# noCV engineering task library

Content version 5

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.

## DENV — Keep environment configuration explicit and recoverable

A fictional notification service uses environment files assembled by shell scripts. Defaults differ by machine, secret values appear in diagnostics, and emergency flags have no expiry. Build a typed local configuration compiler with fake secret references and synthetic environments; no real credentials or notification providers are supplied.

**Field:** DevOps. **Suggested stack:** TypeScript, JSON Schema, Secret adapter, Vitest.

**Engineer value:** Practice configuration as a reviewed contract with safe diagnostics, provenance, and rollback.

**Company value:** Review environment changes before deployment and reduce outages caused by missing, stale, or silently defaulted settings.

**Delivery agreement:** Ten linked tickets across three phases. Use a local repository and fake providers; deliver workflow code, failure tests, a rollback rehearsal, and a concise runbook.

### Setup prerequisites

- Configuration precedence

- Schema validation

- Least privilege

### Make the delivery contract visible

Replace implicit workflow assumptions with reviewable inputs and outcomes.

#### DENV-101 — Define precedence without depending on process order

**Task · Medium priority · Foundational**

noCV practice brief v5 · DENV-101 · Keep environment configuration explicit and recoverable

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Make the delivery contract visible. Depends on: No preceding ticket.

Difficulty: Foundational. Estimated focused work: 90 minutes; setup and prerequisite tickets are additional.

Estimated field mix: DevOps 70% · Platform engineering 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Local, environment, and command-line values are merged in object iteration order, so the same inputs produce different ports in two scripts.

Acceptance criteria

- Declare precedence for base, environment, and explicit override layers

- Each resolved value retains its source layer

- Duplicate keys within one layer fail parsing

Implementation constraints

- Do not read the host process environment directly in domain tests.

Verification

- Resolve the same layers in shuffled input order and compare output.

- Provide duplicate keys and confirm no partial configuration is returned.

Deliverables

- Layered configuration resolver and precedence tests

Rollout and recovery: Generate a report beside the current scripts before switching consumers.

Project prerequisites: Configuration precedence Schema validation Least privilege

Engineer value: Practice configuration as a reviewed contract with safe diagnostics, provenance, and rollback.

Company value: Review environment changes before deployment and reduce outages caused by missing, stale, or silently defaulted settings.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### DENV-102 — Reject missing required values before service startup

**Bug · Medium priority · Foundational**

noCV practice brief v5 · DENV-102 · Keep environment configuration explicit and recoverable

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Make the delivery contract visible. Depends on: DENV-101.

Difficulty: Foundational. Estimated focused work: 90 minutes; setup and prerequisite tickets are additional.

Estimated field mix: DevOps 70% · Quality engineering 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The service starts with an empty callback base URL and fails only when the first delivery completes.

Acceptance criteria

- Schema distinguishes required, optional, and defaulted values

- Validation reports all safe field errors together

- Invalid configuration prevents provider initialization

Implementation constraints

- Defaults must be explicit in the versioned schema and safe for every environment that uses them.

Verification

- Validate complete development and production-like fixture configurations.

- Remove several required fields and confirm providers are never constructed.

Deliverables

- Typed configuration schema and startup tests

Rollout and recovery: Run validation as a pre-deployment gate before enforcing it at startup.

Project prerequisites: Configuration precedence Schema validation Least privilege

Engineer value: Practice configuration as a reviewed contract with safe diagnostics, provenance, and rollback.

Company value: Review environment changes before deployment and reduce outages caused by missing, stale, or silently defaulted settings.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### DENV-103 — Keep secret values out of configuration diffs

**Story · Medium priority · Intermediate**

noCV practice brief v5 · DENV-103 · Keep environment configuration explicit and recoverable

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Make the delivery contract visible. Depends on: DENV-102.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: DevOps 60% · Security 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A deployment preview serializes the fully resolved configuration, including a fake API token value, into the job log.

Acceptance criteria

- Configuration stores secret references separately from ordinary values

- Diffs show reference identity and version without secret content

- Errors and snapshots redact values even when resolution fails

Implementation constraints

- Use sentinel fake secrets and assert they never appear in output.

Verification

- Diff two configurations with changed secret references.

- Make resolution fail with a sentinel value in the provider error and verify redaction.

Deliverables

- Secret-reference model and log-leak tests

Rollout and recovery: Remove full resolved-config logging before connecting any nonfixture provider.

Project prerequisites: Configuration precedence Schema validation Least privilege

Engineer value: Practice configuration as a reviewed contract with safe diagnostics, provenance, and rollback.

