Commit Graph

17 Commits

Author SHA1 Message Date
Jon Chery 090839d2e5 feat(P03): l2-regulatory-reporting manifest (T-3.4)
---ci---
phase: 3
milestone: v1.0
status: execute
persona: infra-stub-engineer
task: T-3.4
requirements:
  covered: [REQ-04, REQ-05]
---/ci---

Wave 1, task T-3.4. Creates modules/l2/l2-regulatory-reporting/manifest.yaml composing
5 L1s by name (D-020). All referenced L1 names exist in modules/l1/.
2026-07-21 13:22:14 +00:00
Jon Chery 6394c2f5fb feat(P03): l2-energy-analytics-api manifest (T-3.3)
---ci---
phase: 3
milestone: v1.0
status: execute
persona: infra-stub-engineer
task: T-3.3
requirements:
  covered: [REQ-04, REQ-05]
---/ci---

Wave 1, task T-3.3. Creates modules/l2/l2-energy-analytics-api/manifest.yaml composing
5 L1s by name (D-020). All referenced L1 names exist in modules/l1/.
2026-07-21 13:22:04 +00:00
Jon Chery 5febbae940 feat(P03): l2-commodity-price-feed manifest (T-3.2)
---ci---
phase: 3
milestone: v1.0
status: execute
persona: infra-stub-engineer
task: T-3.2
requirements:
  covered: [REQ-04, REQ-05]
---/ci---

Wave 1, task T-3.2. Creates modules/l2/l2-commodity-price-feed/manifest.yaml composing
5 L1s by name (D-020). All referenced L1 names exist in modules/l1/.
2026-07-21 13:21:40 +00:00
Jon Chery 6e7231afd5 feat(P03): l2-invoice-service manifest (T-3.1)
---ci---
phase: 3
milestone: v1.0
status: execute
persona: infra-stub-engineer
task: T-3.1
requirements:
  covered: [REQ-04, REQ-05]
---/ci---

Wave 1, task T-3.1. Creates modules/l2/l2-invoice-service/manifest.yaml composing
5 L1s by name (D-020). All referenced L1 names exist in modules/l1/.
2026-07-21 13:21:32 +00:00
Jon Chery e85041d67c docs(P03): create 3-wave phase plan (REQ-04/05/06/07/08/11)
---ci---
phase: 3
milestone: v1.0
status: plan
plan:
  waves: 3
  wave_1_infra_stub: [T-3.1..T-3.4 create 4 L2 manifests]
  wave_2_backend: [T-3.5 policy_checker, T-3.6 confidence_signal, T-3.7 evidence_writer, T-3.8 mock_executor, T-3.9 l3b_agent_stub]
  wave_3_coordination: [T-3.10 verify_phase03, T-3.11 traceability]
  requirements_covered: [REQ-04, REQ-05, REQ-06, REQ-07, REQ-08, REQ-11]
  must_haves: 9
  verification:
    typecheck: bash -n + python -m py_compile + yaml load
    test: scripts/verify_phase03.sh
    build: no-op
---/ci---

PLAN.md replaced with Phase 03 plan. Wave 1 (infra-stub-engineer) creates
the 4 L2 manifests. Wave 2 (backend-engineer) creates the 5 core scripts.
Wave 3 (lead-developer) wires the verify script + traceability.
2026-07-21 13:20:48 +00:00
Jon Chery 7310da224e docs(P03): research findings — L2/contract/state/audit/core-script schemas
---ci---
phase: 3
milestone: v1.0
status: research
research:
  l2_schema: l1s list of {name, inputs: map}; 4 L2s each referencing 5 L1s
  contract_schema: stack + inputs + optional public-ingress: bool
  state_json_shape: l2, l1s array (name+applied+exit_code), contract
  audit_json: JSON array; canonical-JSON SHA-256 hash chain; GENESIS prev_hash
  core_script_io: 5 scripts with explicit input/output/exit contracts
  personas: no change; backend-engineer owns core scripts + L2 manifests; infra-stub-engineer owns L1 manifests only
---/ci---

