diff --git a/.ciagent/CHECKPOINT.json b/.ciagent/CHECKPOINT.json index ec380bb..fd2431c 100644 --- a/.ciagent/CHECKPOINT.json +++ b/.ciagent/CHECKPOINT.json @@ -1,12 +1,11 @@ { - "phase": 5, - "stage": "complete", - "milestone": "v1.20", - "phase_role": "final", + "phase": 0, + "stage": "specify", + "milestone": "v1.21", + "phase_role": "pre_execution", "attempts": 0, - "updated_at": "2026-08-07T21:30:00Z", - "milestone_complete": true, - "tag": "v1.19.4", - "requirements": ["REQ-230","REQ-231","REQ-232","REQ-233","REQ-234","REQ-235","REQ-236","REQ-237","REQ-238","REQ-239","REQ-240","REQ-241","REQ-242","REQ-243","REQ-244"], - "notes": "v1.20 milestone complete. 5 phases: P0 pre-execution, P1 consumer-cleanup (gitea removal + doc simplification, REQ-230..232), P2 slide-pipeline (S&P theme + render automation, REQ-239..243), P3 product-roadmap (12-month slides, REQ-244), P4 transparent-terraform (run_platform.sh split + var.enabled feature flags + stale path fix, REQ-233..238), P5 final-review-ship. 15 requirements complete. Guard test test_no_forge_mentions.py passes. 12 slide pipeline tests pass. 45 adapter tests pass. All L1 modules terraform validate OK. Next milestone starts fresh." -} + "updated_at": "2026-08-11T00:00:00Z", + "milestone_complete": false, + "requirements": ["REQ-245","REQ-246","REQ-247","REQ-248","REQ-249","REQ-250","REQ-251","REQ-252","REQ-253"], + "notes": "v1.21 milestone — Nova Deck Refinement & Pipeline Hardening. P0 specify stage: added v1.21 requirements (REQ-245..253), set active_milestone=v1.21 in config.json, synced PROJECT.md strategic-direction pillar for integration objective. 9 requirements, 6 execution phases planned (P1 strategic-docs, P2 slides, P3 marp+talking-points+README, P4 pipeline-hardening, P5 render+verify, P6 final-review-ship). Tags on v1.20.x line." +} \ No newline at end of file diff --git a/.ciagent/PROJECT.md b/.ciagent/PROJECT.md index 405eac3..d73fb86 100644 --- a/.ciagent/PROJECT.md +++ b/.ciagent/PROJECT.md @@ -1266,16 +1266,29 @@ P7 review+audit+ship). Tags on the v1.16.x line: `v1.16.0` (P0) → - **Pillar A — Strategic Direction.** A durable, PO-authored `.ciagent/NORTH_STAR.md` encodes the platform's vision, 4 strategic - objectives, 5 anti-goals, v1.17 non-goals, 12–18mo targets (with a + objectives, anti-goals, v1.17 non-goals, 12–18mo targets (with a grounding column), and success criteria. CIAgent reads it in every future `/ci-run` so the direction survives across milestones. The attestation clarification is reflected: human attestation required at stage gates (QA for production, SRE for operational readiness); autonomy - in operations, not in accountability. + in operations, not in accountability. **v1.21 refinement:** Strategic + Objective #4 reframed from "default substrate for agentic consumption" to + integrating with externally owned PDLC/SDLC/Agentic/Citizen Developer + platforms regardless of source (Nova provides skills + MCP endpoints; + all prod intents go through the same controls). Objective #2 reworded: + trust is established by deterministic scripts that calculate a score — + the platform functions without AI. Objective #3 reworded with four + CTO-grade metrics (Lead Time PR→Prod, Infrastructure Vulnerability + Count trend, MTTR, Cloud Spend Reduction) all flowing into PowerBI. + Anti-goals #1, #4, #5 removed; replaced with "not an upstream + development platform" and "not a replacement for the PDLC". - **Pillar B — Leadership Metrics + PowerBI.** Instrument Nova to collect, aggregate, and surface leadership-grade metrics that prove the - "no-humans" autonomous-infrastructure value proposition. Nova-native + "no-humans" autonomous-infrastructure value proposition (reframed in + v1.21 to "autonomous cloud delivery" — professional framing; the + platform delivers safe production deployment without an operator in + the loop of normal operations). Nova-native minimal tech (CloudEvents 1.0 envelope, JSONL event log, SQLite cold store, hash-chained Decision Ledger via `outbox_writer.py` extension) + Infracost for pre-apply cost estimates. Hybrid model: existing diff --git a/.ciagent/REQUIREMENTS.md b/.ciagent/REQUIREMENTS.md index 0b3e005..918cfed 100644 --- a/.ciagent/REQUIREMENTS.md +++ b/.ciagent/REQUIREMENTS.md @@ -1536,3 +1536,183 @@ with documented schemas. | REQ-242 | P2 | complete | | REQ-243 | P2 | complete | | REQ-244 | P3 | complete | + +## v1.21 — Nova Deck Refinement & Pipeline Hardening + +> Leadership-deck refinement based on 33 review notes on the v1.20 deck +> (v1.20 shipped as `nova-no-humans-platform*`). This milestone renames the +> deck to the professional "Autonomous Cloud Delivery Platform" framing, +> restructures the narrative (Problem → Solution → Proof → Roadmap + Ask), +> removes internal provenance from audience-facing slides, hardens the +> policy pipeline (Checkov before plan, Wiz-or-Checkov on plan), and moves +> the strategic integration objective into the North Star. +> +> Tags run on the v1.20.x line (milestone v1.21 → tags v1.20.0, v1.20.1, …). + +### REQ-245 — Deck rename + restructure + +The deck files are renamed from `nova-no-humans-platform*` to +`nova-autonomous-cloud-delivery*` across all five artifacts +(source `.md`, `-marp.md`, `.html`, `.pptx`, `-talking-points.md`). +The in-deck title becomes "Nova — The Autonomous Cloud Delivery Platform" +(professional, conveys autonomy without the provocative "no-humans" +wording). The narrative restructures to 18 main + 1 appendix slides: + +1. The Problem (merged old 1+2; broader problem framing; no "arc"; no + "18 capabilities verified"; not "humans are the problem"; add tribal + knowledge / rockstar-operator framing) +2. Nova's Vision +3. Strategic Objectives + Anti-Goals +4. Scope: Downstream of PDLC (moved up) +5. RACI: Who Owns What (moved up) +6. The Platform Pipeline +7. The Decision Ledger +8. The Attestation Matrix +9. Telemetry & Live Ops +10. Decision Ledger + Attestation Coverage +11. Cost & ROI +12. What's Deferred — and Why +13. Roadmap to the North Star +14. 12-Month Product Roadmap +15. Quarter-by-Quarter Outcomes +16. Production-Grade Guidance via Atelier (1/2) +17. Production-Grade Guidance via Atelier (2/2) +18. Recap + Ask +A1. Metrics Glossary + +Removed: old Slide 10 (Capability Health), old Slide 12 (Zero-Touch +Efficiency), old Appendix A2 (Operating Model & Cost). Slide 5's first +table removed. + +### REQ-246 — Thesis rename + reframe + +`.ciagent/NO_HUMANS_THESIS.md` is renamed (git mv) to +`.ciagent/AUTONOMY_THESIS.md`. Content reframes from "removing humans" to +"autonomy in operations, human at stage gates" — professional, not +provocative. The operator-bottleneck framing is softened; the attestation +model + provable trust are emphasized. Anti-claims are retained and +reworded for a tech-leadership audience. All references across the repo +are updated to the new filename + framing. + +### REQ-247 — Strategic-docs sync (NORTH_STAR + PROJECT) + +`NORTH_STAR.md` is updated: +- Vision polished for a technical audience concerned about security, + security remediation velocity, and reliability; "infrastructure + operations become visible" is preserved as a recurring theme. +- Strategic Objective #2 (provable trust) is reworded: trust is + established by deterministic scripts that calculate a score, not by + AI. The platform functions without AI. "AI decisions" are really + automated decisions. +- Strategic Objective #3 (ROI) is reworded with four CTO-grade metrics: + Lead Time (PR → Production), Infrastructure Vulnerability Count + (downward trend), MTTR, Cloud Spend Reduction. All flow into PowerBI + views and are captured by the telemetry pipeline. +- Strategic Objective #4 is replaced: integrate with externally owned + PDLC, SDLC, Agentic, and Citizen Developer platforms regardless of + source; Nova provides skills + MCP endpoints to make applications + production-grade; all intents to deploy to production go through the + same rigorous controls and quality gates. +- Anti-goals #1 (hyperscaler competitor), #4 (legacy untagged), and #5 + (sold to operators) are removed. Two new anti-goals added: not an + upstream development platform; not a replacement for the Product + Lifecycle (PDLC). +- Anti-goal #3 reworded to remove the "removes humans" framing. + +`PROJECT.md` mission statement + scope are synchronized with the +integration objective and the reworded strategic objectives. + +### REQ-248 — RACI restructure (Quality Engineering + SRE) + +The RACI matrix (slide + `docs/raci.md`) is restructured: +- A **Quality Engineering** column is added. +- The Platform column no longer holds the **A** for release attestation; + accountability is reassigned to QA or SRE as appropriate. +- "Release Management" is renamed to **SRE**. +- "Release attestation" is