Files
ewoooc/docs/guides/ai_automation_mainline_work_items.md
ogt c091c466c2
Some checks failed
CD Pipeline / deploy (push) Has been cancelled
fix(growth): partition Yahoo promotion candidates
2026-07-15 13:15:33 +08:00

14 KiB

AI Automation Mainline Work Items

Updated: 2026-07-15 13:12 Asia/Taipei Governance: global_product_governance_v2 + ADR-038 Current P0: GROWTH-P0-001 comparison coverage truth + autonomous refresh

Source Of Truth

  • Production runtime receipt/post-verifier/durable DB receipt is authoritative.
  • Gitea main, deploy marker, CD run and production readback are the only source/deploy truth; GitHub remains frozen.
  • Source/test/UI/CD green does not mean runtime closure.
  • Completion must report program, asset coverage and runtime closure separately.
  • PixelRAG visual evidence cannot write formal prices or ai_insights before identity, PromotionGate and internal RAG canary proof.

Ordered P0

Order ID Status Work item Exit evidence / next machine action
1 SEC-P0-001 Completed Deny-by-default route access control governance/evidence/SEC-P0-001-20260711T122758Z.json plus the current runtime receipt prove anonymous matrix 8/8 denied, public /metrics 404, exact internal target up, EwoooC product markers present, Prometheus identity preserved and momo-db unchanged.
2 GROWTH-P0-001 In progress (runtime_partial) Comparison coverage truth + autonomous refresh V10.800 is live at Gitea object 4670f80f98f705050784f26adf7797b54e4c409f. Production run 70857a03b2ae49bbbd6683d3781441f8 scanned the first 8 unresolved items and closed no_write_verified; run a950e4b209234088b88bc35b70b3bbda scanned 20, found 3 exact + 1 unit-price independently verified candidates, but check-mode correctly blocked the mixed promotion batch with zero formal writes. Production truth therefore remains 21 ready + 1 candidate validation + 28 unmatched, 42% count, 51.0% revenue and 1/15 formal platforms. V10.801 source candidate routes source-disallowed unit-price matches to candidate-only receipts while exact matches continue to controlled apply; full regression is 2,106 passed / 9 skipped / 0 failed. Next: deploy V10.801 and rerun the same bounded limit-20 canary before updating any KPI.
3 SEC-P0-002 In progress (canary_ready) Database identity + least-privilege RBAC V10.789 is live and governance/auth_identity_runtime_receipt.json verifies required tables, two active admins, durable lockout, session revocation, trusted proxy policy and no-secret mutation audit readiness. Runtime is intentionally hybrid because zero database-admin success receipts have been captured; auto retires shared authority after two durable successes without a manual review gate. Next: capture database-admin login receipts and verify automatic database-only cutover.
4 SEC-P0-003 In progress Webhook trust and replay protection Telegram secret-token verification code exists; production secret activation remains unproven. Exit: secret provisioned outside source, required mode enabled, invalid-secret 401 and authorized callback canary pass.
5 SUPPLY-P0-001 In progress Gitea-only secure software supply chain Gitea-native checkout, secret-safe .dockerignore, commit-bound source receipt and governance gate are active. Exit: exact dependency lock, internal SAST/SCA/secret scan, SBOM, image digest/provenance, vulnerability SLA and production digest readback.
6 GOV-P0-001 In progress Canonical full asset graph + runtime reconciliation governance/ewoooc_asset_inventory.json seeds hosts, services, data, AI, routes, supply chain, observability and recovery. Exit: same-run probe receipt for every asset; drift auto-creates work items.
7 GOV-P0-002 Not started Unified controlled-apply envelope Introduce one trace_id/run_id/work_item_id across sensor, identity, SOT diff, decision, risk, dry-run, execution, verifier, rollback/retry and learning acknowledgement. Start with EventRouter + AutoHeal.
8 RAG-P0-001 Not started Internal RAG candidate canary V10.770 stops at candidate preview. Exit: bounded pgvector candidate canary, signature/readback/feedback receipt, no price write and no premature ai_insights promotion. Next: run_internal_rag_candidate_canary.
9 MCP-P0-001 In progress (federation_source_ready) MCP/RAG production runtime closure V10.796 source adds a strict public aggregate receipt for canonical ewoooc and momo-pro-system identities without opening authenticated internal APIs or exposing endpoint/tool payload data. Exit still requires V10.796 production /health, two fresh AWOOOI durable receipts with fingerprint recompute, live MCP servers/router/RAG, approved caller/tool boundary and production query canary. Current source readiness must not be reported as runtime closure.
10 SEC-P0-004 Not started Security operations lifecycle and metrics Add durable security incident state and publish MTTA, MTTR, recurrence, false positive, human intervention, verifier pass, rollback and freshness. Exit: detect-to-learn production receipt.
11 REL-P0-001 In progress Formal deploy and visible proof discipline Gitea main is 4670f80f98f705050784f26adf7797b54e4c409f; Action #1132 is waiting because no matching ewoooc-host runner is online and therefore provides no CD execution evidence. A bounded exact-Git-object fallback deployed V10.800 from archive SHA-256 d660339f30727f62bf2f39eae2665fe6b832f77e6743743bc8ea85b6206dbc05; check/apply/hash/preflight/canary receipts are under /home/ollama/momo-deploy-backups/ewoooc-20260715T045049Z-4670f80/. Production internal/external /health is healthy at V10.800, all 16 runtime hashes match the exact object, three application containers are healthy, and momo-db remained unchanged at cd092451cb5fd555d0ffff70642e109f3b742882c418beeab631793d1e9dc55d. Next: deploy the tested V10.801 promotion-policy fix through the same bounded path, then complete authenticated desktop/mobile visible smoke; runner recovery remains a release-governance gap.

