Jon Chery
985e8f32d5
fix(P03): l3b_agent_stub reads body from rest[0] not argv[1] (T-3.9)
...
---ci---
phase: 3
milestone: v1.0
status: execute
persona: backend-engineer
task: T-3.9
requirements:
covered: [REQ-12]
---/ci---
Wave 2, task T-3.9. parse_output_flag strips -o; read_issue_body now reads body from rest[0] (after -o removed) instead of sys.argv[1].
2026-07-21 13:27:26 +00:00
Jon Chery
1de274c35c
fix(P03): confidence_signal emits literal 0.90/0.40 (T-3.6)
...
---ci---
phase: 3
milestone: v1.0
status: execute
persona: backend-engineer
task: T-3.6
requirements:
covered: [REQ-08]
---/ci---
Wave 2, task T-3.6. json.dumps collapsed 0.90 -> 0.9; emit literal two-decimal score per contract while remaining valid JSON.
2026-07-21 13:26:46 +00:00
Jon Chery
464131fdf4
feat(P03): l3b_agent_stub.py (T-3.9)
...
---ci---
phase: 3
milestone: v1.0
status: execute
persona: backend-engineer
task: T-3.9
requirements:
covered: [REQ-12]
---/ci---
Wave 2, task T-3.9. L3B keyword parser: maps issue body text to L2 stack (D-008) and emits contract.yaml (D-021).
2026-07-21 13:26:20 +00:00
Jon Chery
28535f9f5f
feat(P03): mock_executor.sh (T-3.8)
...
---ci---
phase: 3
milestone: v1.0
status: execute
persona: backend-engineer
task: T-3.8
requirements:
covered: [REQ-06]
---/ci---
Wave 2, task T-3.8. Mock L2 composition executor: resolves manifest, invokes each L1 mock_apply.sh, writes state.json (D-022).
2026-07-21 13:25:59 +00:00
Jon Chery
4c37ad1d03
feat(P03): evidence_writer.py (T-3.7)
...
---ci---
phase: 3
milestone: v1.0
status: execute
persona: backend-engineer
task: T-3.7
requirements:
covered: [REQ-11]
---/ci---
Wave 2, task T-3.7. Hash-chained audit event writer (D-023/D-005) with auto-genesis and atomic writes.
2026-07-21 13:24:44 +00:00
Jon Chery
2be16f72b9
feat(P03): confidence_signal.py (T-3.6)
...
---ci---
phase: 3
milestone: v1.0
status: execute
persona: backend-engineer
task: T-3.6
requirements:
covered: [REQ-08]
---/ci---
Wave 2, task T-3.6. Confidence signal: 0.90 on policy pass, 0.40 on violation; exit 0 always (D-024).
2026-07-21 13:24:23 +00:00
Jon Chery
d59b4a013b
feat(P03): policy_checker.py (T-3.5)
...
---ci---
phase: 3
milestone: v1.0
status: execute
persona: backend-engineer
task: T-3.5
requirements:
covered: [REQ-07]
---/ci---
Wave 2, task T-3.5. Policy enforcement script: rejects contracts with public-ingress: true.
2026-07-21 13:24:09 +00:00
Jon Chery
090839d2e5
feat(P03): l2-regulatory-reporting manifest (T-3.4)
...
---ci---
phase: 3
milestone: v1.0
status: execute
persona: infra-stub-engineer
task: T-3.4
requirements:
covered: [REQ-04, REQ-05]
---/ci---
Wave 1, task T-3.4. Creates modules/l2/l2-regulatory-reporting/manifest.yaml composing
5 L1s by name (D-020). All referenced L1 names exist in modules/l1/.
2026-07-21 13:22:14 +00:00
Jon Chery
6394c2f5fb
feat(P03): l2-energy-analytics-api manifest (T-3.3)
...
---ci---
phase: 3
milestone: v1.0
status: execute
persona: infra-stub-engineer
task: T-3.3
requirements:
covered: [REQ-04, REQ-05]
---/ci---
Wave 1, task T-3.3. Creates modules/l2/l2-energy-analytics-api/manifest.yaml composing
5 L1s by name (D-020). All referenced L1 names exist in modules/l1/.
2026-07-21 13:22:04 +00:00
Jon Chery
5febbae940
feat(P03): l2-commodity-price-feed manifest (T-3.2)
...
