# noCV engineering task library

Content version 5

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.

## BIDENT — Workload identity credential rotation

A fictional export worker shares a long-lived object-store credential across environments. The team needs a provider-neutral identity boundary with safe expiry and revocation.

**Field:** Cloud infrastructure. **Suggested stack:** TypeScript, JWT, HTTP.

**Engineer value:** Practice workload identity, audience restrictions, and credential lifecycle failures.

**Company value:** Produce a migration path that narrows credential scope and makes revocation observable.

**Delivery agreement:** Deliver local identity contracts and rotation rehearsals; deploy no live trust policy.

### Setup prerequisites

- Create a local identity issuer and object-store double using generated test-only keys; no cloud account or production secret.

### Define trust scope

Bind identities to workloads and resources.

#### BIDENT-101 — Inventory the export worker's required storage operations

**Task · Medium priority · Foundational**

noCV practice brief v5 · BIDENT-101 · Workload identity credential rotation

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Define trust scope. Depends on: No preceding ticket.

Difficulty: Foundational. Estimated focused work: 60 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 80% · Cloud infrastructure 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The worker credential permits listing and deleting unrelated storage objects.

Acceptance criteria

- List operations required for one export lifecycle.

- Separate read, write, and cleanup authority.

- Identify unnecessary permissions.

Implementation constraints

- Use synthetic object namespaces.

Verification

- Complete an export with the proposed operation list.

- Deny an unrelated bucket-list request.

Deliverables

- Least-privilege operation matrix.

Rollout and recovery: Review scope before issuing replacement credentials.

Project prerequisites: Create a local identity issuer and object-store double using generated test-only keys; no cloud account or production secret.

Engineer value: Practice workload identity, audience restrictions, and credential lifecycle failures.

Company value: Produce a migration path that narrows credential scope and makes revocation observable.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIDENT-102 — Bind workload assertions to issuer, audience, and environment

**Task · High priority · Advanced**

noCV practice brief v5 · BIDENT-102 · Workload identity credential rotation

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Define trust scope. Depends on: BIDENT-101.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 80% · Cloud infrastructure 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A staging assertion is accepted by the production-class storage adapter.

Acceptance criteria

- Validate issuer and exact audience.

- Bind workload and environment identity.

- Reject unknown signing keys and algorithms.

Implementation constraints

- Use generated local test keys only.

Verification

- Accept a matching assertion.

- Reject wrong audience, environment, and algorithm fixtures.

Deliverables

- Assertion verifier.

Rollout and recovery: Fail closed on unresolved trust configuration.

Project prerequisites: Create a local identity issuer and object-store double using generated test-only keys; no cloud account or production secret.

Engineer value: Practice workload identity, audience restrictions, and credential lifecycle failures.

Company value: Produce a migration path that narrows credential scope and makes revocation observable.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Issue bounded credentials

Validate tokens, caching, and provider failures.

#### BIDENT-103 — Issue short-lived storage grants with exact resource scope

**Task · High priority · Advanced**

noCV practice brief v5 · BIDENT-103 · Workload identity credential rotation

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Issue bounded credentials. Depends on: BIDENT-102.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 70% · Cloud infrastructure 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A workload token grants access to every export instead of one operation.

Acceptance criteria

- Bind grant to resource and allowed operation.

- Enforce expiry and unique grant identity.

- Prevent the caller from widening scope.

Implementation constraints

- Grant fields derive from authorized server state.

Verification

- Write the intended synthetic export.

- Reject a different resource or operation under the same grant.

Deliverables

- Scoped grant issuer.

Rollout and recovery: Start with one export path; retain no broad fallback credential.

Project prerequisites: Create a local identity issuer and object-store double using generated test-only keys; no cloud account or production secret.

Engineer value: Practice workload identity, audience restrictions, and credential lifecycle failures.