GROWTH-P0-001 Fixed Execution Lanes

These lanes are one ordered current P0, not optional side work. They must advance in this order and keep formal-price writes behind verified same-item evidence.

Lane Status Production baseline Next machine action
A. Sales freshness In progress (sla_runtime_closed_source_redundancy_partial) Latest sales date 2026-07-13; before the 2026-07-15 20:00 cutoff, raw lag is 2 but SLA lag is 0, state is grace and decisions remain released. Scheduler receipt 0f24219e0bbb4740b7ad6645e7952296 and explicit canary receipt 6e2df008f65544fe8e557c11ff0dbb93 both persisted completed_no_write; durable decision is no_candidate_fresh_no_write. Live and persisted readiness now agree at Google Drive 1/4; HTTPS, IMAP and local remain disabled. Continue automatic report-arrival reconciliation. At/after 20:00 require 2026-07-14 or automatically block decision use, emit the bounded upstream action and verify the next arrival receipt; keep source redundancy partial until another approved source is live.
B. Verified same-item evidence In progress TOP50 fixed cohort: 21 verified, 1 candidate/source validation, 28 unmatched. Count coverage is 42%; revenue-weighted coverage is NT$180,667 / NT$354,062 = 51.0%. V10.797 outer-pack false exact candidates were quarantined without deletion; V10.798 normalizes nested quantity, and V10.799 prevents mapping status from changing cohort membership. Runs 58bb702057284cd382c82314b418d713 and cb40a5dcdaa045c69bf9611ebb13bba2 wrote/read back five verified offers; run 14d4aac64d434e34bfbd0f0edb7ef1eb closed no-write after zero safe candidates. Wait for fresh source evidence before retrying the same unresolved subset, broaden approved structured platform adapters, preserve deterministic identity/unit/variant gates, and publish both count and revenue coverage deltas with the same scope fingerprint per run.
C. Platform runtime coverage In progress (runtime_canary_no_write) V10.800 is live, scheduler registration is verified and two production runs persisted durable receipts. Limit 8 closed no-write; limit 20 found 3 exact + 1 unit-price, and check-mode stopped the mixed batch before DB write. Formal runtime remains 1/15; PixelRAG remains evidence-only. Deploy V10.801 source-profile promotion partition, rerun limit 20, write/read back exact only, retain unit-price as candidate-only, then require at least two exact readbacks before atomically enabling active + enabled + write_enabled.