---ci---
phase: 3
milestone: v1.0
status: execute
persona: infra-stub-engineer
task: T-3.2
requirements:
covered: [REQ-04, REQ-05]
---/ci---
Wave 1, task T-3.2. Creates modules/l2/l2-commodity-price-feed/manifest.yaml composing
5 L1s by name (D-020). All referenced L1 names exist in modules/l1/.
2026-07-21 13:21:40 +00:00
Jon Chery
6e7231afd5
feat(P03): l2-invoice-service manifest (T-3.1)
...
---ci---
phase: 3
milestone: v1.0
status: execute
persona: infra-stub-engineer
task: T-3.1
requirements:
covered: [REQ-04, REQ-05]
---/ci---
Wave 1, task T-3.1. Creates modules/l2/l2-invoice-service/manifest.yaml composing
5 L1s by name (D-020). All referenced L1 names exist in modules/l1/.
2026-07-21 13:21:32 +00:00
Jon Chery
e85041d67c
docs(P03): create 3-wave phase plan (REQ-04/05/06/07/08/11)
...
---ci---
phase: 3
milestone: v1.0
status: plan
plan:
waves: 3
wave_1_infra_stub: [T-3.1..T-3.4 create 4 L2 manifests]
wave_2_backend: [T-3.5 policy_checker, T-3.6 confidence_signal, T-3.7 evidence_writer, T-3.8 mock_executor, T-3.9 l3b_agent_stub]
wave_3_coordination: [T-3.10 verify_phase03, T-3.11 traceability]
requirements_covered: [REQ-04, REQ-05, REQ-06, REQ-07, REQ-08, REQ-11]
must_haves: 9
verification:
typecheck: bash -n + python -m py_compile + yaml load
test: scripts/verify_phase03.sh
build: no-op
---/ci---
PLAN.md replaced with Phase 03 plan. Wave 1 (infra-stub-engineer) creates
the 4 L2 manifests. Wave 2 (backend-engineer) creates the 5 core scripts.
Wave 3 (lead-developer) wires the verify script + traceability.
2026-07-21 13:20:48 +00:00
Jon Chery
7310da224e
docs(P03): research findings — L2/contract/state/audit/core-script schemas
...
---ci---
phase: 3
milestone: v1.0
status: research
research:
l2_schema: l1s list of {name, inputs: map}; 4 L2s each referencing 5 L1s
contract_schema: stack + inputs + optional public-ingress: bool
state_json_shape: l2, l1s array (name+applied+exit_code), contract
audit_json: JSON array; canonical-JSON SHA-256 hash chain; GENESIS prev_hash
core_script_io: 5 scripts with explicit input/output/exit contracts
personas: no change; backend-engineer owns core scripts + L2 manifests; infra-stub-engineer owns L1 manifests only
---/ci---
ARCHITECTURE.md gains the L2 manifest schema, the L2 list with per-L2
L1 references (5 each, within max-depth-5), the contract.yaml schema,
the state.json shape, the audit.json event + canonical-JSON hash chain,
and a core-script I/O contract table. PERSONAS.md is unchanged for
Phase 03 (backend-engineer and infra-stub-engineer were both already
active in the project-level roster).
2026-07-21 13:20:13 +00:00
Jon Chery
e00393adfd
decision(P03): clarification — L2/contract/evidence/hash-chain schemas
...
