# noCV engineering task library

Content version 5

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.

## BIAC — Reviewable infrastructure plan pipeline

A fictional application team manages a small database, cache, and object store. Reviewers struggle to distinguish harmless configuration changes from destructive replacements.

**Field:** Cloud infrastructure. **Suggested stack:** TypeScript, Terraform plan JSON, Policy fixtures.

**Engineer value:** Practice infrastructure risk analysis, plan integrity, and least-privilege change workflows.

**Company value:** Give infrastructure reviewers concrete change scope and recovery consequences.

**Delivery agreement:** Deliver an offline plan-review tool and synthetic workflow; provision nothing externally.

### Setup prerequisites

- Author synthetic infrastructure plans and state snapshots; use local files only and no cloud credentials.

### Parse plan authority

Normalize resource actions and unknown values.

#### BIAC-101 — Normalize infrastructure resource actions for review

**Task · Medium priority · Foundational**

noCV practice brief v5 · BIAC-101 · Reviewable infrastructure plan pipeline

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Parse plan authority. Depends on: No preceding ticket.

Difficulty: Foundational. Estimated focused work: 60 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Cloud infrastructure 70% · Developer tooling 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Review summaries collapse updates and replacements into one change count.

Acceptance criteria

- Separate create, update, replace, and delete actions.

- Preserve resource addresses and dependencies.

- Represent unknown values explicitly.

Implementation constraints

- Treat plan JSON as untrusted data.

Verification

- Parse a valid mixed-action plan.

- Reject malformed action combinations.

Deliverables

- Plan action model.

Rollout and recovery: Adopt read-only summaries before any execution integration.

Project prerequisites: Author synthetic infrastructure plans and state snapshots; use local files only and no cloud credentials.

Engineer value: Practice infrastructure risk analysis, plan integrity, and least-privilege change workflows.

Company value: Give infrastructure reviewers concrete change scope and recovery consequences.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIAC-102 — Redact sensitive plan values while preserving review context

**Task · High priority · Intermediate**

noCV practice brief v5 · BIAC-102 · Reviewable infrastructure plan pipeline

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Parse plan authority. Depends on: BIAC-101.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 60% · Cloud infrastructure 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A database password appears in a generated review report.

Acceptance criteria

- Honor sensitive markers recursively.

- Remove seeded secret values from report and errors.

- Keep resource identity and action visible.

Implementation constraints

- Unknown nested formats must fail safely.

Verification

- Review a non-sensitive change.

- Seed secrets in nested arrays and verify redaction.

Deliverables

- Plan redaction boundary.

Rollout and recovery: Block report publication if redaction validation fails.

Project prerequisites: Author synthetic infrastructure plans and state snapshots; use local files only and no cloud credentials.

Engineer value: Practice infrastructure risk analysis, plan integrity, and least-privilege change workflows.

Company value: Give infrastructure reviewers concrete change scope and recovery consequences.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Review risk

Surface destructive changes and policy failures.

#### BIAC-103 — Flag replacements of persistent resources with recovery requirements

**Task · High priority · Advanced**

noCV practice brief v5 · BIAC-103 · Reviewable infrastructure plan pipeline

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Review risk. Depends on: BIAC-101, BIAC-102.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Cloud infrastructure 50% · Site reliability 50%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A small naming change replaces the database resource.

Acceptance criteria

- Identify persistent resource replacements.

- Require declared backup and restore context.

- Show dependent application impact.

Implementation constraints

- Do not infer that a snapshot policy proves restorability.

Verification

- Flag a synthetic database replacement.

- Allow a stateless replacement with its distinct risk classification.

Deliverables

- Replacement risk rule.

Rollout and recovery: Require review before any persistent-resource execution path.

Project prerequisites: Author synthetic infrastructure plans and state snapshots; use local files only and no cloud credentials.

Engineer value: Practice infrastructure risk analysis, plan integrity, and least-privilege change workflows.

