diff --git a/.ciagent/IDEATION_v0.13.md b/.ciagent/IDEATION_v0.13.md new file mode 100644 index 0000000..34ea918 --- /dev/null +++ b/.ciagent/IDEATION_v0.13.md @@ -0,0 +1,76 @@ +# IDEATION v0.13: Production Hardening Round 2 + +**Status**: complete (2026-08-07). The `--ideate` flag was passed. Three +deep codebase sweeps (security, reliability, feature/doc claims) +served as the ideation engine. All accepted ideas are captured as +REQ-149..REQ-163 in REQUIREMENTS.md and mapped to phases P01..P12 in +ROADMAP.md. + +## Ideation methodology + +Standard CIAgent ideation runs three tiers: +1. **Mechanical** (git-native pattern mining, coverage gap analysis, + verification layer inversion, architectural drift, spec-driven) +2. **Backend-enriched** (prioritization, novel suggestions, chaos + engineering) +3. **Cross-project** (multi-project registry mining — N/A, single + project) + +For v0.13, the ideation was driven by three parallel `explore` agents +that performed deep codebase sweeps: +- **Security sweep** → 28 new security findings (F26-F32 critical, + F34-F42 high, F72-F77 medium, F95-F97 low) +- **Reliability sweep** → 37 new reliability findings (scheduler dead + code, concurrency hazards, SSH timeouts, IPv6, DB growth, cache + staleness, migration safety) +- **Feature/doc sweep** → 26 new claim-vs-reality / doc-drift findings + (mTLS claim false, cli.md missing 25 subcommands, CHANGELOG stale, + verify-reqs bypassed, help text stale) + +These ~60 findings were synthesized into 15 requirements (REQ-149.. +REQ-163) and 14 phases. + +## Accepted ideas (15 → REQ-149..REQ-163) + +| IDEATE-ID | Category | Title | Confidence | REQ | Phase | +|-----------|----------|-------|------------|-----|-------| +| IDEATE-01 | security | Go toolchain bump to 1.25.12+ (24 stdlib vulns) | 0.95 | REQ-149 | P01 | +| IDEATE-02 | security | Input validation & injection hardening (11 vectors) | 0.92 | REQ-150 | P02 | +| IDEATE-03 | architecture | Wire scheduler into job run (R-022) | 0.90 | REQ-151 | P03 | +| IDEATE-04 | spec | Fix jobspec parser: schedule/timeout silently dropped | 0.95 | REQ-152 | P03 | +| IDEATE-05 | security | Wire ACL enforcement into all request paths (R-023) | 0.92 | REQ-153 | P04 | +| IDEATE-06 | security | Seal/audit CLI + chain race + key zeroing | 0.88 | REQ-154 | P05 | +| IDEATE-07 | security | Implement auth init-idp + auth register | 0.85 | REQ-155 | P06 | +| IDEATE-08 | reliability | Concurrency safety (SQLite, flock, cache, atomic writes) | 0.90 | REQ-156 | P07 | +| IDEATE-09 | reliability | Transport & SSH safety (typed errors, IPv6, timeouts) | 0.88 | REQ-157 | P08 | +| IDEATE-10 | reliability | Migration & operational safety (job stop, DB retention, logs cap) | 0.85 | REQ-158 | P09 | +| IDEATE-11 | quality | Observability expansion (metrics, security headers) | 0.82 | REQ-159 | P10 | +| IDEATE-12 | quality | Doc drift round 2 (README, cli.md, CHANGELOG, help text, verify-reqs) | 0.92 | REQ-160 | P11 | +| IDEATE-13 | feature | Implement --type linux SSH-join | 0.88 | REQ-161 | P12 | +| IDEATE-14 | spec | UAT plan (docs/uat.md, 3-host topology, claim matrix) | 0.95 | REQ-162 | P12 | +| IDEATE-15 | spec | UAT signoff script (uat-signoff.sh, ~35 assertions, idempotent) | 0.95 | REQ-163 | P12 | + +## Skipped ideas (0) + +No ideas were skipped. All ~60 findings are addressed either as +requirements (critical/high/medium) or as accepted residual risks +documented in RESEARCH_v0.13.md (9 low-severity items). + +## Chaos engineering considerations + +- **What if the scheduler picks a node that goes down mid-deploy?** + → R-022: SSH-push is idempotent; re-run targets the next-best node. +- **What if ACL enforcement locks out the operator?** + → C-40: bootstrap ACL grants cluster-admin to the init cert's SVID. +- **What if the seal key is lost?** + → C-41: Shamir 3-of-5 recovery; if quorum unavailable, cluster + unrecoverable by design (documented, no backdoor). +- **What if concurrent upgrades race?** + → REQ-156: upgrade lock file refuses concurrent invocations. +- **What if the UAT signoff script has a false-pass assertion?** + → REQ-163: uat-smoke.sh runs the pure-CLI subset in CI validate; + the full script is operator-run on bare metal. + +## Kickoff + +All 15 ideas are accepted and mapped to phases. Proceeding to PLAN.