Phase 0: SPECIFY → CLARIFY → RESEARCH → IDEATE → PLAN → GRILL. NFR milestone v1.16 (Nova Simplification), 20 execution phases + final. Tags on v1.15.x line: v1.15.5 (this phase) → v1.15.6..v1.15.25 (P1-P20) → v1.15.26 (P21 final = release). Scope (D-113..D-119): Simplify without regressions, Security, Maintainability, User/Developer Experience, No Humans Onboarding Flow (request-path only; real AWS provisioning deferred). Regression gate (D-118, G-111) gates P9 + P21 at 20/22 Verified + 2 Skipped. Grill: PASS-with-binding (G-111..G-113, E-002 deferred to P21). ---ci--- project: acdl phase: 0 milestone: v1.16 status: complete phase_role: pre_execution requirements: covered: [REQ-165, REQ-166, REQ-167, REQ-168, REQ-169, REQ-170, REQ-171, REQ-172, REQ-173, REQ-174, REQ-175, REQ-176, REQ-177, REQ-178, REQ-179, REQ-180, REQ-181, REQ-182, REQ-183, REQ-184] partial: [] ---/ci---
19 KiB
project, milestone, generated_at, generator, verification_toolchain
| project | milestone | generated_at | generator | verification_toolchain | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| acdl | v1.16 | 2026-07-30 | lead-developer |
|
ACDL — Persona Roster (project-level, v1.11 RESTART)
v1.11 is a restart (D-097). The v1.9 roster is superseded. Three structural corrections: (1) stateless adapter (D-098), (2) terraform owns lifecycle (D-101), (3) pipeline-driven testing (D-102). The roster is simplified to the three active domains: data (terraform foundation), backend (adapter/resolver), general (pipelines/workflows).
Active personas
lead-developer
- Domain: coordination
- Active: true
- Phase-specific: false
- Reason: Owns CIAgent metadata, cross-phase verification scripts, the v1.11 phase orchestration (D-107: P56a + P56b split), and arbitrates persona conflicts. Resolves the milestone decomposition and the STANDARDS.md §8 rewrite (the adapter extension pattern is replaced by the per-module terraform subdir pattern).
backend-engineer
- Domain: backend
- Active: true
- Phase-specific: false
- Reason: Owns the adapter rewrite (D-098: stateless assembler — deletes TYPE_MAP/INPUT_MAP/OUTPUT_MAP + 39 type-specific branches, becomes a ~80-line assembler that emits
module "x" { source = "..." ... }blocks) and the contract resolver env-aware state keys (D-106:spike/{id}/{env}/terraform.tfstate). The adapter holds no module content; the engine binding lives in the per-moduleterraform/subdir. Co-authoring expected on the adapter +run_platform.shboundary (general adds--apply/--destroymodes that invoke the adapter). - Territory:
adapters/terraform/adapter.py(rewrite to stateless assembler),core/contract_resolver.py(env-aware state keys, deterministic composition),schemas/stack.schema.json(if the stack instance shape changes),tests/test_adapter*.py(regression baseline — the s3 instance.json round-trip must still pass).
data-engineer
- Domain: data
- Active: true
- Phase-specific: false
- Reason: Reactivated for v1.11. Owns the heaviest territory: the per-module
terraform/subdirs (D-098/D-099/D-100 — the engine binding) for all 12 L1 modules, plus the single platform VPC (D-105:terraform/platformowns ONE VPC; the microservice composition drops itsvpcchild and references the platform VPC via data source). Each L1 module ships a real terraform module dir (versions/variables/locals/main/outputs.tf) owning its resource shape, nested blocks, and defaults.locals.tfis used heavily to centralize default interpolation (D-099). Multi-resource modules get the full 5-file split; trivial single-resource modules may inline locals in main.tf. This is the binding constraint — the stateless adapter cannot be written until the reference s3 module exists (D-107: P56a proves the design with s3 first). - Territory:
terraform/(platform VPC, D-105),modules/l1/*/terraform/(per-module terraform subdirs — the engine binding),modules/l1/*/interface.json(defaults move from adapter to interface inputs),modules/registry.json(terraform_dir field),modules/l2/microservice/composition.json(drop the vpc child, D-105),modules/STANDARDS.md§8 (rewrite the adapter extension pattern → per-module terraform subdir pattern).