Company value: Give infrastructure reviewers concrete change scope and recovery consequences.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIAC-104 — Reject public exposure introduced by default configuration

**Bug · High priority · Advanced**

noCV practice brief v5 · BIAC-104 · Reviewable infrastructure plan pipeline

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Review risk. Depends on: BIAC-102.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 70% · Cloud infrastructure 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

An omitted access setting turns a private storage resource public.

Acceptance criteria

- Evaluate effective exposure including defaults.

- Identify the exact field causing exposure.

- Keep unknown defaults unresolved.

Implementation constraints

- Use explicit provider-schema fixtures rather than live provider assumptions.

Verification

- Detect a public-access transition.

- Keep unknown provider behavior blocked for review.

Deliverables

- Exposure policy check.

Rollout and recovery: Start with the modeled resource types; reject unsupported exposure analysis.

Project prerequisites: Author synthetic infrastructure plans and state snapshots; use local files only and no cloud credentials.

Engineer value: Practice infrastructure risk analysis, plan integrity, and least-privilege change workflows.

Company value: Give infrastructure reviewers concrete change scope and recovery consequences.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIAC-105 — Validate backup retention changes against declared recovery policy

**Task · High priority · Intermediate**

noCV practice brief v5 · BIAC-105 · Reviewable infrastructure plan pipeline

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Review risk. Depends on: BIAC-103.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Site reliability 60% · Cloud infrastructure 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A retention reduction removes the recovery window the application team relies on.

Acceptance criteria

- Compare proposed retention with the scenario requirement.

- Account for deletion of old backup generations.

- Require an explanation for incompatible changes.

Implementation constraints

- Policy requirements are explicit inputs.

Verification

- Accept a compatible retention update.

- Flag a shorter recovery window and missing policy.

Deliverables

- Retention plan rule.

Rollout and recovery: Review changes alongside the restore rehearsal record.

Project prerequisites: Author synthetic infrastructure plans and state snapshots; use local files only and no cloud credentials.

Engineer value: Practice infrastructure risk analysis, plan integrity, and least-privilege change workflows.

Company value: Give infrastructure reviewers concrete change scope and recovery consequences.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Bind execution intent

Verify freshness, ownership, and recovery information.

#### BIAC-106 — Detect plan drift between review and execution

**Task · High priority · Advanced**

noCV practice brief v5 · BIAC-106 · Reviewable infrastructure plan pipeline

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Bind execution intent. Depends on: BIAC-104, BIAC-105.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Cloud infrastructure 50% · Security 30% · Developer tooling 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A plan is reviewed, then regenerated with additional deletions before execution.

Acceptance criteria

- Bind approval intent to plan digest and target identity.

- Check state serial and configuration revision.

- Reject modified or stale plans.

Implementation constraints

- No actual cloud apply is performed in this exercise.

Verification

- Accept an unchanged synthetic reviewed plan.

- Change one action and reject the execution intent.

Deliverables

- Plan binding verifier.

Rollout and recovery: Require regeneration and review on drift; preserve prior plan artifacts.

Project prerequisites: Author synthetic infrastructure plans and state snapshots; use local files only and no cloud credentials.

Engineer value: Practice infrastructure risk analysis, plan integrity, and least-privilege change workflows.

Company value: Give infrastructure reviewers concrete change scope and recovery consequences.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIAC-107 — Keep infrastructure workspace identities from crossing environments

**Bug · High priority · Intermediate**

noCV practice brief v5 · BIAC-107 · Reviewable infrastructure plan pipeline

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Bind execution intent. Depends on: BIAC-106.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Cloud infrastructure 60% · Security 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A staging plan is accidentally paired with production target metadata.

Acceptance criteria

- Bind workspace, account class, and resource namespace.

- Reject mixed-environment inputs.

- Show sanitized target context in the review summary.

Implementation constraints

- Use fictional account identities and no credentials.