Company value: Produce a migration path that narrows credential scope and makes revocation observable.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIDENT-104 — Refresh credentials before expiry without creating a refresh storm

**Bug · High priority · Intermediate**

noCV practice brief v5 · BIDENT-104 · Workload identity credential rotation

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Issue bounded credentials. Depends on: BIDENT-103.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Performance engineering 50% · Security 30% · Cloud infrastructure 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Every concurrent request refreshes the same expiring credential.

Acceptance criteria

- Coalesce equivalent in-flight refreshes.

- Refresh within a declared bounded window.

- Avoid caching failed or mismatched grants.

Implementation constraints

- Cache keys include workload, resource scope, and audience.

Verification

- Share one refresh across concurrent requests.

- Reject cross-scope cache reuse and retry a failed refresh safely.

Deliverables

- Credential cache.

Rollout and recovery: Use short cache lifetimes; clear affected entries on validation failure.

Project prerequisites: Create a local identity issuer and object-store double using generated test-only keys; no cloud account or production secret.

Engineer value: Practice workload identity, audience restrictions, and credential lifecycle failures.

Company value: Produce a migration path that narrows credential scope and makes revocation observable.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIDENT-105 — Keep clock skew from extending grant lifetime indefinitely

**Task · High priority · Intermediate**

noCV practice brief v5 · BIDENT-105 · Workload identity credential rotation

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Issue bounded credentials. Depends on: BIDENT-102, BIDENT-104.

Difficulty: Intermediate. Estimated focused work: 120 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 80% · Cloud infrastructure 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A large token leeway makes expired credentials valid far longer than intended.

Acceptance criteria

- Bound allowed skew explicitly.

- Reject impossible issue and expiry ordering.

- Report clock-related failures without token contents.

Implementation constraints

- Use an injected clock for deterministic checks.

Verification

- Accept a token inside the declared skew window.

- Reject expired and future-issued tokens beyond the bound.

Deliverables

- Expiry boundary tests.

Rollout and recovery: Deploy with monitored clock assumptions; stop issuance if time authority is unavailable.

Project prerequisites: Create a local identity issuer and object-store double using generated test-only keys; no cloud account or production secret.

Engineer value: Practice workload identity, audience restrictions, and credential lifecycle failures.

Company value: Produce a migration path that narrows credential scope and makes revocation observable.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIDENT-106 — Prevent identity-provider outages from selecting static credentials

**Bug · High priority · Advanced**

noCV practice brief v5 · BIDENT-106 · Workload identity credential rotation

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Issue bounded credentials. Depends on: BIDENT-104, BIDENT-105.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 50% · Site reliability 30% · Cloud infrastructure 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The adapter silently falls back to an old environment secret when token refresh fails.

Acceptance criteria

- Remove implicit static fallback.

- Return a bounded unavailable state.

- Allow only already-valid scoped grants until expiry.

Implementation constraints

- Never log credentials in failure diagnostics.

Verification

- Continue with a valid unexpired grant.

- Fail closed after expiry during issuer outage.

Deliverables

- Provider failure behavior.

Rollout and recovery: Disable issuance cleanly on outage; restore only after trust validation succeeds.

Project prerequisites: Create a local identity issuer and object-store double using generated test-only keys; no cloud account or production secret.

Engineer value: Practice workload identity, audience restrictions, and credential lifecycle failures.

Company value: Produce a migration path that narrows credential scope and makes revocation observable.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Rehearse lifecycle changes

Test rotation, revocation, and migration recovery.

#### BIDENT-107 — Rotate signing keys with a bounded overlap window

**Task · High priority · Advanced**

noCV practice brief v5 · BIDENT-107 · Workload identity credential rotation

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Rehearse lifecycle changes. Depends on: BIDENT-105, BIDENT-106.

Difficulty: Advanced. Estimated focused work: 210 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 60% · Cloud infrastructure 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Immediate key replacement breaks in-flight exports while indefinite overlap preserves old authority.

Acceptance criteria

- Publish new verification key before issuance switches.

- Bound old-key acceptance by policy and token expiry.