ARCHITECTURE.md gains the L2 manifest schema, the L2 list with per-L2
L1 references (5 each, within max-depth-5), the contract.yaml schema,
the state.json shape, the audit.json event + canonical-JSON hash chain,
and a core-script I/O contract table. PERSONAS.md is unchanged for
Phase 03 (backend-engineer and infra-stub-engineer were both already
active in the project-level roster).
2026-07-21 13:20:13 +00:00
Jon Chery e00393adfd decision(P03): clarification — L2/contract/evidence/hash-chain schemas
---ci---
phase: 3
milestone: v1.0
status: clarify
decisions:
  - id: D-020
    decision: L2 manifest.yaml schema with l1s: list of {name, inputs: map}
    rationale: REQ-04 says L2 composes L1s; REQ-05 caps depth at 5 (L2->L1 is depth 1)
    confidence: 0.90
    alternatives: [graph-of-L1s with edges, single flat list of L1 names with no inputs]
  - id: D-021
    decision: contract.yaml schema with stack, inputs, optional public-ingress: bool
    rationale: REQ-07 cites public-ingress:true as the forbidden key; REQ-08 keys off policy pass/fail
    confidence: 0.90
    alternatives: [separate policy file, contract-free intent]
  - id: D-022
    decision: mock_executor.sh writes state.json with l2, l1s array (name+applied+exit_code), contract
    rationale: REQ-06 says writes state.json but does not specify shape
    confidence: 0.85
    alternatives: [per-L1 state files, no state file]
  - id: D-023
    decision: evidence_writer.py appends to audit.json (JSON array); each event has seq, ts, stage, event, prev_hash, hash (SHA-256 of canonical JSON); genesis has prev_hash=GENESIS, seq=0
    rationale: D-005 mandates hash-chained ledger; canonical JSON for deterministic hashing
    confidence: 0.90
    alternatives: [signed commits only, append-only log file]
  - id: D-024
    decision: confidence_signal.py prints {score, reason} JSON to stdout; exit 0 always
    rationale: REQ-08 literal: base 0.90, drops to 0.40, gate >= 0.50
    confidence: 0.95
    alternatives: [exit non-zero on fail, separate side-channel file]
  - id: D-025
    decision: policy_checker.py exits 1 with stdout POLICY_VIOLATION:PUBLIC_INGRESS on public-ingress:true; else exit 0 with stdout POLICY_PASS
    rationale: REQ-07 literal
    confidence: 0.99
    alternatives: []
  - id: D-026
    decision: l3b_agent_stub.py reads issue body from argv[1] or stdin, applies D-008 keyword map, writes contract.yaml to stdout (or -o <path>)
    rationale: D-008 + Act 3 example; L3B must produce same contract format as L3A
    confidence: 0.90
    alternatives: [fixed-output contract per stack, no -o flag]
---/ci---

Phase 03 has real ambiguities (no schema was specified for L2 manifests,
contract.yaml, audit.json events, or the L3B output format). Seven
decisions logged: D-020 L2 schema, D-021 contract.yaml schema, D-022
state.json shape, D-023 audit.json event + hash chain, D-024
confidence_signal output, D-025 policy_checker output, D-026 l3b_agent
I/O contract.
2026-07-21 13:19:43 +00:00
Jon Chery 6e27df7404 docs(P02): post-ship traceability + roadmap update (v1.0.2)
---ci---
phase: 2
milestone: v1.0
status: shipped
requirements:
  complete: [REQ-02, REQ-03]
release:
  tag: v1.0.2
  pr: 2
---/ci---

ROADMAP Phase 02 -> complete (v1.0.2). REQUIREMENTS REQ-02/03 -> complete.
2026-07-21 13:18:51 +00:00
grimacing 00d0043866 ship: phase-02 l1-modules (v1.0.2)
Squash merge of phase/02-l1-modules into milestone/v1.0-initial; 8 L1 stub modules created; verify_phase02.sh green.
v1.0.2
2026-07-21 13:18:12 +00:00
Jon Chery fd423e2df1 docs(P01): post-ship traceability + roadmap update (v1.0.1)
---ci---
phase: 1
milestone: v1.0
status: shipped
requirements:
  complete: [REQ-01, REQ-09]
  partial: [REQ-10, REQ-12]
release:
  tag: v1.0.1
  url: https://git.cloudinit.dev/continuous-intelligence/acdl/releases/tag/v1.0.1
  pr: 1
---/ci---

ROADMAP Phase 01 -> complete (v1.0.1). REQUIREMENTS REQ-01/09 -> complete;
REQ-10/12 -> partial (full impl in Phase 04).
2026-07-21 13:12:01 +00:00
grimacing 8947e89d7b ship: phase-01 repo-scaffolding (v1.0.1)
Squash merge of phase/01-repo-scaffolding into milestone/v1.0-initial; tagged v1.0.1.
2026-07-21 13:11:02 +00:00
Jon Chery b953fd4a8e docs(P01): complete repo-scaffolding phase
---ci---
phase: 1
milestone: v1.0
status: complete
requirements:
  covered: [REQ-01, REQ-09]
  partial: [REQ-10, REQ-12]
---/ci---

