service image build and promotion workflow

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Constrain image construction. Depends on: AIMAGE-101, AIMAGE-102.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 60% · Platform engineering 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The API image starts as root and writes temporary report files into the application directory.

Acceptance criteria

- Use a non-root runtime user.

- Keep the base filesystem read-only with an explicit temporary directory.

- Reject startup when required writable storage is unavailable.

Implementation constraints

- No privileged mode, host mounts, host networking or container-engine socket.

Verification

- Serve a request under the restricted runtime configuration.

- Attempt a write to the application directory and verify denial.

Deliverables

- Restricted runtime definition and filesystem probe

Rollout and recovery: Canary the restricted image locally; stop rollout if required writes lack an explicit temporary path.

Project prerequisites: Create a tiny local HTTP service and nonprivileged image build. Use synthetic registries or provider fixtures; no production deployment.

Engineer value: Practice artifact identity, least privilege and reproducible delivery.

Company value: Review whether deployed bytes can be traced and rolled back reliably.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Promote exact artifacts

Validate artifacts and preserve provenance.

#### AIMAGE-104 — Record image provenance without embedding build credentials

**Story · Medium priority · Intermediate**

noCV practice brief v5 · AIMAGE-104 · Harden a service image build and promotion workflow

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Promote exact artifacts. Depends on: AIMAGE-102, AIMAGE-103.

Difficulty: Intermediate. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Platform engineering 60% · Security 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Operations can see a tag but cannot trace it to source revision, dependency lock hash or build run.

Acceptance criteria

- Record source revision, input hashes and final image digest.

- Associate provenance with the exact artifact digest.

- Exclude environment values and registry tokens.

Implementation constraints

- Use a local provenance document for this exercise.

Verification

- Resolve a built digest to its source and lockfile hashes.

- Alter provenance digest and reject the mismatch.

Deliverables

- Artifact provenance manifest and verification command

Rollout and recovery: Attach provenance to new builds; refuse promotion when it cannot be verified.

Project prerequisites: Create a tiny local HTTP service and nonprivileged image build. Use synthetic registries or provider fixtures; no production deployment.

Engineer value: Practice artifact identity, least privilege and reproducible delivery.

Company value: Review whether deployed bytes can be traced and rolled back reliably.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AIMAGE-105 — Promote the tested digest instead of rebuilding for each environment

**Story · High priority · Advanced**

noCV practice brief v5 · AIMAGE-105 · Harden a service image build and promotion workflow

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Promote exact artifacts. Depends on: AIMAGE-104.

Difficulty: Advanced. Estimated focused work: 210 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Platform engineering 100%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The staging build passes, but production rebuilds the same commit with different transitive dependencies.

Acceptance criteria

- Promotion selects the exact tested digest.

- Separate runtime configuration from artifact construction.

- Reject a tag that resolves to a different digest at promotion.

Implementation constraints

- Model registries through a testable provider interface.

Verification

- Promote a tested synthetic digest through two environments.

- Move a mutable tag and verify promotion rejects the changed artifact.

Deliverables

- Digest promotion command and tag-race regression

Rollout and recovery: Canary promotion metadata; restore the previously selected digest if validation fails.

Project prerequisites: Create a tiny local HTTP service and nonprivileged image build. Use synthetic registries or provider fixtures; no production deployment.

Engineer value: Practice artifact identity, least privilege and reproducible delivery.

Company value: Review whether deployed bytes can be traced and rolled back reliably.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AIMAGE-106 — Stop promotion when required security scan results are missing

**Task · Medium priority · Advanced**

noCV practice brief v5 · AIMAGE-106 · Harden a service image build and promotion workflow

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Promote exact artifacts. Depends on: AIMAGE-104, AIMAGE-105.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 60% · Platform engineering 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A scan service times out and the build pipeline treats absence of findings as a clean result.

Acceptance criteria

- Represent passed, failed and unavailable scan states distinctly.

- Require scan policy and artifact digest to match.

- Unavailable required results block promotion with a retry path.

Implementation constraints

- Use synthetic scan responses; do not claim current vulnerability coverage.

Verification

- Promote with matching passed policy results.

- Timeout or return a different digest and verify promotion remains blocked.

Deliverables

- Scan-result gate and unavailable-state tests

Rollout and recovery: Run the gate before environment selection; retry scans without rebuilding the artifact.

Project prerequisites: Create a tiny local HTTP service and nonprivileged image build. Use synthetic registries or provider fixtures; no production deployment.

Engineer value: Practice artifact identity, least privilege and reproducible delivery.

Company value: Review whether deployed bytes can be traced and rolled back reliably.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AIMAGE-107 — Make artifact promotion idempotent across lost CI responses

**Bug · Medium priority · Expert**

noCV practice brief v5 · AIMAGE-107 · Harden a service image build and promotion workflow

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Promote exact artifacts. Depends on: AIMAGE-105, AIMAGE-106.