general (lead-developer + backend-engineer pipeline work)
- Domain: coordination + pipelines
- Active: true
- Phase-specific: false
- Reason: Owns the pipeline-driven testing (D-102/D-103/D-104) and the terraform lifecycle modes (D-101). The modules-lifecycle pipeline (Gitea + GitHub, byte-identical) matrix-runs each L1 module's
examples/{simple,complex}.ymlcontracts through apply→modify→destroy against live AWS.run_platform.shgains--applyand--destroymodes; Python never runs terraform.verify_deploy_microservice.pyis deleted (D-101). Co-authoring expected on therun_platform.shboundary (backend-engineer rewrites the adapter thatrun_platform.shinvokes). - Territory:
pipelines/modules-lifecycle.yml,.gitea/workflows/modules-lifecycle.yml+.github/workflows/modules-lifecycle.yml(byte-identical, D-102),scripts/run_platform.sh(--apply/--destroymodes, D-101),scripts/run_primitive_plan.sh(if extended for lifecycle),scripts/run_pattern_plan.sh(if extended),pipelines/README.md(document the new pipeline),schemas/deploy-pipeline.schema.json(if the lifecycle stages are added to the contract).
Deactivated personas
lambda-engineer (custom, v1.9 — deactivated for v1.11)
- Domain: serverless
- Active: false
- Phase-specific: false
- Reason: No per-module Python this milestone (D-102: testing is pipeline-driven, not pytest). The v1.9 Lambda (
core/lambda/contract_ingestor.py) and theterraform/platform/main.tfLambda/DynamoDB/KMS/Secrets definitions persist from v1.9 but are not touched in v1.11. Theacdl-sod-haltSNS topic and the attestation matrix are out of scope. Removed from the roster for v1.11; reactivates if a future milestone touches the Lambda.
platform-engineer (custom, v1.9 — folded into data-engineer for v1.11)
- Domain: infra
- Active: false
- Phase-specific: false
- Reason: The v1.11 scope (D-097..D-107) is terraform module authoring + adapter rewrite + pipelines — not the v1.9-era L1/L2 IR-typed module authoring or the AWS OIDC bootstrap. The platform-engineer's v1.9 territory (
adapters/terraform/**,modules/**,terraform/**) is split: the adapter goes to backend-engineer (rewrite), the per-module terraform subdirs + platform VPC go to data-engineer (the heaviest v1.11 work). Folded into data-engineer for v1.11; reactivates if a future milestone does IR-shaped module authoring or OIDC bootstrap work.
security-engineer (custom, v1.9 — deactivated for v1.11)
- Domain: security
- Active: false
- Phase-specific: false
- Reason: The v1.11 scope does not touch Wiz/Kyverno/Checkov adapters, the HITL matrix, separation-of-duties, or the audit ledger. The security-engineer's v1.9 territory persists but is not touched. Removed from the roster for v1.11; reactivates if a future milestone touches security adapters or HITL gates.
frontend-engineer
- Domain: frontend
- Active: false
- Phase-specific: false
- Reason: The evidence timeline UI (
evidence-ui/**) is unchanged from v1.0 and not touched in v1.11. Removed from the active roster; reactivates if a future milestone touches the timeline UI.
data-engineer (v1.9 — was deactivated, reactivated for v1.11)
- Domain: data
- Active: true (reactivated)
- Phase-specific: false
- Reason: See the active
data-engineerentry above. The v1.9 deactivation rationale ("No ORM/persistence framework") no longer applies — v1.11's data-engineer owns terraform module authoring, not a data persistence layer.
infra-stub-engineer (custom, v1.0 only)
- Domain: backend
- Active: false
- Reason: Owned L1 stub modules in the v1.0 demo. The demo is archived to
demo/; real L1 modules are owned by data-engineer (v1.11). Not reactivated.
