docs: plan PSD survey remediation checklist
This commit is contained in:
@@ -0,0 +1,120 @@
|
||||
# PSD Survey Remediation Checklist Implementation Plan
|
||||
|
||||
> **For agentic workers:** REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (`- [ ]`) syntax for tracking.
|
||||
|
||||
**Goal:** Create one versioned, secret-free operational checklist for discussing and closing the ten PSD survey blockers one at a time.
|
||||
|
||||
**Architecture:** A single Markdown document under `docs/operations/` owns the current activity, resume marker, status summary, per-activity discussion record, and final re-survey gate. Protected evidence remains outside Git and is referenced only by path, digest, timestamp, or sanitized result.
|
||||
|
||||
**Tech Stack:** Markdown, Git, `rg`, repository documentation checks.
|
||||
|
||||
**Spec:** `docs/superpowers/specs/2026-08-20-psd-survey-remediation-checklist-design.md`
|
||||
|
||||
## Global Constraints
|
||||
|
||||
- Create only `docs/operations/psd-server-survey-remediation-checklist.md`.
|
||||
- Use only `PENDING`, `IN_DISCUSSION`, `BLOCKED`, and `PASS` as activity states.
|
||||
- Set Activity 1 to `IN_DISCUSSION`; set Activities 2–10 to `PENDING`.
|
||||
- Keep `SURVEY_NO_GO` and prohibit Project A/B until their documented gates pass.
|
||||
- Never include passwords, tokens, cookies, private keys, connection strings, raw claims, or realistic secret examples.
|
||||
- Keep the legacy stack running and unchanged; this plan performs documentation work only.
|
||||
|
||||
---
|
||||
|
||||
### Task 1: Create and verify the resumable operational checklist
|
||||
|
||||
**Files:**
|
||||
- Read: `docs/superpowers/specs/2026-08-20-psd-survey-remediation-checklist-design.md`
|
||||
- Read: `docs/operations/psd-server-sol-orchestration-prompt.md`
|
||||
- Create: `docs/operations/psd-server-survey-remediation-checklist.md`
|
||||
|
||||
**Interfaces:**
|
||||
- Consumes: the approved activity order, safety rules, status vocabulary, and resume contract from the design.
|
||||
- Produces: the single operational document used by later sessions to select and discuss exactly one activity.
|
||||
|
||||
- [ ] **Step 1: Confirm the documentation baseline**
|
||||
|
||||
Run:
|
||||
|
||||
```bash
|
||||
git status --short --branch
|
||||
test -f docs/superpowers/specs/2026-08-20-psd-survey-remediation-checklist-design.md
|
||||
test -f docs/operations/psd-server-sol-orchestration-prompt.md
|
||||
```
|
||||
|
||||
Expected: the two source documents exist and no unrelated uncommitted changes overlap the target.
|
||||
|
||||
- [ ] **Step 2: Create the checklist with the fixed initial state**
|
||||
|
||||
Create `docs/operations/psd-server-survey-remediation-checklist.md` with these top-level sections in order:
|
||||
|
||||
1. `Purpose and authority`
|
||||
2. `Program gate`
|
||||
3. `Current activity and resume point`
|
||||
4. `How to use this checklist`
|
||||
5. `Activity summary`
|
||||
6. `Activity 1` through `Activity 10`
|
||||
7. `Fresh survey and owner gate`
|
||||
8. `Change log`
|
||||
|
||||
Set the initial fields to:
|
||||
|
||||
```text
|
||||
Program result: SURVEY_NO_GO
|
||||
Current activity: 1 — Rotate or revoke the exposed DWH credential safely
|
||||
Resume from: Activity 1, identify the accountable credential owner and the credential type without revealing its value
|
||||
```
|
||||
|
||||
Each activity section must contain exactly these fields:
|
||||
|
||||
```text
|
||||
Status
|
||||
Accountable owner
|
||||
Objective
|
||||
Why this is required
|
||||
Ordered actions
|
||||
Required redacted evidence
|
||||
Discussion notes
|
||||
Decision
|
||||
Blockers
|
||||
Next step
|
||||
```
|
||||
|
||||
Use factual initial values such as `Unassigned`, `Not discussed`, and `No decision recorded`; do not use ambiguous filler markers.
|
||||
|
||||
- [ ] **Step 3: Verify structure, initial state, and safety gates**
|
||||
|
||||
Run:
|
||||
|
||||
```bash
|
||||
test "$(rg -c '^## Activity [0-9]+:' docs/operations/psd-server-survey-remediation-checklist.md)" -eq 10
|
||||
test "$(rg -c 'Status: `IN_DISCUSSION`' docs/operations/psd-server-survey-remediation-checklist.md)" -eq 1
|
||||
test "$(rg -c 'Status: `PENDING`' docs/operations/psd-server-survey-remediation-checklist.md)" -eq 9
|
||||
rg -n --fixed-strings 'Program result: `SURVEY_NO_GO`' docs/operations/psd-server-survey-remediation-checklist.md
|
||||
rg -n --fixed-strings 'Current activity: `1`' docs/operations/psd-server-survey-remediation-checklist.md
|
||||
rg -n --fixed-strings 'Project A remains forbidden' docs/operations/psd-server-survey-remediation-checklist.md
|
||||
rg -n --fixed-strings 'Project B remains forbidden' docs/operations/psd-server-survey-remediation-checklist.md
|
||||
if rg -n '\b(TB[D]|TO[D]O)\b|<[^>]+>' docs/operations/psd-server-survey-remediation-checklist.md; then exit 1; fi
|
||||
git diff --check
|
||||
```
|
||||
|
||||
Expected: ten activities, one current discussion, nine pending activities, all gates present, no filler markers, and a clean Markdown diff.
|
||||
|
||||
- [ ] **Step 4: Perform a count-only secret-pattern check**
|
||||
|
||||
Run a scan that treats ripgrep exit `0` as failure, exit `1` as no match, and any other exit as a scanner error. Check for private-key headers, bearer-shaped values, and credential assignments with non-whitespace values of eight or more characters. Do not print matching content.
|
||||
|
||||
Expected: `secret-pattern-scan=PASS`.
|
||||
|
||||
- [ ] **Step 5: Review and commit only the checklist**
|
||||
|
||||
Run:
|
||||
|
||||
```bash
|
||||
git diff -- docs/operations/psd-server-survey-remediation-checklist.md
|
||||
git add docs/operations/psd-server-survey-remediation-checklist.md
|
||||
git diff --cached --check
|
||||
git commit -m "docs: add PSD survey remediation checklist"
|
||||
```
|
||||
|
||||
Expected: one committed operational document; no server, configuration, evidence, or secret file changed.
|
||||
Reference in New Issue
Block a user