---ci---
phase: 3
milestone: v1.0
status: clarify
decisions:
- id: D-020
decision: L2 manifest.yaml schema with l1s: list of {name, inputs: map}
rationale: REQ-04 says L2 composes L1s; REQ-05 caps depth at 5 (L2->L1 is depth 1)
confidence: 0.90
alternatives: [graph-of-L1s with edges, single flat list of L1 names with no inputs]
- id: D-021
decision: contract.yaml schema with stack, inputs, optional public-ingress: bool
rationale: REQ-07 cites public-ingress:true as the forbidden key; REQ-08 keys off policy pass/fail
confidence: 0.90
alternatives: [separate policy file, contract-free intent]
- id: D-022
decision: mock_executor.sh writes state.json with l2, l1s array (name+applied+exit_code), contract
rationale: REQ-06 says writes state.json but does not specify shape
confidence: 0.85
alternatives: [per-L1 state files, no state file]
- id: D-023
decision: evidence_writer.py appends to audit.json (JSON array); each event has seq, ts, stage, event, prev_hash, hash (SHA-256 of canonical JSON); genesis has prev_hash=GENESIS, seq=0
rationale: D-005 mandates hash-chained ledger; canonical JSON for deterministic hashing
confidence: 0.90
alternatives: [signed commits only, append-only log file]
- id: D-024
decision: confidence_signal.py prints {score, reason} JSON to stdout; exit 0 always
rationale: REQ-08 literal: base 0.90, drops to 0.40, gate >= 0.50
confidence: 0.95
alternatives: [exit non-zero on fail, separate side-channel file]
- id: D-025
decision: policy_checker.py exits 1 with stdout POLICY_VIOLATION:PUBLIC_INGRESS on public-ingress:true; else exit 0 with stdout POLICY_PASS
rationale: REQ-07 literal
confidence: 0.99
alternatives: []
- id: D-026
decision: l3b_agent_stub.py reads issue body from argv[1] or stdin, applies D-008 keyword map, writes contract.yaml to stdout (or -o <path>)
rationale: D-008 + Act 3 example; L3B must produce same contract format as L3A
confidence: 0.90
alternatives: [fixed-output contract per stack, no -o flag]
---/ci---
Phase 03 has real ambiguities (no schema was specified for L2 manifests,
contract.yaml, audit.json events, or the L3B output format). Seven
decisions logged: D-020 L2 schema, D-021 contract.yaml schema, D-022
state.json shape, D-023 audit.json event + hash chain, D-024
confidence_signal output, D-025 policy_checker output, D-026 l3b_agent
I/O contract.
2026-07-21 13:19:43 +00:00
Jon Chery
6e27df7404
docs(P02): post-ship traceability + roadmap update (v1.0.2)
...
---ci---
phase: 2
milestone: v1.0
status: shipped
requirements:
complete: [REQ-02, REQ-03]
release:
tag: v1.0.2
pr: 2
---/ci---
ROADMAP Phase 02 -> complete (v1.0.2). REQUIREMENTS REQ-02/03 -> complete.
2026-07-21 13:18:51 +00:00
grimacing
00d0043866
ship: phase-02 l1-modules (v1.0.2)
...
Squash merge of phase/02-l1-modules into milestone/v1.0-initial; 8 L1 stub modules created; verify_phase02.sh green.
v1.0.2
2026-07-21 13:18:12 +00:00
Jon Chery
fd423e2df1
docs(P01): post-ship traceability + roadmap update (v1.0.1)
...
---ci---
phase: 1
milestone: v1.0
status: shipped
requirements:
complete: [REQ-01, REQ-09]
partial: [REQ-10, REQ-12]
release:
tag: v1.0.1
url: https://git.cloudinit.dev/continuous-intelligence/acdl/releases/tag/v1.0.1
pr: 1
---/ci---
ROADMAP Phase 01 -> complete (v1.0.1). REQUIREMENTS REQ-01/09 -> complete;
REQ-10/12 -> partial (full impl in Phase 04).
2026-07-21 13:12:01 +00:00
grimacing
8947e89d7b
ship: phase-01 repo-scaffolding (v1.0.1)
...
Squash merge of phase/01-repo-scaffolding into milestone/v1.0-initial; tagged v1.0.1.
2026-07-21 13:11:02 +00:00
Jon Chery
b953fd4a8e
docs(P01): complete repo-scaffolding phase
...
---ci---
phase: 1
milestone: v1.0
status: complete
requirements:
covered: [REQ-01, REQ-09]
partial: [REQ-10, REQ-12]
---/ci---
Squash merge of phase/01-repo-scaffolding into milestone/v1.0-initial.
Phase 01 ships the three-repo scaffold (acdl, acdl-contracts, acdl-evidence),
the placeholder index.html on acdl-evidence (D-012/D-016 raw-URL substitute
for unsupported Gitea Pages), the qa + prod branches on acdl-contracts
(D-013 stand-in for unsupported Gitea environments), the workflow skeletons
(pipeline.yml + issue-to-contract.yml), and the idempotent setup + verify
scripts. REQ-10/12 remain partial pending Phase 04 full implementation.
v1.0.1
2026-07-21 13:10:50 +00:00
Jon Chery
38eaec9337
docs(P01): create 3-wave phase plan (REQ-01/09/10)
...