split into two rows: the SRE part is + **Production Readiness** (operational readiness sign-off). +- The slide is sized to fit (text shrunk / low-impact rows dropped). + +### REQ-249 — Atelier split (2 slides) + +Slide 19 (Production-Grade Guidance via Atelier) is split into two slides: +- **16 (1/2):** Skills + MCP server overview (the 9 skills, the 4 MCP + tools, the plugin-registry + stdio surface). +- **17 (2/2):** Agentic validation beyond deterministic scanners + + vendored Atelier for audit reproducibility. +The benefit wording is improved; the same spirit is retained. + +### REQ-250 — Pipeline hardening (Checkov before plan; Wiz-or-Checkov on plan) + +`scripts/run_platform.sh` (and `scripts/run_postapply.sh` where +relevant) implement the two-stage policy scan: +1. **Checkov runs on static code** (the generated `main.tf` / TF + directory) **before** `terraform plan` — fail-fast, quick developer + feedback on policy violations in the authored code. +2. **After `terraform plan`:** if `WIZ_API_TOKEN` + `WIZ_API_URL` are + set, run **Wiz against the plan**; otherwise run **Checkov against + the plan** as a drop-in replacement. **Wiz and Checkov are never + both run on the plan.** +`adapters/wiz/wiz_adapter.py` is updated if needed for plan-mode +input. Slide 6 + `docs/scope.md` reflect the new flow. Tests +(`tests/test_pipeline.py`, `tests/test_pipeline_contract.py`, and +any checkov/wiz tests) are updated and pass. + +### REQ-251 — Theme CSS fix (Appendix A1) + footer cleanup + +`docs/presentations/assets/nova-sp-theme.css` is fixed so the Appendix +A1 Metrics Glossary table is readable (the table background color is +corrected). The Marp footer no longer shows the version (`v1.20`) or +the `Act %{page}/5` artifact. The title-slide subtitle no longer shows +`v1.18 — Citizen Developer & Production-Grade Guidance`; it becomes +"Product Development & Citizen Developer Overview" (or similar) to +convey the audience for the platform. + +### REQ-252 — Global citation + badge + version removal + +Across all audience-facing slides (the Marp deck, the source-of-truth +markdown, and the talking points): +- All internal citations are removed: `D-###` decision IDs, + `REQ-###` requirement IDs, and internal file paths + (e.g. `outbox_writer.py`, `confidence_signal.py`). +- All `Planned` badges are removed. +- The version is removed from the footer and the title slide. +Every benefit callout is rewritten for a tech-leadership audience +(security, remediation velocity, reliability, lead time). A "less is +more / no fluff" final prose pass is applied; the story stays clear. + +### REQ-253 — Render + verify + ship + +Changed/new mermaid diagrams are re-rendered (slide 1 new diagram, slide +9 expand, Atelier split). HTML + PPTX are re-rendered via +`scripts/render_slides.sh`. `tests/test_slides_pipeline.py` passes: +asserts 18 main + 1 appendix slides, no badge spans, no version in the +footer, no `D-###`/`REQ-###`/`.py` paths in audience-facing slides, and +filename refs updated in render scripts + CI workflow + README. +`tests/test_no_forge_mentions.py` passes. Full `pytest` passes +(pipeline-hardening tests green). `run_platform.sh --check-only` passes. +Milestone ship: tag the final phase on the v1.20.x line; create a +release; attach the PPTX. + +### Out of Scope (v1.21) + +- **Live pilot estate activation** — still deferred (D-096). +- **ML anomaly-forecasting service** — still deferred. +- **Multi-cloud (Azure/GCP) implementation** — still deferred. +- **Tamper-evident ledger (S3 Object Lock + JWS)** — still deferred + (D-083); the deck describes it as a roadmap item without citing the + decision ID in the audience-facing slides. + +### v1.21 Traceability + +| REQ | Phase | Status | +|-----|-------|--------| +| REQ-245 | P2 | pending | +| REQ-246 | P1 | pending | +| REQ-247 | P1 | pending | +| REQ-248 | P2 | pending | +| REQ-249 | P2 | pending | +| REQ-250 | P4 | pending | +| REQ-251 | P3 | pending | +| REQ-252 | P2 | pending | +| REQ-253 | P5 | pending | diff --git a/.ciagent/config.json b/.ciagent/config.json index 5a5cf5a..caf59ac 100644 --- a/.ciagent/config.json +++ b/.ciagent/config.json @@ -8,7 +8,7 @@ ], "active_project": "acdl", "active_projects": ["acdl"], - "active_milestone": "v1.20", + "active_milestone": "v1.21", "autonomy": { "level": "full", "escalation_hooks": ["deploy", "delete_data", "merge_to_main"],