# noCV engineering task library

Content version 5

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.

## BARTIF — Artifact registry promotion controls

A fictional application team deploys mutable image tags and cannot reliably identify the artifact running during an incident.

**Field:** Cloud infrastructure. **Suggested stack:** TypeScript, OCI metadata, JSON.

**Engineer value:** Practice artifact identity, promotion policies, and release provenance.

**Company value:** Provide reproducible deployments and a clear path to withdraw defective artifacts.

**Delivery agreement:** Deliver offline promotion checks and local registry-state rehearsals; perform no real deployment.

### Setup prerequisites

- Author synthetic artifact manifests and a local registry double; do not pull or execute untrusted images.

### Identify immutable artifacts

Capture build identity and provenance.

#### BARTIF-101 — Resolve deployment references to immutable artifact digests

**Task · Medium priority · Foundational**

noCV practice brief v5 · BARTIF-101 · Artifact registry promotion controls

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Identify immutable artifacts. Depends on: No preceding ticket.

Difficulty: Foundational. Estimated focused work: 60 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Developer tooling 40% · Security 40% · Cloud infrastructure 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The same release tag points to different bytes across environments.

Acceptance criteria

- Store the resolved digest with each deployment intent.

- Preserve the human-readable tag as metadata.

- Reject missing or ambiguous digest resolution.

Implementation constraints

- Synthetic registry manifests are sufficient.

Verification

- Resolve a stable release reference.

- Move its tag and detect changed identity.

Deliverables

- Artifact identity model.

Rollout and recovery: Introduce digest recording before enforcing immutable references.

Project prerequisites: Author synthetic artifact manifests and a local registry double; do not pull or execute untrusted images.

Engineer value: Practice artifact identity, promotion policies, and release provenance.

Company value: Provide reproducible deployments and a clear path to withdraw defective artifacts.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BARTIF-102 — Record build inputs without exposing build secrets

**Task · High priority · Intermediate**

noCV practice brief v5 · BARTIF-102 · Artifact registry promotion controls

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Identify immutable artifacts. Depends on: BARTIF-101.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 60% · Developer tooling 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Provenance output includes all build environment variables.

Acceptance criteria

- Record source revision, builder version, and declared inputs.

- Exclude secrets and workstation paths.

- Bind provenance to the exact artifact digest.

Implementation constraints

- Use allowlisted metadata rather than environment dumps.

Verification

- Verify a complete synthetic provenance record.

- Reject mismatched digest and detect seeded secret leakage.

Deliverables

- Provenance manifest.

Rollout and recovery: Block promotion when required provenance is missing.

Project prerequisites: Author synthetic artifact manifests and a local registry double; do not pull or execute untrusted images.

Engineer value: Practice artifact identity, promotion policies, and release provenance.

Company value: Provide reproducible deployments and a clear path to withdraw defective artifacts.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Control promotion

Validate artifact readiness and environment bindings.

#### BARTIF-103 — Reject promotion of artifacts with unresolved policy findings

**Task · High priority · Advanced**

noCV practice brief v5 · BARTIF-103 · Artifact registry promotion controls

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Control promotion. Depends on: BARTIF-102.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 50% · Developer tooling 30% · Cloud infrastructure 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A failed scan is treated like a scan with no findings.

Acceptance criteria

- Distinguish passed, failed, missing, and stale checks.

- Bind check results to artifact and policy versions.

- Keep unresolved required checks blocking.

Implementation constraints

- Fixture scan results are not real vulnerability evidence.

Verification

- Promote a fixture with complete checks.

- Reject unavailable or stale check results.

Deliverables

- Promotion policy evaluator.

Rollout and recovery: Run advisory comparisons before enforcement.

Project prerequisites: Author synthetic artifact manifests and a local registry double; do not pull or execute untrusted images.

Engineer value: Practice artifact identity, promotion policies, and release provenance.