Phase-specific overrides
| Phase | Personas active | Notes |
|---|---|---|
| 56a adapter-rewrite-and-s3-reference-module | data-engineer (lead: s3 reference terraform module — proves the design), backend-engineer (lead: stateless adapter rewrite — emits module blocks for s3), general (run_platform.sh --apply/--destroy skeleton) | security/lambda/frontend idle |
| 56b remaining-11-l1-module-terraform-subdirs | data-engineer (lead: author 11 L1 module terraform subdirs — vpc, ecs-cluster, ecs-service, iam-role, alb, ecr, cloudfront, waf, rds, kms-key, uptime), backend-engineer (adapter: confirm each module round-trips through the assembler), general (modules-lifecycle pipeline wiring) | security/lambda/frontend idle |
| (modules-lifecycle pipeline) | general (lead: byte-identical Gitea+GitHub workflow + matrix apply→modify→destroy), data-engineer (examples/{simple,complex}.yml contracts as the modify variants), backend-engineer (adapter confirms the lifecycle cells resolve) | security/lambda/frontend idle |
| (platform VPC + composition drop) | data-engineer (lead: terraform/platform VPC + microservice composition drops vpc child, D-105), backend-engineer (resolver: env-aware state keys, D-106) | general/security/lambda/frontend idle |
| verify | lead-developer (lead: 4-layer verification), all active personas (review their territory) | — |
| review-audit-complete | lead-developer (lead: review + audit + milestone completion), all active personas (review participation) | — |
Domain priority (used by TaskDecomposer)
data → backend → general
Rationale: in v1.11, the terraform foundation (per-module terraform/
subdirs + platform VPC) is the binding constraint — the stateless adapter
cannot be written until the reference s3 module exists (D-107: P56a
proves the design with s3 first). Backend (adapter/resolver) follows once
the module shape is proven. General (pipelines/workflows) wires the
lifecycle modes last, once the adapter + modules produce valid terraform.
Conflict resolutions (lead-developer arbitration)
backend-engineervsdata-engineerovermodules/l1/*/interface.json: data-engineer owns the interface defaults (defaults move from the adapter to the interface inputs, D-100); backend-engineer owns the adapter that reads them. Co-authoring is expected; conflict goes to lead-developer.backend-engineervsgeneraloverscripts/run_platform.sh: backend-engineer rewrites the adapter thatrun_platform.shinvokes; general adds the--apply/--destroymodes. The interface (the CLI flags + the adapter invocation) is co-authored; conflicts go to lead-developer.data-engineervsgeneralovermodules/l1/*/examples/: data-engineer owns the example contracts (the modify variants, D-103); general owns the pipeline that matrix-runs them. Co-authoring is expected; conflicts go to lead-developer.lead-developervs any: lead-developer owns.ciagent/**+docs/**meta + verification scripts +modules/STANDARDS.md§8 rewrite; persona engineers do not edit CIAgent metadata or the vision/architecture source docs.
Territory enforcement mode
warn — config.json has no personas.territory_enforcement field, so the
default per execute.md is warn. Cross-territory edits are logged in the
commit message but do not fail the task. v1.11's scope means co-authoring
across territories is likely (e.g. backend + general on the adapter +
run_platform.sh boundary; data + general on the examples + pipeline
boundary); warn keeps it frictionless.
v1.15 Persona Addendum — Nova Rebrand (2026-07-30)
Milestone: v1.15-Nova. The roster carries forward from v1.11/v1.14 unchanged — the rebrand touches existing territories, no new domains. frontend-engineer remains deactivated (no UI; decks are markdown = lead-developer territory). No security-engineer persona is activated — the ABAC session-policy + tag-key migration (REQ-162) is data-engineer territory (terraform IAM) with lead-developer review.
