docs: plan PSD survey remediation checklist

This commit is contained in:
User
2026-08-20 15:21:18 +02:00
parent 4ebd2b77a3
commit afb0831e40
@@ -0,0 +1,120 @@
# PSD Survey Remediation Checklist Implementation Plan
> **For agentic workers:** REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (`- [ ]`) syntax for tracking.
**Goal:** Create one versioned, secret-free operational checklist for discussing and closing the ten PSD survey blockers one at a time.
**Architecture:** A single Markdown document under `docs/operations/` owns the current activity, resume marker, status summary, per-activity discussion record, and final re-survey gate. Protected evidence remains outside Git and is referenced only by path, digest, timestamp, or sanitized result.
**Tech Stack:** Markdown, Git, `rg`, repository documentation checks.
**Spec:** `docs/superpowers/specs/2026-08-20-psd-survey-remediation-checklist-design.md`
## Global Constraints
- Create only `docs/operations/psd-server-survey-remediation-checklist.md`.
- Use only `PENDING`, `IN_DISCUSSION`, `BLOCKED`, and `PASS` as activity states.
- Set Activity 1 to `IN_DISCUSSION`; set Activities 2–10 to `PENDING`.
- Keep `SURVEY_NO_GO` and prohibit Project A/B until their documented gates pass.
- Never include passwords, tokens, cookies, private keys, connection strings, raw claims, or realistic secret examples.
- Keep the legacy stack running and unchanged; this plan performs documentation work only.
---
### Task 1: Create and verify the resumable operational checklist
**Files:**
- Read: `docs/superpowers/specs/2026-08-20-psd-survey-remediation-checklist-design.md`
- Read: `docs/operations/psd-server-sol-orchestration-prompt.md`
- Create: `docs/operations/psd-server-survey-remediation-checklist.md`
**Interfaces:**
- Consumes: the approved activity order, safety rules, status vocabulary, and resume contract from the design.
- Produces: the single operational document used by later sessions to select and discuss exactly one activity.
- [ ] **Step 1: Confirm the documentation baseline**
Run:
```bash
git status --short --branch
test -f docs/superpowers/specs/2026-08-20-psd-survey-remediation-checklist-design.md
test -f docs/operations/psd-server-sol-orchestration-prompt.md
```
Expected: the two source documents exist and no unrelated uncommitted changes overlap the target.
- [ ] **Step 2: Create the checklist with the fixed initial state**
Create `docs/operations/psd-server-survey-remediation-checklist.md` with these top-level sections in order:
1. `Purpose and authority`
2. `Program gate`
3. `Current activity and resume point`
4. `How to use this checklist`
5. `Activity summary`
6. `Activity 1` through `Activity 10`
7. `Fresh survey and owner gate`
8. `Change log`
Set the initial fields to:
```text
Program result: SURVEY_NO_GO
Current activity: 1 — Rotate or revoke the exposed DWH credential safely
Resume from: Activity 1, identify the accountable credential owner and the credential type without revealing its value
```
Each activity section must contain exactly these fields:
```text
Status
Accountable owner
Objective
Why this is required
Ordered actions
Required redacted evidence
Discussion notes
Decision
Blockers
Next step
```
Use factual initial values such as `Unassigned`, `Not discussed`, and `No decision recorded`; do not use ambiguous filler markers.
- [ ] **Step 3: Verify structure, initial state, and safety gates**
Run:
```bash
test "$(rg -c '^## Activity [0-9]+:' docs/operations/psd-server-survey-remediation-checklist.md)" -eq 10
test "$(rg -c 'Status: `IN_DISCUSSION`' docs/operations/psd-server-survey-remediation-checklist.md)" -eq 1
test "$(rg -c 'Status: `PENDING`' docs/operations/psd-server-survey-remediation-checklist.md)" -eq 9
rg -n --fixed-strings 'Program result: `SURVEY_NO_GO`' docs/operations/psd-server-survey-remediation-checklist.md
rg -n --fixed-strings 'Current activity: `1`' docs/operations/psd-server-survey-remediation-checklist.md
rg -n --fixed-strings 'Project A remains forbidden' docs/operations/psd-server-survey-remediation-checklist.md
rg -n --fixed-strings 'Project B remains forbidden' docs/operations/psd-server-survey-remediation-checklist.md
if rg -n '\b(TB[D]|TO[D]O)\b|<[^>]+>' docs/operations/psd-server-survey-remediation-checklist.md; then exit 1; fi
git diff --check
```
Expected: ten activities, one current discussion, nine pending activities, all gates present, no filler markers, and a clean Markdown diff.
- [ ] **Step 4: Perform a count-only secret-pattern check**
Run a scan that treats ripgrep exit `0` as failure, exit `1` as no match, and any other exit as a scanner error. Check for private-key headers, bearer-shaped values, and credential assignments with non-whitespace values of eight or more characters. Do not print matching content.
Expected: `secret-pattern-scan=PASS`.
- [ ] **Step 5: Review and commit only the checklist**
Run:
```bash
git diff -- docs/operations/psd-server-survey-remediation-checklist.md
git add docs/operations/psd-server-survey-remediation-checklist.md
git diff --cached --check
git commit -m "docs: add PSD survey remediation checklist"
```
Expected: one committed operational document; no server, configuration, evidence, or secret file changed.