Three deep codebase sweeps served as the ideation engine:
- Security: 28 findings (4 critical, 8 high, 8 medium, 6 low)
- Reliability: 37 findings (scheduler dead code, concurrency, timeouts)
- Feature/doc: 26 findings (claim-vs-reality, doc-drift)
All critical/high/medium findings mapped to 15 requirements across 14
phases. 9 low-severity residual risks documented and accepted.
---ci---
project: orca
phase: 0
milestone: v0.13
status: ideate
decisions:
- id: D-248
decision: "v0.13 minor not v1.0"
confidence: 0.95
- id: D-249
decision: "Operator-driven UAT doc plus signoff script"
confidence: 0.92
- id: D-250
decision: "All 8 themes 14 phases"
confidence: 0.90
- id: D-251
decision: "Implement type linux SSH-join"
confidence: 0.88
- id: D-252
decision: "Real systemctl stop via SSH"
confidence: 0.90
- id: D-253
decision: "3-host UAT topology"
confidence: 0.92
- id: D-254
decision: "Idempotent signoff script"
confidence: 0.95
requirements:
covered: [REQ-149, REQ-150, REQ-151, REQ-152, REQ-153, REQ-154, REQ-155, REQ-156, REQ-157, REQ-158, REQ-159, REQ-160, REQ-161, REQ-162, REQ-163]
---/ci---
4.0 KiB
IDEATION v0.13: Production Hardening Round 2
Status: complete (2026-08-07). The --ideate flag was passed. Three
deep codebase sweeps (security, reliability, feature/doc claims)
served as the ideation engine. All accepted ideas are captured as
REQ-149..REQ-163 in REQUIREMENTS.md and mapped to phases P01..P12 in
ROADMAP.md.
Ideation methodology
Standard CIAgent ideation runs three tiers:
- Mechanical (git-native pattern mining, coverage gap analysis, verification layer inversion, architectural drift, spec-driven)
- Backend-enriched (prioritization, novel suggestions, chaos engineering)
- Cross-project (multi-project registry mining — N/A, single project)
For v0.13, the ideation was driven by three parallel explore agents
that performed deep codebase sweeps:
- Security sweep → 28 new security findings (F26-F32 critical, F34-F42 high, F72-F77 medium, F95-F97 low)
- Reliability sweep → 37 new reliability findings (scheduler dead code, concurrency hazards, SSH timeouts, IPv6, DB growth, cache staleness, migration safety)
- Feature/doc sweep → 26 new claim-vs-reality / doc-drift findings (mTLS claim false, cli.md missing 25 subcommands, CHANGELOG stale, verify-reqs bypassed, help text stale)
These ~60 findings were synthesized into 15 requirements (REQ-149.. REQ-163) and 14 phases.
Accepted ideas (15 → REQ-149..REQ-163)
| IDEATE-ID | Category | Title | Confidence | REQ | Phase |
|---|---|---|---|---|---|
| IDEATE-01 | security | Go toolchain bump to 1.25.12+ (24 stdlib vulns) | 0.95 | REQ-149 | P01 |
| IDEATE-02 | security | Input validation & injection hardening (11 vectors) | 0.92 | REQ-150 | P02 |
| IDEATE-03 | architecture | Wire scheduler into job run (R-022) | 0.90 | REQ-151 | P03 |
| IDEATE-04 | spec | Fix jobspec parser: schedule/timeout silently dropped | 0.95 | REQ-152 | P03 |
| IDEATE-05 | security | Wire ACL enforcement into all request paths (R-023) | 0.92 | REQ-153 | P04 |
| IDEATE-06 | security | Seal/audit CLI + chain race + key zeroing | 0.88 | REQ-154 | P05 |
| IDEATE-07 | security | Implement auth init-idp + auth register | 0.85 | REQ-155 | P06 |
| IDEATE-08 | reliability | Concurrency safety (SQLite, flock, cache, atomic writes) | 0.90 | REQ-156 | P07 |
| IDEATE-09 | reliability | Transport & SSH safety (typed errors, IPv6, timeouts) | 0.88 | REQ-157 | P08 |
| IDEATE-10 | reliability | Migration & operational safety (job stop, DB retention, logs cap) | 0.85 | REQ-158 | P09 |
| IDEATE-11 | quality | Observability expansion (metrics, security headers) | 0.82 | REQ-159 | P10 |
| IDEATE-12 | quality | Doc drift round 2 (README, cli.md, CHANGELOG, help text, verify-reqs) | 0.92 | REQ-160 | P11 |
| IDEATE-13 | feature | Implement --type linux SSH-join | 0.88 | REQ-161 | P12 |
| IDEATE-14 | spec | UAT plan (docs/uat.md, 3-host topology, claim matrix) | 0.95 | REQ-162 | P12 |
| IDEATE-15 | spec | UAT signoff script (uat-signoff.sh, ~35 assertions, idempotent) | 0.95 | REQ-163 | P12 |
Skipped ideas (0)
No ideas were skipped. All ~60 findings are addressed either as requirements (critical/high/medium) or as accepted residual risks documented in RESEARCH_v0.13.md (9 low-severity items).
Chaos engineering considerations
- What if the scheduler picks a node that goes down mid-deploy? → R-022: SSH-push is idempotent; re-run targets the next-best node.
- What if ACL enforcement locks out the operator? → C-40: bootstrap ACL grants cluster-admin to the init cert's SVID.
- What if the seal key is lost? → C-41: Shamir 3-of-5 recovery; if quorum unavailable, cluster unrecoverable by design (documented, no backdoor).
- What if concurrent upgrades race? → REQ-156: upgrade lock file refuses concurrent invocations.
- What if the UAT signoff script has a false-pass assertion? → REQ-163: uat-smoke.sh runs the pure-CLI subset in CI validate; the full script is operator-run on bare metal.
Kickoff
All 15 ideas are accepted and mapped to phases. Proceeding to PLAN.