Company value: Provide reproducible deployments and a clear path to withdraw defective artifacts.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BARTIF-104 — Keep environment-specific settings outside immutable application bytes

**Task · Medium priority · Advanced**

noCV practice brief v5 · BARTIF-104 · Artifact registry promotion controls

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Control promotion. Depends on: BARTIF-101, BARTIF-102.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Platform engineering 50% · Cloud infrastructure 50%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The team rebuilds the same release for staging and production, making tested bytes differ from deployed bytes.

Acceptance criteria

- Use one application digest across modeled environments.

- Bind runtime configuration separately.

- Validate required configuration without embedding secrets.

Implementation constraints

- No actual cloud deployment is required.

Verification

- Promote the same digest through two synthetic environments.

- Reject a configuration missing a required setting.

Deliverables

- Artifact/configuration boundary.

Rollout and recovery: Adopt on one service; retain previous configuration versions for recovery.

Project prerequisites: Author synthetic artifact manifests and a local registry double; do not pull or execute untrusted images.

Engineer value: Practice artifact identity, promotion policies, and release provenance.

Company value: Provide reproducible deployments and a clear path to withdraw defective artifacts.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BARTIF-105 — Bind a promotion decision to current environment state

**Bug · High priority · Advanced**

noCV practice brief v5 · BARTIF-105 · Artifact registry promotion controls

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Control promotion. Depends on: BARTIF-103, BARTIF-104.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Platform engineering 50% · Database engineering 30% · Cloud infrastructure 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Two simultaneous promotion requests overwrite each other's intended release.

Acceptance criteria

- Require expected environment revision.

- Record one accepted transition atomically.

- Reject stale decisions without changing active identity.

Implementation constraints

- Use a local state store and explicit transition methods.

Verification

- Promote against the current revision.

- Race two decisions and verify one conflict.

Deliverables

- Optimistic promotion workflow.

Rollout and recovery: Start with serialized local promotion; preserve every prior revision.

Project prerequisites: Author synthetic artifact manifests and a local registry double; do not pull or execute untrusted images.

Engineer value: Practice artifact identity, promotion policies, and release provenance.

Company value: Provide reproducible deployments and a clear path to withdraw defective artifacts.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BARTIF-106 — Handle registry unavailability without changing artifact identity

**Task · High priority · Intermediate**

noCV practice brief v5 · BARTIF-106 · Artifact registry promotion controls

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Control promotion. Depends on: BARTIF-105.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Cloud infrastructure 40% · Site reliability 40% · Security 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A failed digest lookup falls back to the latest cached tag.

Acceptance criteria

- Use cached data only for the exact verified digest.

- Return unavailable for unresolved references.

- Bound fetch retries and response size.

Implementation constraints

- Do not substitute another release during failure.

Verification

- Reuse a verified digest manifest.

- Fail tag resolution during outage without selecting latest.

Deliverables

- Registry failure handling.

Rollout and recovery: Keep current release running in the scenario; retry promotion explicitly.

Project prerequisites: Author synthetic artifact manifests and a local registry double; do not pull or execute untrusted images.

Engineer value: Practice artifact identity, promotion policies, and release provenance.

Company value: Provide reproducible deployments and a clear path to withdraw defective artifacts.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Recover releases

Handle withdrawal, retention, and rollback.

#### BARTIF-107 — Withdraw a defective artifact without deleting incident history

**Task · High priority · Advanced**

noCV practice brief v5 · BARTIF-107 · Artifact registry promotion controls

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Recover releases. Depends on: BARTIF-105.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Platform engineering 40% · Security 40% · Cloud infrastructure 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Deleting a bad image makes historical deployment records impossible to inspect.

Acceptance criteria

- Mark the digest withdrawn with reason and actor.

- Block new promotion of withdrawn artifacts.

- Preserve manifests and prior deployment references.

Implementation constraints

- Withdrawal is append-only state, not evidence deletion.