- Reject retired keys after the overlap.

Implementation constraints

- Private keys remain test-only runtime inputs.

Verification

- Complete an in-flight old-key export during overlap.

- Reject an old-key token after retirement.

Deliverables

- Key rotation rehearsal.

Rollout and recovery: Retain the previous public verifier only for the declared overlap.

Project prerequisites: Create a local identity issuer and object-store double using generated test-only keys; no cloud account or production secret.

Engineer value: Practice workload identity, audience restrictions, and credential lifecycle failures.

Company value: Produce a migration path that narrows credential scope and makes revocation observable.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIDENT-108 — Revoke one workload without disrupting unrelated exporters

**Task · High priority · Advanced**

noCV practice brief v5 · BIDENT-108 · Workload identity credential rotation

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Rehearse lifecycle changes. Depends on: BIDENT-107.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 80% · Cloud infrastructure 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A broad emergency revocation stops every export worker.

Acceptance criteria

- Scope revocation to workload identity and grant class.

- Check revocation before accepting cached authority.

- Preserve unrelated authorized workloads.

Implementation constraints

- Privileged revocations require append-only audit metadata.

Verification

- Revoke one synthetic worker.

- Verify its cached grant fails while another worker succeeds.

Deliverables

- Scoped revocation behavior.

Rollout and recovery: Test revocation before replacing the static credential path.

Project prerequisites: Create a local identity issuer and object-store double using generated test-only keys; no cloud account or production secret.

Engineer value: Practice workload identity, audience restrictions, and credential lifecycle failures.

Company value: Produce a migration path that narrows credential scope and makes revocation observable.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIDENT-109 — Design the static-to-workload identity cutover

**Task · High priority · Expert**

noCV practice brief v5 · BIDENT-109 · Workload identity credential rotation

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Rehearse lifecycle changes. Depends on: BIDENT-106, BIDENT-108.

Difficulty: Expert. Estimated focused work: 300 minutes; setup and prerequisite tickets are additional.

Estimated field mix: System design 40% · Security 40% · Cloud infrastructure 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The team must migrate without leaving a forgotten permanent credential active.

Acceptance criteria

- Inventory callers and staged cutover order.

- Define proof that no caller requires the old credential.

- Compare rollback availability against retained-secret risk.

Implementation constraints

- Do not restore broad credentials automatically on failure.

Verification

- Migrate two synthetic callers and revoke the old key.

- Detect a forgotten caller before declaring the migration complete.

Deliverables

- Identity migration decision record.

Rollout and recovery: Use a reviewed emergency path; retire the static key after verified caller migration.

Project prerequisites: Create a local identity issuer and object-store double using generated test-only keys; no cloud account or production secret.

Engineer value: Practice workload identity, audience restrictions, and credential lifecycle failures.

Company value: Produce a migration path that narrows credential scope and makes revocation observable.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### BIDENT-110 — Write credential-failure diagnostics without secret exposure

**Chore · Low priority · Foundational**

noCV practice brief v5 · BIDENT-110 · Workload identity credential rotation

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Rehearse lifecycle changes. Depends on: BIDENT-109.

Difficulty: Foundational. Estimated focused work: 60 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 50% · Site reliability 50%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Operators need to distinguish expiry, audience mismatch, and issuer failure.

Acceptance criteria

- Define safe failure categories and request IDs.

- Document scoped recovery actions.

- Exclude tokens, private keys, and authorization headers.

Implementation constraints

- Use synthetic secret markers in verification.

Verification

- Diagnose an expired grant from safe metadata.

- Verify no seeded secret appears in logs or reports.

Deliverables

- Identity support runbook.

Rollout and recovery: Publish with the adapter and recheck after logging changes.

Project prerequisites: Create a local identity issuer and object-store double using generated test-only keys; no cloud account or production secret.

Engineer value: Practice workload identity, audience restrictions, and credential lifecycle failures.

Company value: Produce a migration path that narrows credential scope and makes revocation observable.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.