Company value: Review environment changes before deployment and reduce outages caused by missing, stale, or silently defaulted settings.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Control change and failure

Add bounded concurrency, authority checks, and restart-safe transitions.

#### DENV-104 — Validate cross-field configuration invariants

**Chore · Medium priority · Intermediate**

noCV practice brief v5 · DENV-104 · Keep environment configuration explicit and recoverable

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Control change and failure. Depends on: DENV-102.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: DevOps 70% · Distributed systems 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Retries are enabled while the idempotency store is disabled, creating duplicate notification attempts after timeouts.

Acceptance criteria

- Cross-field rules run after individual field validation

- Retry requires a compatible idempotency mode and positive deadline

- Errors identify involved settings without exposing values

Implementation constraints

- Keep invariants centralized and versioned rather than scattered among service constructors.

Verification

- Validate supported retry and store combinations.

- Enable retry with no store and with a shorter operation deadline than backoff.

Deliverables

- Configuration invariant set and combination matrix

Rollout and recovery: Evaluate current environment fixtures and resolve all violations before enforcement.

Project prerequisites: Configuration precedence Schema validation Least privilege

Engineer value: Practice configuration as a reviewed contract with safe diagnostics, provenance, and rollback.

Company value: Review environment changes before deployment and reduce outages caused by missing, stale, or silently defaulted settings.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### DENV-105 — Require expiry and ownership for emergency feature overrides

**Task · High priority · Advanced**

noCV practice brief v5 · DENV-105 · Keep environment configuration explicit and recoverable

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Control change and failure. Depends on: DENV-101, DENV-103.

Difficulty: Advanced. Estimated focused work: 240 minutes; setup and prerequisite tickets are additional.

Estimated field mix: DevOps 70% · Site reliability 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A disable-delivery flag added during a rehearsal remains set for weeks because its reason and owner exist only in chat.

Acceptance criteria

- Override records owner, reason, scope, creation, and expiry

- Expired override fails compilation instead of remaining active

- Normal configuration remains visible beneath the override

Implementation constraints

- Use synthetic operator identities; flags do not bypass authorization or audit.

Verification

- Apply an active scoped override and show its provenance.

- Compile expired and ownerless overrides and confirm blocking errors.

Deliverables

- Expiring override registry and policy tests

Rollout and recovery: Introduce reporting before rejecting legacy unowned fixture flags.

Project prerequisites: Configuration precedence Schema validation Least privilege

Engineer value: Practice configuration as a reviewed contract with safe diagnostics, provenance, and rollback.

Company value: Review environment changes before deployment and reduce outages caused by missing, stale, or silently defaulted settings.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### DENV-106 — Promote configuration by immutable revision

**Bug · High priority · Advanced**

noCV practice brief v5 · DENV-106 · Keep environment configuration explicit and recoverable

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Control change and failure. Depends on: DENV-103, DENV-104.

Difficulty: Advanced. Estimated focused work: 240 minutes; setup and prerequisite tickets are additional.

Estimated field mix: DevOps 70% · Security 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A mutable environment file changes after approval but before deployment, so the applied settings were never reviewed.

Acceptance criteria

- Compilation produces canonical content and immutable revision hash

- Approval and deployment bind the exact revision

- Any source-layer change produces a new revision

Implementation constraints

- Exclude secret values while binding secret reference identities and schema version.

Verification

- Approve and deploy one unchanged revision.

- Edit a source layer after approval and verify deployment refuses the stale authorization.

Deliverables

- Immutable configuration revision and approval-binding tests

Rollout and recovery: Use revision identities in the local deployment simulator before removing mutable file reads.

Project prerequisites: Configuration precedence Schema validation Least privilege

Engineer value: Practice configuration as a reviewed contract with safe diagnostics, provenance, and rollback.

Company value: Review environment changes before deployment and reduce outages caused by missing, stale, or silently defaulted settings.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### DENV-107 — Resolve secret rotation without restarting into a mixed revision

**Story · High priority · Expert**

noCV practice brief v5 · DENV-107 · Keep environment configuration explicit and recoverable

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Control change and failure. Depends on: DENV-103, DENV-106.

Difficulty: Expert. Estimated focused work: 360 minutes; setup and prerequisite tickets are additional.

Estimated field mix: DevOps 65% · Security 35%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Two secret references rotate independently while workers reload, leaving some requests signed with mismatched key and certificate versions.