Verification

- Verify a matching staging plan.

- Reject a production identity substituted after review.

Deliverables

- Environment binding guard.

Rollout and recovery: Fail closed on ambiguous identity.

Project prerequisites: Author synthetic infrastructure plans and state snapshots; use local files only and no cloud credentials.

Engineer value: Practice infrastructure risk analysis, plan integrity, and least-privilege change workflows.

Company value: Give infrastructure reviewers concrete change scope and recovery consequences.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIAC-108 — Model partial apply recovery without assuming atomic infrastructure changes

**Task · High priority · Expert**

noCV practice brief v5 · BIAC-108 · Reviewable infrastructure plan pipeline

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Bind execution intent. Depends on: BIAC-103, BIAC-106, BIAC-107.

Difficulty: Expert. Estimated focused work: 300 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Cloud infrastructure 40% · System design 30% · Site reliability 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A plan contains several resource updates, and the third may fail after earlier changes succeed.

Acceptance criteria

- Identify dependency-ordered partial states.

- Compare forward repair and rollback per resource.

- Preserve completed changes in the recovery record.

Implementation constraints

- Do not present infrastructure apply as one database transaction.

Verification

- Simulate failure after two accepted changes.

- Reject a rollback that would delete newly authoritative data.

Deliverables

- Partial-apply recovery decision record.

Rollout and recovery: Keep execution hypothetical until target-specific recovery is verified.

Project prerequisites: Author synthetic infrastructure plans and state snapshots; use local files only and no cloud credentials.

Engineer value: Practice infrastructure risk analysis, plan integrity, and least-privilege change workflows.

Company value: Give infrastructure reviewers concrete change scope and recovery consequences.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIAC-109 — Generate an infrastructure change summary for application owners

**Story · Medium priority · Intermediate**

noCV practice brief v5 · BIAC-109 · Reviewable infrastructure plan pipeline

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Bind execution intent. Depends on: BIAC-108.

Difficulty: Intermediate. Estimated focused work: 120 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Cloud infrastructure 70% · Developer tooling 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Application owners cannot determine whether a plan changes endpoints or causes downtime.

Acceptance criteria

- Summarize connectivity, storage, and availability impacts.

- Link impacts to exact resource actions.

- List unresolved values and required follow-up.

Implementation constraints

- Do not hide unresolved risks behind an overall green status.

Verification

- Explain a cache replacement and endpoint change.

- Show unknown replacement timing explicitly.

Deliverables

- Owner review report.

Rollout and recovery: Attach reports to the exact plan digest.

Project prerequisites: Author synthetic infrastructure plans and state snapshots; use local files only and no cloud credentials.

Engineer value: Practice infrastructure risk analysis, plan integrity, and least-privilege change workflows.

Company value: Give infrastructure reviewers concrete change scope and recovery consequences.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIAC-110 — Document how to retire a policy exception

**Chore · Low priority · Foundational**

noCV practice brief v5 · BIAC-110 · Reviewable infrastructure plan pipeline

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Bind execution intent. Depends on: BIAC-109.

Difficulty: Foundational. Estimated focused work: 60 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 60% · Cloud infrastructure 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A temporary public-access exception remains active after the migration finishes.

Acceptance criteria

- Require owner, scope, reason, and expiry.

- Reject expired or wildcard exceptions.

- Preserve exception history after retirement.

Implementation constraints

- Exceptions cannot bypass plan identity checks.

Verification

- Retire a scoped synthetic exception.

- Verify an expired exception blocks the next plan.

Deliverables

- Exception lifecycle guide.

Rollout and recovery: Inventory exceptions before enabling enforcement.

Project prerequisites: Author synthetic infrastructure plans and state snapshots; use local files only and no cloud credentials.

Engineer value: Practice infrastructure risk analysis, plan integrity, and least-privilege change workflows.

Company value: Give infrastructure reviewers concrete change scope and recovery consequences.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.
