Files
orca/.ciagent/IDEATION_v0.13.md
T
Jon Chery a2a651e628 docs(P00): ideation results — 15 accepted (REQ-149..REQ-163), 0 skipped
Three deep codebase sweeps served as the ideation engine:
- Security: 28 findings (4 critical, 8 high, 8 medium, 6 low)
- Reliability: 37 findings (scheduler dead code, concurrency, timeouts)
- Feature/doc: 26 findings (claim-vs-reality, doc-drift)

All critical/high/medium findings mapped to 15 requirements across 14
phases. 9 low-severity residual risks documented and accepted.

---ci---
project: orca
phase: 0
milestone: v0.13
status: ideate
decisions:
  - id: D-248
    decision: "v0.13 minor not v1.0"
    confidence: 0.95
  - id: D-249
    decision: "Operator-driven UAT doc plus signoff script"
    confidence: 0.92
  - id: D-250
    decision: "All 8 themes 14 phases"
    confidence: 0.90
  - id: D-251
    decision: "Implement type linux SSH-join"
    confidence: 0.88
  - id: D-252
    decision: "Real systemctl stop via SSH"
    confidence: 0.90
  - id: D-253
    decision: "3-host UAT topology"
    confidence: 0.92
  - id: D-254
    decision: "Idempotent signoff script"
    confidence: 0.95
requirements:
  covered: [REQ-149, REQ-150, REQ-151, REQ-152, REQ-153, REQ-154, REQ-155, REQ-156, REQ-157, REQ-158, REQ-159, REQ-160, REQ-161, REQ-162, REQ-163]
---/ci---
2026-08-07 18:44:24 +00:00

4.0 KiB

IDEATION v0.13: Production Hardening Round 2

Status: complete (2026-08-07). The --ideate flag was passed. Three deep codebase sweeps (security, reliability, feature/doc claims) served as the ideation engine. All accepted ideas are captured as REQ-149..REQ-163 in REQUIREMENTS.md and mapped to phases P01..P12 in ROADMAP.md.

Ideation methodology

Standard CIAgent ideation runs three tiers:

  1. Mechanical (git-native pattern mining, coverage gap analysis, verification layer inversion, architectural drift, spec-driven)
  2. Backend-enriched (prioritization, novel suggestions, chaos engineering)
  3. Cross-project (multi-project registry mining — N/A, single project)

For v0.13, the ideation was driven by three parallel explore agents that performed deep codebase sweeps:

  • Security sweep → 28 new security findings (F26-F32 critical, F34-F42 high, F72-F77 medium, F95-F97 low)
  • Reliability sweep → 37 new reliability findings (scheduler dead code, concurrency hazards, SSH timeouts, IPv6, DB growth, cache staleness, migration safety)
  • Feature/doc sweep → 26 new claim-vs-reality / doc-drift findings (mTLS claim false, cli.md missing 25 subcommands, CHANGELOG stale, verify-reqs bypassed, help text stale)

These ~60 findings were synthesized into 15 requirements (REQ-149.. REQ-163) and 14 phases.

Accepted ideas (15 → REQ-149..REQ-163)

IDEATE-ID Category Title Confidence REQ Phase
IDEATE-01 security Go toolchain bump to 1.25.12+ (24 stdlib vulns) 0.95 REQ-149 P01
IDEATE-02 security Input validation & injection hardening (11 vectors) 0.92 REQ-150 P02
IDEATE-03 architecture Wire scheduler into job run (R-022) 0.90 REQ-151 P03
IDEATE-04 spec Fix jobspec parser: schedule/timeout silently dropped 0.95 REQ-152 P03
IDEATE-05 security Wire ACL enforcement into all request paths (R-023) 0.92 REQ-153 P04
IDEATE-06 security Seal/audit CLI + chain race + key zeroing 0.88 REQ-154 P05
IDEATE-07 security Implement auth init-idp + auth register 0.85 REQ-155 P06
IDEATE-08 reliability Concurrency safety (SQLite, flock, cache, atomic writes) 0.90 REQ-156 P07
IDEATE-09 reliability Transport & SSH safety (typed errors, IPv6, timeouts) 0.88 REQ-157 P08
IDEATE-10 reliability Migration & operational safety (job stop, DB retention, logs cap) 0.85 REQ-158 P09
IDEATE-11 quality Observability expansion (metrics, security headers) 0.82 REQ-159 P10
IDEATE-12 quality Doc drift round 2 (README, cli.md, CHANGELOG, help text, verify-reqs) 0.92 REQ-160 P11
IDEATE-13 feature Implement --type linux SSH-join 0.88 REQ-161 P12
IDEATE-14 spec UAT plan (docs/uat.md, 3-host topology, claim matrix) 0.95 REQ-162 P12
IDEATE-15 spec UAT signoff script (uat-signoff.sh, ~35 assertions, idempotent) 0.95 REQ-163 P12

Skipped ideas (0)

No ideas were skipped. All ~60 findings are addressed either as requirements (critical/high/medium) or as accepted residual risks documented in RESEARCH_v0.13.md (9 low-severity items).

Chaos engineering considerations

  • What if the scheduler picks a node that goes down mid-deploy? → R-022: SSH-push is idempotent; re-run targets the next-best node.
  • What if ACL enforcement locks out the operator? → C-40: bootstrap ACL grants cluster-admin to the init cert's SVID.
  • What if the seal key is lost? → C-41: Shamir 3-of-5 recovery; if quorum unavailable, cluster unrecoverable by design (documented, no backdoor).
  • What if concurrent upgrades race? → REQ-156: upgrade lock file refuses concurrent invocations.
  • What if the UAT signoff script has a false-pass assertion? → REQ-163: uat-smoke.sh runs the pure-CLI subset in CI validate; the full script is operator-run on bare metal.

Kickoff

All 15 ideas are accepted and mapped to phases. Proceeding to PLAN.