Verification

- Withdraw a synthetic defective artifact.

- Reject new promotion while retaining historical reads.

Deliverables

- Artifact withdrawal workflow.

Rollout and recovery: Withdraw before cleanup; use a separate approved retention policy.

Project prerequisites: Author synthetic artifact manifests and a local registry double; do not pull or execute untrusted images.

Engineer value: Practice artifact identity, promotion policies, and release provenance.

Company value: Provide reproducible deployments and a clear path to withdraw defective artifacts.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BARTIF-108 — Protect rollback artifacts from registry retention cleanup

**Bug · High priority · Intermediate**

noCV practice brief v5 · BARTIF-108 · Artifact registry promotion controls

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Recover releases. Depends on: BARTIF-107.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Storage systems 40% · Site reliability 30% · Cloud infrastructure 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A cleanup job deletes the last known usable release.

Acceptance criteria

- Retain artifacts referenced by active and rollback revisions.

- Evaluate cleanup from current authoritative references.

- Produce a dry-run deletion set.

Implementation constraints

- Use only local synthetic artifacts.

Verification

- Identify unreferenced eligible artifacts.

- Keep an older digest referenced by a rollback plan.

Deliverables

- Reference-aware retention policy.

Rollout and recovery: Run dry-run review before local deletion.

Project prerequisites: Author synthetic artifact manifests and a local registry double; do not pull or execute untrusted images.

Engineer value: Practice artifact identity, promotion policies, and release provenance.

Company value: Provide reproducible deployments and a clear path to withdraw defective artifacts.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BARTIF-109 — Assess rollback compatibility beyond selecting an older digest

**Task · High priority · Expert**

noCV practice brief v5 · BARTIF-109 · Artifact registry promotion controls

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Recover releases. Depends on: BARTIF-104, BARTIF-108.

Difficulty: Expert. Estimated focused work: 300 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Site reliability 40% · Database engineering 30% · Platform engineering 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

An older image starts successfully but cannot read data written by the new release.

Acceptance criteria

- Bind rollback candidates to schema and configuration compatibility.

- Rehearse representative read/write behavior locally.

- Compare rollback with forward repair when compatibility fails.

Implementation constraints

- Artifact availability alone does not prove recoverability.

Verification

- Restore a compatible synthetic release.

- Reject an incompatible candidate despite its valid digest.

Deliverables

- Rollback compatibility assessment.

Rollout and recovery: Keep compatible artifacts and configuration together; choose forward repair when required.

Project prerequisites: Author synthetic artifact manifests and a local registry double; do not pull or execute untrusted images.

Engineer value: Practice artifact identity, promotion policies, and release provenance.

Company value: Provide reproducible deployments and a clear path to withdraw defective artifacts.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BARTIF-110 — Write an artifact incident lookup guide

**Chore · Low priority · Foundational**

noCV practice brief v5 · BARTIF-110 · Artifact registry promotion controls

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Recover releases. Depends on: BARTIF-109.

Difficulty: Foundational. Estimated focused work: 60 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Site reliability 50% · Developer tooling 30% · Cloud infrastructure 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

On-call staff need to identify source, checks, and prior release from one deployed digest.

Acceptance criteria

- Show lookup from environment revision to artifact.

- Link provenance and policy results by identity.

- Document withdrawn and missing-artifact behavior.

Implementation constraints

- Do not include registry credentials in examples.

Verification

- Trace one synthetic deployment to source inputs.

- Handle a withdrawn artifact without losing history.

Deliverables

- Artifact investigation guide.

Rollout and recovery: Store with promotion tooling and update when manifest schema changes.

Project prerequisites: Author synthetic artifact manifests and a local registry double; do not pull or execute untrusted images.

Engineer value: Practice artifact identity, promotion policies, and release provenance.

Company value: Provide reproducible deployments and a clear path to withdraw defective artifacts.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.