Squash merge of phase/01-repo-scaffolding into milestone/v1.0-initial.
Phase 01 ships the three-repo scaffold (acdl, acdl-contracts, acdl-evidence),
the placeholder index.html on acdl-evidence (D-012/D-016 raw-URL substitute
for unsupported Gitea Pages), the qa + prod branches on acdl-contracts
(D-013 stand-in for unsupported Gitea environments), the workflow skeletons
(pipeline.yml + issue-to-contract.yml), and the idempotent setup + verify
scripts. REQ-10/12 remain partial pending Phase 04 full implementation.
v1.0.1
2026-07-21 13:10:50 +00:00
Jon Chery 38eaec9337 docs(P01): create 3-wave phase plan (REQ-01/09/10)
---ci---
phase: 1
milestone: v1.0
status: plan
plan:
  waves: 3
  wave_1_coordination: [T-1.1 gitignore+layout+README, T-1.2 verify_phase01.sh]
  wave_2_backend: [T-2.1 gitea_setup.sh, T-2.2 pipeline.yml skeleton, T-2.3 issue-to-contract.yml skeleton]
  wave_3_coordination: [T-3.1 wire verify + traceability update]
  requirements_covered: [REQ-01, REQ-09, REQ-10]
  must_haves: 6
  verification:
    typecheck: bash -n scripts/*.sh
    test: scripts/verify_phase01.sh
    build: no-op
---/ci---

PLAN.md defines 3 vertical-slice waves: coordination (skeleton + verify
script), backend (Gitea setup + workflow skeletons), coordination (wiring +
traceability). infra-stub-engineer and frontend-engineer have 0 tasks this
phase. Branch for EXECUTE will be phase/01-repo-scaffolding.
2026-07-21 12:59:27 +00:00
Jon Chery 6691974445 docs(P01): research findings — Gitea API surface + persona roster
---ci---
phase: 1
milestone: v1.0
status: research
research:
  gitea_capabilities:
    pages: not_supported
    environments_api: not_supported
    repository_dispatch: not_supported
    workflow_call: supported
    workflow_dispatch: supported
    issues_opened: supported
  workarounds:
    - D-012 raw file URLs in place of Pages
    - D-013 workflow_dispatch approval inputs in place of environments
    - D-014 workflow_dispatch API in place of repository_dispatch
  verification_toolchain:
    typecheck: bash -n + python -m py_compile (no package.json)
    test: per-phase scripts/verify_phaseNN.sh
    build: no-op
---/ci---

ARCHITECTURE.md gains a Gitea API surface table and a branch-pinning rule.
PERSONAS.md is the canonical project-level persona roster: lead-developer
and backend-engineer always active; infra-stub-engineer custom persona owns
L1 stubs; data-engineer deactivated (no DB); frontend-engineer deactivated
until Phase 05.
2026-07-21 12:58:35 +00:00
Jon Chery e5f5604319 decision(P01): clarification — project mode, pages fallback, env gates
---ci---
phase: 1
milestone: v1.0
status: clarify
decisions:
  - id: D-011
    decision: Single-project mode explicitly enforced via config.json mode=single
    rationale: run.md Step 0 reads projects[] length as multi-project trigger; explicit flag disambiguates from D-010
    confidence: 0.95
    alternatives: [move acdl into .ciagent/acdl/ subdirectory and adopt multi-project paths]
  - id: D-012
    decision: Gitea has no native Pages; serve acdl-evidence via raw file URLs + CORS note
    rationale: Research confirms Gitea has no [pages] section; raw URLs work without server config
    confidence: 0.85
    alternatives: [sidecar static server, external Pages host]
  - id: D-013
    decision: QA/Prod gates modeled as workflow_dispatch approval inputs (D-004 fallback) instead of Gitea environments
    rationale: Research confirms Gitea ignores environment: blocks and exposes no environments API
    confidence: 0.90
    alternatives: [external approval bot, drop approval gates entirely]
  - id: D-014
    decision: Cross-repo triggering uses workflow_dispatch API from inside a step (no repository_dispatch)
    rationale: Gitea Actions does not support repository_dispatch
    confidence: 0.85
    alternatives: [push-based trigger with a sentinel file, polling]
  - id: D-015
    decision: New repos acdl-contracts and acdl-evidence use default_branch=main with auto_init=true
    rationale: Matches Gitea DEFAULT_BRANCH=main; required for the default branch to exist before any push
    confidence: 0.95
    alternatives: [use milestone/v1.0-initial as default_branch]
  - id: D-016
    decision: Pages placeholder for Phase 01 is a minimal HTML stub; full timeline UI deferred to Phase 05
    rationale: Phase 01 success criterion is the URL returns 200 with placeholder; full UI is Phase 05
    confidence: 0.90
    alternatives: [build a minimal timeline now]
---/ci---