Acceptance criteria

- Dependent secret references resolve as one declared bundle revision

- Reload publishes only a fully validated immutable snapshot

- In-flight work retains its starting snapshot until completion

Implementation constraints

- Fake secret material stays inside the local adapter and is never included in generic configuration hashes.

Verification

- Rotate a complete bundle while old and new operations overlap.

- Withhold one member and confirm no worker selects the partial revision.

Deliverables

- Secret-bundle reload protocol and overlap test

Rollout and recovery: Keep restart-based rotation available until snapshot reload is proven.

Project prerequisites: Configuration precedence Schema validation Least privilege

Engineer value: Practice configuration as a reviewed contract with safe diagnostics, provenance, and rollback.

Company value: Review environment changes before deployment and reduce outages caused by missing, stale, or silently defaulted settings.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Operate and improve

Measure the workflow, rehearse recovery, and document ownership.

#### DENV-108 — Detect environment drift without copying secret data

**Chore · High priority · Advanced**

noCV practice brief v5 · DENV-108 · Keep environment configuration explicit and recoverable

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Operate and improve. Depends on: DENV-106.

Difficulty: Advanced. Estimated focused work: 240 minutes; setup and prerequisite tickets are additional.

Estimated field mix: DevOps 70% · Platform engineering 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A local environment's retry count is changed outside the compiler, but drift reports are disabled because teams fear dumping secrets.

Acceptance criteria

- Compare ordinary canonical values and secret reference identities

- Report missing, extra, and changed paths with provenance

- Secret values and provider error bodies are never serialized

Implementation constraints

- Observed configuration comes from a bounded fake runtime projection.

Verification

- Detect changes in an ordinary value and a secret reference version.

- Return a sentinel secret in observed input and prove it cannot enter the report.

Deliverables

- Redacted drift detector and fixture report

Rollout and recovery: Begin in read-only mode and resolve unexplained differences before automation.

Project prerequisites: Configuration precedence Schema validation Least privilege

Engineer value: Practice configuration as a reviewed contract with safe diagnostics, provenance, and rollback.

Company value: Review environment changes before deployment and reduce outages caused by missing, stale, or silently defaulted settings.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### DENV-109 — Roll back configuration without rolling back application code

**Task · High priority · Expert**

noCV practice brief v5 · DENV-109 · Keep environment configuration explicit and recoverable

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Operate and improve. Depends on: DENV-106, DENV-107, DENV-108.

Difficulty: Expert. Estimated focused work: 360 minutes; setup and prerequisite tickets are additional.

Estimated field mix: DevOps 60% · Site reliability 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A new timeout revision overloads the fake provider, but the only recovery script redeploys the entire previous application artifact.

Acceptance criteria

- Rollback selects a prior compatible configuration revision

- Compatibility is checked against the current application contract

- History retains failed and restored revisions plus observed outcome

Implementation constraints

- Rollback never mutates a historical revision or reuses its approval for another environment.

Verification

- Deploy a bad timeout revision and restore the prior compatible configuration.

- Choose a revision requiring an older schema and block rollback with an actionable result.

Deliverables

- Configuration rollback command and recovery rehearsal

Rollout and recovery: Maintain one known-compatible revision for each simulated environment.

Project prerequisites: Configuration precedence Schema validation Least privilege

Engineer value: Practice configuration as a reviewed contract with safe diagnostics, provenance, and rollback.

Company value: Review environment changes before deployment and reduce outages caused by missing, stale, or silently defaulted settings.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### DENV-110 — Publish the environment contract for service owners

**Bug · Medium priority · Intermediate**

noCV practice brief v5 · DENV-110 · Keep environment configuration explicit and recoverable

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Operate and improve. Depends on: DENV-105, DENV-108, DENV-109.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: DevOps 70% · Developer tooling 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

New owners know variable names but not which settings can change independently, which require restart, or how failure appears.

Acceptance criteria

- Reference lists type, source, default, sensitivity, reload behavior, and owner

- Cross-field invariants and rollback compatibility are linked

- Examples use synthetic values and secret references only

Implementation constraints

- Generated reference comes from the same schema used by validation.

Verification

- Generate and review documentation for every current field.

- Add an undocumented schema field and make the consistency test fail.

Deliverables

- Generated environment reference and owner runbook

Rollout and recovery: Require schema and documentation consistency in CI.

Project prerequisites: Configuration precedence Schema validation Least privilege

Engineer value: Practice configuration as a reviewed contract with safe diagnostics, provenance, and rollback.

Company value: Review environment changes before deployment and reduce outages caused by missing, stale, or silently defaulted settings.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.
