From afb0831e40cf67e916c43287c821a017502eda71 Mon Sep 17 00:00:00 2001 From: User Date: Thu, 20 Aug 2026 15:21:18 +0200 Subject: [PATCH] docs: plan PSD survey remediation checklist --- ...-08-20-psd-survey-remediation-checklist.md | 120 ++++++++++++++++++ 1 file changed, 120 insertions(+) create mode 100644 docs/superpowers/plans/2026-08-20-psd-survey-remediation-checklist.md diff --git a/docs/superpowers/plans/2026-08-20-psd-survey-remediation-checklist.md b/docs/superpowers/plans/2026-08-20-psd-survey-remediation-checklist.md new file mode 100644 index 00000000..770af130 --- /dev/null +++ b/docs/superpowers/plans/2026-08-20-psd-survey-remediation-checklist.md @@ -0,0 +1,120 @@ +# PSD Survey Remediation Checklist Implementation Plan + +> **For agentic workers:** REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (`- [ ]`) syntax for tracking. + +**Goal:** Create one versioned, secret-free operational checklist for discussing and closing the ten PSD survey blockers one at a time. + +**Architecture:** A single Markdown document under `docs/operations/` owns the current activity, resume marker, status summary, per-activity discussion record, and final re-survey gate. Protected evidence remains outside Git and is referenced only by path, digest, timestamp, or sanitized result. + +**Tech Stack:** Markdown, Git, `rg`, repository documentation checks. + +**Spec:** `docs/superpowers/specs/2026-08-20-psd-survey-remediation-checklist-design.md` + +## Global Constraints + +- Create only `docs/operations/psd-server-survey-remediation-checklist.md`. +- Use only `PENDING`, `IN_DISCUSSION`, `BLOCKED`, and `PASS` as activity states. +- Set Activity 1 to `IN_DISCUSSION`; set Activities 2–10 to `PENDING`. +- Keep `SURVEY_NO_GO` and prohibit Project A/B until their documented gates pass. +- Never include passwords, tokens, cookies, private keys, connection strings, raw claims, or realistic secret examples. +- Keep the legacy stack running and unchanged; this plan performs documentation work only. + +--- + +### Task 1: Create and verify the resumable operational checklist + +**Files:** +- Read: `docs/superpowers/specs/2026-08-20-psd-survey-remediation-checklist-design.md` +- Read: `docs/operations/psd-server-sol-orchestration-prompt.md` +- Create: `docs/operations/psd-server-survey-remediation-checklist.md` + +**Interfaces:** +- Consumes: the approved activity order, safety rules, status vocabulary, and resume contract from the design. +- Produces: the single operational document used by later sessions to select and discuss exactly one activity. + +- [ ] **Step 1: Confirm the documentation baseline** + +Run: + +```bash +git status --short --branch +test -f docs/superpowers/specs/2026-08-20-psd-survey-remediation-checklist-design.md +test -f docs/operations/psd-server-sol-orchestration-prompt.md +``` + +Expected: the two source documents exist and no unrelated uncommitted changes overlap the target. + +- [ ] **Step 2: Create the checklist with the fixed initial state** + +Create `docs/operations/psd-server-survey-remediation-checklist.md` with these top-level sections in order: + +1. `Purpose and authority` +2. `Program gate` +3. `Current activity and resume point` +4. `How to use this checklist` +5. `Activity summary` +6. `Activity 1` through `Activity 10` +7. `Fresh survey and owner gate` +8. `Change log` + +Set the initial fields to: + +```text +Program result: SURVEY_NO_GO +Current activity: 1 — Rotate or revoke the exposed DWH credential safely +Resume from: Activity 1, identify the accountable credential owner and the credential type without revealing its value +``` + +Each activity section must contain exactly these fields: + +```text +Status +Accountable owner +Objective +Why this is required +Ordered actions +Required redacted evidence +Discussion notes +Decision +Blockers +Next step +``` + +Use factual initial values such as `Unassigned`, `Not discussed`, and `No decision recorded`; do not use ambiguous filler markers. + +- [ ] **Step 3: Verify structure, initial state, and safety gates** + +Run: + +```bash +test "$(rg -c '^## Activity [0-9]+:' docs/operations/psd-server-survey-remediation-checklist.md)" -eq 10 +test "$(rg -c 'Status: `IN_DISCUSSION`' docs/operations/psd-server-survey-remediation-checklist.md)" -eq 1 +test "$(rg -c 'Status: `PENDING`' docs/operations/psd-server-survey-remediation-checklist.md)" -eq 9 +rg -n --fixed-strings 'Program result: `SURVEY_NO_GO`' docs/operations/psd-server-survey-remediation-checklist.md +rg -n --fixed-strings 'Current activity: `1`' docs/operations/psd-server-survey-remediation-checklist.md +rg -n --fixed-strings 'Project A remains forbidden' docs/operations/psd-server-survey-remediation-checklist.md +rg -n --fixed-strings 'Project B remains forbidden' docs/operations/psd-server-survey-remediation-checklist.md +if rg -n '\b(TB[D]|TO[D]O)\b|<[^>]+>' docs/operations/psd-server-survey-remediation-checklist.md; then exit 1; fi +git diff --check +``` + +Expected: ten activities, one current discussion, nine pending activities, all gates present, no filler markers, and a clean Markdown diff. + +- [ ] **Step 4: Perform a count-only secret-pattern check** + +Run a scan that treats ripgrep exit `0` as failure, exit `1` as no match, and any other exit as a scanner error. Check for private-key headers, bearer-shaped values, and credential assignments with non-whitespace values of eight or more characters. Do not print matching content. + +Expected: `secret-pattern-scan=PASS`. + +- [ ] **Step 5: Review and commit only the checklist** + +Run: + +```bash +git diff -- docs/operations/psd-server-survey-remediation-checklist.md +git add docs/operations/psd-server-survey-remediation-checklist.md +git diff --cached --check +git commit -m "docs: add PSD survey remediation checklist" +``` + +Expected: one committed operational document; no server, configuration, evidence, or secret file changed.