P1

Order ID Status Work item Exit evidence / next machine action
12 RES-P1-001 Not started Backup/offsite/restore automation Fresh checksum and offsite coverage plus isolated non-destructive restore drill with measured RPO/RTO.
13 PLAT-P1-001 Not started Non-root container and capability hardening Shadow non-root image, writable-path inventory, capability drop/read-only filesystem canary, three-app rollout.
14 APPSEC-P1-001 In progress CSP and DOM/XSS hardening Security headers are present and CSP is report-only. Collect violations, remove high-risk innerHTML/inline sinks, then enforce CSP by canary.
15 APPSEC-P1-002 Not started Unsafe shared-cache serialization removal Replace writable pickle caches in dashboard/daily-sales/EDM/sales with constrained JSON or signed schema.
16 ARCH-P1-001 In progress Split oversized policy/executor/verifier modules Current top debts include 44k-line PChome mapping and 14k-line smoke service. Split by bounded family and independent tests.
17 UX-P1-001 In progress Professional full-site UI/UX V10.800 production template leads with 業績比價覆蓋, backed by 51.0% revenue coverage and 21/50 product transparency instead of the old unqualified 10% card. External platform evidence now separates formal and candidate counts with compact chips and hidden detail text. Existing V10.795 desktop/mobile overflow smoke remains valid for layout; this release still needs a fresh authenticated production screenshot before visible closure is claimed. Continue the same first-viewport, progressive-disclosure, accessibility and state coverage across every remaining primary page.
18 PIXELRAG-P1-001 Not started Ollama-first multimodal embedding benchmark Verify approved visual embedding on GCP-A -> GCP-B -> 111 and design pgvector-compatible visual metadata; FAISS remains disallowed without ADR.
19 MARKET-P1-001 In progress Marketplace source contracts Yahoo Shopping V10.800 is live with public-boundary allowlists, bounded streaming/rate, provenance, current product-detail readback, stock/spec/variant guards and controlled canary. Production activation remains pending because mixed exact/unit promotion was safely blocked; V10.801 adds source-specific promotion partition. Shopee, Coupang, ETMall, Friday and Rakuten still require equivalent structured contracts, and blocked pages remain non-product data.
20 QA-P1-001 In progress Deterministic test and CI governance V10.801 workstation source baseline is 2,106 passed / 9 skipped / 0 failed; focused promotion-policy/Yahoo/source-readiness/same-item scope is 63 passed. V10.800 production exact-object hashes, health, scheduler registration, two no-write receipts and fixed cohort fingerprint are verified. Action #1132 remains waiting without runner execution, so CI parity is not claimed. Next: deploy V10.801 and require exact DB readback plus source activation receipt.

P2

Order ID Status Work item Exit evidence / next machine action
21 GOV-P2-001 Not started Continuous NIST/ASVS control trend Persist governance snapshots, compare control/asset/runtime drift and create ordered work items automatically.
22 DATA-P2-001 Not started Data classification and retention enforcement Classify business, personal, operational and model data; automate retention, deletion eligibility and audit evidence without destructive default actions.
23 CHAOS-P2-001 Not started Controlled resilience exercises Run non-destructive model-host, MCP, queue, Telegram and app-container failure drills with rollback and learning receipts.

Completed Foundations

These are reusable foundations, not proof that the full program is complete.

Status Capability Current boundary
Completed Multi-commerce PixelRAG visual evidence for momo, pchome, shopee_tw, coupang_tw, yahoo_shopping_tw, etmall_tw, friday_tw, rakuten_tw Evidence-only; blocked pages are not product data.
Completed External MCP/RAG capability inventory Registry/integration readback exists; runtime enablement remains P0.
Completed PixelRAG receipt -> RAG candidate replay Candidate-only; no formal knowledge or price write.
Completed Source-contract replay worker Public-boundary artifact receipts only.
Completed Marketplace adapter preflight and dry-run Deterministic no-write contracts.
Completed Marketplace identity matcher replay Candidate identity only.
Completed PromotionGate replay No production write.
Completed Embedding-signature guard replay Signature readiness only.
Completed Candidate knowledge replay Internal RAG preview only; canary remains P0.
Completed PixelRAG application portfolio Commerce/RAG/UX/ops/marketing/governance inventory.
Completed Ollama-first VLM route readiness and replay worker Evidence-bound artifact output; no direct price write.
Completed Platform probe worker Shopee/Coupang barriers become structured fallback/backoff receipts.

Definition Of Done

A work item can be Completed only when the same production run contains:

  1. sensor/source receipt;
  2. normalized canonical asset identity;
  3. source-of-truth diff;
  4. AI decision and candidate action;
  5. risk/policy decision;
  6. check-mode/dry-run receipt;
  7. idempotent bounded execution receipt;
  8. independent post-verifier and rollback/no-write terminal;
  9. incident/Telegram/KM/RAG/MCP/PlayBook durable acknowledgement.

Missing any stage means partial, degraded or blocked_with_safe_next_action.