---ci---
phase: 1
milestone: v1.0
status: plan
plan:
waves: 3
wave_1_coordination: [T-1.1 gitignore+layout+README, T-1.2 verify_phase01.sh]
wave_2_backend: [T-2.1 gitea_setup.sh, T-2.2 pipeline.yml skeleton, T-2.3 issue-to-contract.yml skeleton]
wave_3_coordination: [T-3.1 wire verify + traceability update]
requirements_covered: [REQ-01, REQ-09, REQ-10]
must_haves: 6
verification:
typecheck: bash -n scripts/*.sh
test: scripts/verify_phase01.sh
build: no-op
---/ci---
PLAN.md defines 3 vertical-slice waves: coordination (skeleton + verify
script), backend (Gitea setup + workflow skeletons), coordination (wiring +
traceability). infra-stub-engineer and frontend-engineer have 0 tasks this
phase. Branch for EXECUTE will be phase/01-repo-scaffolding.
2026-07-21 12:59:27 +00:00
Jon Chery
6691974445
docs(P01): research findings — Gitea API surface + persona roster
...
---ci---
phase: 1
milestone: v1.0
status: research
research:
gitea_capabilities:
pages: not_supported
environments_api: not_supported
repository_dispatch: not_supported
workflow_call: supported
workflow_dispatch: supported
issues_opened: supported
workarounds:
- D-012 raw file URLs in place of Pages
- D-013 workflow_dispatch approval inputs in place of environments
- D-014 workflow_dispatch API in place of repository_dispatch
verification_toolchain:
typecheck: bash -n + python -m py_compile (no package.json)
test: per-phase scripts/verify_phaseNN.sh
build: no-op
---/ci---
ARCHITECTURE.md gains a Gitea API surface table and a branch-pinning rule.
PERSONAS.md is the canonical project-level persona roster: lead-developer
and backend-engineer always active; infra-stub-engineer custom persona owns
L1 stubs; data-engineer deactivated (no DB); frontend-engineer deactivated
until Phase 05.
2026-07-21 12:58:35 +00:00
Jon Chery
e5f5604319
decision(P01): clarification — project mode, pages fallback, env gates
...
---ci---
phase: 1
milestone: v1.0
status: clarify
decisions:
- id: D-011
decision: Single-project mode explicitly enforced via config.json mode=single
rationale: run.md Step 0 reads projects[] length as multi-project trigger; explicit flag disambiguates from D-010
confidence: 0.95
alternatives: [move acdl into .ciagent/acdl/ subdirectory and adopt multi-project paths]
- id: D-012
decision: Gitea has no native Pages; serve acdl-evidence via raw file URLs + CORS note
rationale: Research confirms Gitea has no [pages] section; raw URLs work without server config
confidence: 0.85
alternatives: [sidecar static server, external Pages host]
- id: D-013
decision: QA/Prod gates modeled as workflow_dispatch approval inputs (D-004 fallback) instead of Gitea environments
rationale: Research confirms Gitea ignores environment: blocks and exposes no environments API
confidence: 0.90
alternatives: [external approval bot, drop approval gates entirely]
- id: D-014
decision: Cross-repo triggering uses workflow_dispatch API from inside a step (no repository_dispatch)
rationale: Gitea Actions does not support repository_dispatch
confidence: 0.85
alternatives: [push-based trigger with a sentinel file, polling]
- id: D-015
decision: New repos acdl-contracts and acdl-evidence use default_branch=main with auto_init=true
rationale: Matches Gitea DEFAULT_BRANCH=main; required for the default branch to exist before any push
confidence: 0.95
alternatives: [use milestone/v1.0-initial as default_branch]
- id: D-016
decision: Pages placeholder for Phase 01 is a minimal HTML stub; full timeline UI deferred to Phase 05
rationale: Phase 01 success criterion is the URL returns 200 with placeholder; full UI is Phase 05
confidence: 0.90
alternatives: [build a minimal timeline now]
---/ci---
Clarifications accepted at full autonomy per clarify.md Step 4. Three requirements
re-stated: REQ-09 (new repos default_branch=main), REQ-10 Pages (raw-URL 200
substitute), REQ-10 environments (workflow_dispatch inputs + qa/prod branches).
See .ciagent/REQUIREMENTS.md Clarifications table.
2026-07-21 12:57:50 +00:00
Jon Chery
5222a460e5
chore(config): rotate Gitea token to env-var reference (security)
...