v1.15 territory assignments
| Phase | Lead | Contributors | Territory |
|---|---|---|---|
| P1 docs-decks-prose | lead-developer | — | README.md, docs/**, .ciagent/*.md, deck .md/-marp.md/-talking-points.md/.html, docs/presentations/assets/mmd/*.mmd (+ PNG re-export), pyproject.toml, schemas/*.schema.json $id (D-110), docs/NOVA_MIGRATION.md, .github/workflows/release.yml title, modules/STANDARDS.md |
| P2 code-envvars-consumer-path | backend-engineer | lead-developer (docs/runbook) | core/env.py (NEW dual-read helper, D-108), core/*.py (call-site migration), scripts/*.py + *.sh, adapters/**, tests/**, .gitea/workflows/** + .github/workflows/**, .env + .env.secrets (key rename), schemas/tagging-standard.json, adapters/terraform/policy/custom_rules/acdl_tagging.py → nova_tagging.py (D-109: warn mode) |
| P3 ssm-tagkeys | data-engineer | backend-engineer (readers) | core/output_publisher.py (SSM path /nova/), core/contract_resolver.py (SSM reads), scripts/migrate_ssm_paths.py (NEW), terraform/** (tag keys nova:*), adapters/terraform/policy/custom_rules/nova_tagging.py (D-109: hard mode), ABAC session-policy terraform |
| P4 aws-resource-migration | data-engineer | lead-developer (runbook) | terraform/platform/main.tf, terraform/microservice/main.tf, terraform/ci-vpc/main.tf, terraform/bootstrap/**, modules/l1/alb/instance.json, scripts/migrate_dynamodb_data.py (NEW), docs/NOVA_AWS_MIGRATION.md (NEW runbook), core/lambda/contract_ingestor.py (default table names → nova-*, D-111) |
| P5 final-review-ship | lead-developer | all active (review) | .ciagent/** (REQUIREMENTS/ROADMAP/PROJECT complete), core/env.py (remove dual-read fallback), nova_tagging.py (hard-fail acdl:*), review + audit |
v1.15 domain priority
lead → backend → data (inverted from v1.11)
Rationale: the rebrand is docs/prose-first (P1 establishes the
vocabulary, no runtime impact), then code/env-vars/consumer-path (P2),
then SSM/tag-keys (P3), then the heavy terraform/AWS migration (P4).
Lead-developer owns the docs + runbooks + verification + final ship;
backend-engineer owns the dual-read helper + call-site migration +
contract resolver; data-engineer owns the terraform resource/tag/SSM
migration (the heaviest terraform territory). Co-authoring expected at:
core/env.py + core/*.py boundary (backend + lead on the helper
design), nova_tagging.py + schemas/tagging-standard.json boundary
(backend authors the rule, data-engineer owns the tag-key schema),
core/output_publisher.py SSM path + terraform outputs boundary
(backend writes the reader, data-engineer owns the terraform that
produces the outputs).
v1.15 verification toolchain (unchanged from v1.14)
typecheck: terraform validate && python3 -m py_compile core/**/*.py adapters/**/*.py
test: bash scripts/run_regression.sh # 16-capability gate
build: bash scripts/run_ci.sh # full local CI reproduction
The regression gate (CAP-001..CAP-016) must stay 16/16 Verified
throughout the rebrand — the rebrand must not regress any capability.