Clarifications accepted at full autonomy per clarify.md Step 4. Three requirements
re-stated: REQ-09 (new repos default_branch=main), REQ-10 Pages (raw-URL 200
substitute), REQ-10 environments (workflow_dispatch inputs + qa/prod branches).
See .ciagent/REQUIREMENTS.md Clarifications table.
2026-07-21 12:57:50 +00:00
Jon Chery 5222a460e5 chore(config): rotate Gitea token to env-var reference (security)
---ci---
phase: 0
milestone: v1.0
status: specify
security:
  - id: SEC-001
    type: info_disclosure
    disposition: mitigated
    summary: Literal API token was committed in config.json gitea.api_token_env field
    fix: Replaced literal with env var name 'ACDL_GITEA_TOKEN'; token supplied via shell env at runtime
    severity: high
    stride: Information Disclosure
---/ci---

The 40-char value previously stored in .ciagent/config.json was a live Gitea
API token. Per the spec constraint 'no secrets in repo', the field now holds
an env var name. The token itself is exported in the shell session at runtime
and is never written to disk. Treat the prior value as already-leaked and
rotate it via the Gitea UI before any external disclosure.
2026-07-21 12:55:29 +00:00
Jon Chery e3416f8e77 docs(init): initialize Agentic Cloud Delivery Platform (5 phases)
---ci---
phase: 0
milestone: v1.0
status: specify
decisions:
  - id: D-001
    decision: Use Gitea org continuous-intelligence for all ACDL repos
    rationale: User-specified target org; already exists at git.cloudinit.dev
    confidence: 0.95
    alternatives: [new dedicated demo org]
  - id: D-002
    decision: Map "GitHub Actions" to Gitea Actions (act_runner) using same workflow YAML
    rationale: Environment is Gitea; syntax-compatible with act_runner
    confidence: 0.85
    alternatives: [migrate to GitHub.com, raw shell scripts]
  - id: D-003
    decision: Collapse acdl-platform into the existing empty acdl repo
    rationale: acdl already exists at org root; avoids a 4th repo
    confidence: 0.90
    alternatives: [create separate acdl-platform repo]
  - id: D-004
    decision: Use Gitea environment blocks + required reviewers for QA/Prod; fallback to manual workflow_dispatch with approval input
    rationale: Spec mandates approval gates; forge supports environment protection
    confidence: 0.80
    alternatives: [external approval bot, no approval gates]
  - id: D-005
    decision: Hash-chained ledger (prev_hash + own hash via SHA-256 of canonical JSON) for evidence; declared demonstrative not adversarially secure
    rationale: Spec asks for simple JSON; chain gives visible tamper-evidence
    confidence: 0.85
    alternatives: [signed commits only, full Merkle tree]
  - id: D-006
    decision: Confidence gate threshold = 0.50 exactly (base 0.90, fail drops to 0.40)
    rationale: Explicit in spec
    confidence: 0.99
    alternatives: []
  - id: D-007
    decision: Each mock_apply.sh echoes "[L1: <name>] applying..." + "OK", sleeps 1s, exits 0
    rationale: Spec literal; uniformity aids timeline parsing
    confidence: 0.95
    alternatives: [randomized sleep durations]
  - id: D-008
    decision: L3B keyword->stack mapping: gas/price/ingest/data-lake->commodity-price-feed; invoice/billing->invoice-service; analytics/historical/query->energy-analytics-api; regulatory/compliance/reporting/trading->regulatory-reporting; fallback->invoice-service
    rationale: Mirrors the 4 L2 modules + Act 3 example issue text
    confidence: 0.85
    alternatives: [single default stack, ML classifier (forbidden by no-AI constraint)]
  - id: D-009
    decision: Init milestone = v1.0, branch milestone/v1.0-initial
    rationale: init.md Step 5 mandates milestone/v1.0-initial
    confidence: 0.99
    alternatives: []
  - id: D-010
    decision: Single-project mode for the acdl checkout; ---ci--- blocks omit project field
    rationale: User chose standalone single-project; no other projects in this checkout
    confidence: 0.90
    alternatives: [register acdl in /root multi-project config]
---/ci---

Specification: 30-minute executive demo of the Agentic Cloud Delivery Platform proving automatic, safe, audited infra delivery via local stubs on Gitea Actions (no cloud, no AI APIs).
Requirements: [3 repos under continuous-intelligence org, 8 L1 stub modules, 4 L2 composed modules mirroring S&P Global Energy use cases, 5 core scripts (mock_executor.sh, policy_checker.py, confidence_signal.py, evidence_writer.py, l3b_agent_stub.py), reusable Dev->QA->Prod pipeline with approval gates, issue-triggered L3B agent, Pages evidence timeline UI, 4 scripted demo acts]
Constraints: [local Linux OS, Gitea Actions + Environments, no AWS/GCP/Azure, no external LLM APIs, state in flat JSON/artifacts, EKS Fargate + serverless primitives (no VPC module), L1 single-purpose substrate-agnostic max-depth-1, L2 max-depth-5]
Out of scope: [real cloud provisioning, real LLM inference, production-grade infrastructure, adversarial tamper-proofing of evidence]
2026-07-21 12:46:33 +00:00