Difficulty: Expert. Estimated focused work: 300 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Platform engineering 60% · Database engineering 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A CI runner loses the promotion response and retries, creating competing rollout records for one digest.

Acceptance criteria

- Use a stable promotion key bound to environment and digest.

- Retries resolve one durable promotion record.

- Changed digest under the same key returns conflict.

Implementation constraints

- Persist selection and audit metadata atomically.

Verification

- Drop a response after commit and retry the same selection.

- Reuse a promotion key for another digest and retain the original selection.

Deliverables

- Idempotent promotion command

Rollout and recovery: Enable for synthetic environments; pause conflicting promotions and retain their audit records.

Project prerequisites: Create a tiny local HTTP service and nonprivileged image build. Use synthetic registries or provider fixtures; no production deployment.

Engineer value: Practice artifact identity, least privilege and reproducible delivery.

Company value: Review whether deployed bytes can be traced and rolled back reliably.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Recover artifact failures

Retain usable revisions and rehearse rollback.

#### AIMAGE-108 — Retain rollback images without deleting active environment digests

**Chore · Medium priority · Intermediate**

noCV practice brief v5 · AIMAGE-108 · Harden a service image build and promotion workflow

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Recover artifact failures. Depends on: AIMAGE-105, AIMAGE-107.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Platform engineering 60% · Storage systems 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Registry cleanup removes an image still running in a quiet environment because its tag is old.

Acceptance criteria

- Retention protects every active and explicitly retained rollback digest.

- Compute deletion candidates before executing cleanup.

- Recheck references immediately before removal.

Implementation constraints

- Use exact digest references rather than tag age alone.

Verification

- Expire an unreferenced synthetic image.

- Add an active reference after planning and verify deletion is skipped.

Deliverables

- Digest retention planner and race test

Rollout and recovery: Dry-run retention first; stop cleanup if environment inventory is unavailable.

Project prerequisites: Create a tiny local HTTP service and nonprivileged image build. Use synthetic registries or provider fixtures; no production deployment.

Engineer value: Practice artifact identity, least privilege and reproducible delivery.

Company value: Review whether deployed bytes can be traced and rolled back reliably.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AIMAGE-109 — Rehearse rollback when the new image cannot read existing data

**Task · Medium priority · Expert**

noCV practice brief v5 · AIMAGE-109 · Harden a service image build and promotion workflow

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Recover artifact failures. Depends on: AIMAGE-107, AIMAGE-108.

Difficulty: Expert. Estimated focused work: 360 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Platform engineering 60% · Database engineering 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A new runtime starts successfully but fails on records created by the previous release.

Acceptance criteria

- Declare compatibility expectations for stored data.

- Route back to the retained old digest without rebuilding.

- Identify any irreversible schema step that blocks binary rollback.

Implementation constraints

- Use a synthetic compatibility fixture and local runtime only.

Verification

- Roll out a compatible image and restore its predecessor.

- Trigger a schema incompatibility and stop automatic rollback with an explicit recovery decision.

Deliverables

- Rollback drill and compatibility matrix

Rollout and recovery: Run the drill before promotion; block releases without a viable declared recovery path.

Project prerequisites: Create a tiny local HTTP service and nonprivileged image build. Use synthetic registries or provider fixtures; no production deployment.

Engineer value: Practice artifact identity, least privilege and reproducible delivery.

Company value: Review whether deployed bytes can be traced and rolled back reliably.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### AIMAGE-110 — Publish a release inventory that resolves environments to exact bytes

**Task · Medium priority · Foundational**

noCV practice brief v5 · AIMAGE-110 · Harden a service image build and promotion workflow

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Recover artifact failures. Depends on: AIMAGE-104, AIMAGE-108, AIMAGE-109.

Difficulty: Foundational. Estimated focused work: 90 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Platform engineering 60% · Site reliability 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Incident responders receive three different tag names for what appears to be the same release.

Acceptance criteria

- List environment, selected digest and provenance identity.

- Show requested selection separately from observed running digest.

- Mark missing observations as unknown.

Implementation constraints

- Omit registry credentials and private build output.

Verification

- Resolve two aliases to the same artifact digest.

- Remove runtime observation and display unknown rather than deployed.

Deliverables

- Release inventory projection

Rollout and recovery: Publish read-only inventory first; repair stale observations without changing selections.

Project prerequisites: Create a tiny local HTTP service and nonprivileged image build. Use synthetic registries or provider fixtures; no production deployment.

Engineer value: Practice artifact identity, least privilege and reproducible delivery.

Company value: Review whether deployed bytes can be traced and rolled back reliably.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.