---ci---
phase: 0
milestone: v1.0
status: specify
security:
- id: SEC-001
type: info_disclosure
disposition: mitigated
summary: Literal API token was committed in config.json gitea.api_token_env field
fix: Replaced literal with env var name 'ACDL_GITEA_TOKEN'; token supplied via shell env at runtime
severity: high
stride: Information Disclosure
---/ci---
The 40-char value previously stored in .ciagent/config.json was a live Gitea
API token. Per the spec constraint 'no secrets in repo', the field now holds
an env var name. The token itself is exported in the shell session at runtime
and is never written to disk. Treat the prior value as already-leaked and
rotate it via the Gitea UI before any external disclosure.
2026-07-21 12:55:29 +00:00
Jon Chery
e3416f8e77
docs(init): initialize Agentic Cloud Delivery Platform (5 phases)
...
---ci---
phase: 0
milestone: v1.0
status: specify
decisions:
- id: D-001
decision: Use Gitea org continuous-intelligence for all ACDL repos
rationale: User-specified target org; already exists at git.cloudinit.dev
confidence: 0.95
alternatives: [new dedicated demo org]
- id: D-002
decision: Map "GitHub Actions" to Gitea Actions (act_runner) using same workflow YAML
rationale: Environment is Gitea; syntax-compatible with act_runner
confidence: 0.85
alternatives: [migrate to GitHub.com, raw shell scripts]
- id: D-003
decision: Collapse acdl-platform into the existing empty acdl repo
rationale: acdl already exists at org root; avoids a 4th repo
confidence: 0.90
alternatives: [create separate acdl-platform repo]
- id: D-004
decision: Use Gitea environment blocks + required reviewers for QA/Prod; fallback to manual workflow_dispatch with approval input
rationale: Spec mandates approval gates; forge supports environment protection
confidence: 0.80
alternatives: [external approval bot, no approval gates]
- id: D-005
decision: Hash-chained ledger (prev_hash + own hash via SHA-256 of canonical JSON) for evidence; declared demonstrative not adversarially secure
rationale: Spec asks for simple JSON; chain gives visible tamper-evidence
confidence: 0.85
alternatives: [signed commits only, full Merkle tree]
- id: D-006
decision: Confidence gate threshold = 0.50 exactly (base 0.90, fail drops to 0.40)
rationale: Explicit in spec
confidence: 0.99
alternatives: []
- id: D-007
decision: Each mock_apply.sh echoes "[L1: <name>] applying..." + "OK", sleeps 1s, exits 0
rationale: Spec literal; uniformity aids timeline parsing
confidence: 0.95
alternatives: [randomized sleep durations]
- id: D-008
decision: L3B keyword->stack mapping: gas/price/ingest/data-lake->commodity-price-feed; invoice/billing->invoice-service; analytics/historical/query->energy-analytics-api; regulatory/compliance/reporting/trading->regulatory-reporting; fallback->invoice-service
rationale: Mirrors the 4 L2 modules + Act 3 example issue text
confidence: 0.85
alternatives: [single default stack, ML classifier (forbidden by no-AI constraint)]
- id: D-009
decision: Init milestone = v1.0, branch milestone/v1.0-initial
rationale: init.md Step 5 mandates milestone/v1.0-initial
confidence: 0.99
alternatives: []
- id: D-010
decision: Single-project mode for the acdl checkout; ---ci--- blocks omit project field
rationale: User chose standalone single-project; no other projects in this checkout
confidence: 0.90
alternatives: [register acdl in /root multi-project config]
---/ci---
Specification: 30-minute executive demo of the Agentic Cloud Delivery Platform proving automatic, safe, audited infra delivery via local stubs on Gitea Actions (no cloud, no AI APIs).
Requirements: [3 repos under continuous-intelligence org, 8 L1 stub modules, 4 L2 composed modules mirroring S&P Global Energy use cases, 5 core scripts (mock_executor.sh, policy_checker.py, confidence_signal.py, evidence_writer.py, l3b_agent_stub.py), reusable Dev->QA->Prod pipeline with approval gates, issue-triggered L3B agent, Pages evidence timeline UI, 4 scripted demo acts]
Constraints: [local Linux OS, Gitea Actions + Environments, no AWS/GCP/Azure, no external LLM APIs, state in flat JSON/artifacts, EKS Fargate + serverless primitives (no VPC module), L1 single-purpose substrate-agnostic max-depth-1, L2 max-depth-5]
Out of scope: [real cloud provisioning, real LLM inference, production-grade infrastructure, adversarial tamper-proofing of evidence]
2026-07-21 12:46:33 +00:00