P2/P3/P4 update test fixtures that reference ACDL/acdl so the gate
stays green.
v1.16 Persona Addendum — Nova Simplification (2026-07-30)
Milestone: v1.16-Nova-Simplification (NFR). Roster carries forward unchanged — NFR work touches existing territories, no new domains. The onboarding request-path (P18–P20) is backend-engineer (Lambda action + onboarding.py) + data-engineer (cross-account Terraform) territory. frontend-engineer remains deactivated. No security-engineer persona — the ingestor defense-in-depth (P10) is backend-engineer with lead-developer review; IAM/ABAC (P20) is data-engineer territory.
v1.16 territory assignments
| Phase | Lead | Contributors | Territory |
|---|---|---|---|
| P1 state-bucket+kyverno fix | backend-engineer | data-engineer (kyverno policy) | adapters/terraform/adapter.py:117, adapters/kyverno/policies/require-resource-labels.yml |
| P2 user-facing brand sweep | lead-developer | backend-engineer | core/environment_check.py, core/lambda/contract_ingestor.py, scripts/post_stage_comment.sh, scripts/run_ci.sh, module docstrings, adapters/README.md |
| P3 dead-code+stale-prefix | lead-developer | — | scripts/run_platform.sh, core/local_emulators.py, core/regression_verify.py, lifecycle scripts |
| P4 migrate-ssm except | backend-engineer | — | scripts/migrate_ssm_paths.py |
| P5 regression-verify dedup | backend-engineer | — | core/regression_verify.py |
| P6 run-platform deadcode+hitl-fn | lead-developer | — | scripts/run_platform.sh |
| P7 contract-resolver envloader+kind | backend-engineer | — | core/contract_resolver.py, modules/registry.json |
| P8 workflow generator | lead-developer | backend-engineer (test) | scripts/sync_workflows.py (NEW), tests/test_pipeline_contract.py, .gitea/workflows/**, .github/workflows/** |
| P9 run-platform split | lead-developer | — | scripts/run_platform.sh, scripts/run_decommission.sh (NEW), scripts/run_uptime.sh (NEW) |
| P10 ingestor defense-in-depth | backend-engineer | lead-developer (review) | core/lambda/contract_ingestor.py, core/environments/ |
| P11 ingestor payload validation | backend-engineer | — | core/lambda/contract_ingestor.py |
| P12 split contract-resolver | backend-engineer | — | core/contract_resolver.py → core/contract_resolve.py + core/decommission_transform.py + core/contract_resolver_cli.py |
| P13 split regression-verify | backend-engineer | — | core/regression_verify.py → split modules |
| P14 schema-driven outputs+cache | backend-engineer | data-engineer (interface.json) | core/output_publisher.py, core/contract_resolver.py, modules/l1/*/interface.json |
| P15 run-platform --help+flags | lead-developer | — | scripts/run_platform.sh, README.md |
| P16 workflows README catalog | lead-developer | — | .github/workflows/README.md (NEW) |
| P17 getting-started consolidation | lead-developer | — | README.md |
| P18 onboarding schema+lambda | backend-engineer | lead-developer (schema) | schemas/onboarding.schema.json (NEW), core/lambda/contract_ingestor.py |
| P19 onboarding envfile autogen | backend-engineer | lead-developer (docs) | core/onboarding.py (NEW), core/environment_check.py, core/environments/README.md |
| P20 cross-account role offline | data-engineer | backend-engineer (ABAC) | terraform/onboarding/ (NEW), terraform/platform/main.tf |
| P21 final-review-ship | lead-developer | all active (review) | .ciagent/**, review + audit + ship |
v1.16 domain priority
backend → lead → data (the simplification + security + ingestor work
is backend-heavy; lead-developer owns docs/DX/splits; data-engineer owns
the P20 cross-account Terraform only).
v1.16 verification toolchain
typecheck: terraform validate && python3 -m py_compile core/**/*.py adapters/**/*.py
test: bash scripts/run_regression.sh # 22-capability gate (D-118: P9 + P21)
build: bash scripts/run_ci.sh # full local CI reproduction
The regression gate (22 capabilities) must stay 22/22 Verified throughout v1.16 — simplification must not regress any capability (D-118). P9 (end of Wave 2) and P21 (milestone complete) run the gate; P14 (end of Wave 3) is an offline mid-milestone checkpoint.