14 KiB
14 KiB
AI Automation Mainline Work Items
Updated: 2026-07-15 13:12 Asia/Taipei Governance:
global_product_governance_v2+ ADR-038 Current P0:GROWTH-P0-001 comparison coverage truth + autonomous refresh
Source Of Truth
- Production runtime receipt/post-verifier/durable DB receipt is authoritative.
- Gitea main, deploy marker, CD run and production readback are the only source/deploy truth; GitHub remains frozen.
- Source/test/UI/CD green does not mean runtime closure.
- Completion must report program, asset coverage and runtime closure separately.
- PixelRAG visual evidence cannot write formal prices or
ai_insightsbefore identity, PromotionGate and internal RAG canary proof.
Ordered P0
| Order | ID | Status | Work item | Exit evidence / next machine action |
|---|---|---|---|---|
| 1 | SEC-P0-001 |
Completed | Deny-by-default route access control | governance/evidence/SEC-P0-001-20260711T122758Z.json plus the current runtime receipt prove anonymous matrix 8/8 denied, public /metrics 404, exact internal target up, EwoooC product markers present, Prometheus identity preserved and momo-db unchanged. |
| 2 | GROWTH-P0-001 |
In progress (runtime_partial) |
Comparison coverage truth + autonomous refresh | V10.800 is live at Gitea object 4670f80f98f705050784f26adf7797b54e4c409f. Production run 70857a03b2ae49bbbd6683d3781441f8 scanned the first 8 unresolved items and closed no_write_verified; run a950e4b209234088b88bc35b70b3bbda scanned 20, found 3 exact + 1 unit-price independently verified candidates, but check-mode correctly blocked the mixed promotion batch with zero formal writes. Production truth therefore remains 21 ready + 1 candidate validation + 28 unmatched, 42% count, 51.0% revenue and 1/15 formal platforms. V10.801 source candidate routes source-disallowed unit-price matches to candidate-only receipts while exact matches continue to controlled apply; full regression is 2,106 passed / 9 skipped / 0 failed. Next: deploy V10.801 and rerun the same bounded limit-20 canary before updating any KPI. |
| 3 | SEC-P0-002 |
In progress (canary_ready) |
Database identity + least-privilege RBAC | V10.789 is live and governance/auth_identity_runtime_receipt.json verifies required tables, two active admins, durable lockout, session revocation, trusted proxy policy and no-secret mutation audit readiness. Runtime is intentionally hybrid because zero database-admin success receipts have been captured; auto retires shared authority after two durable successes without a manual review gate. Next: capture database-admin login receipts and verify automatic database-only cutover. |
| 4 | SEC-P0-003 |
In progress | Webhook trust and replay protection | Telegram secret-token verification code exists; production secret activation remains unproven. Exit: secret provisioned outside source, required mode enabled, invalid-secret 401 and authorized callback canary pass. |
| 5 | SUPPLY-P0-001 |
In progress | Gitea-only secure software supply chain | Gitea-native checkout, secret-safe .dockerignore, commit-bound source receipt and governance gate are active. Exit: exact dependency lock, internal SAST/SCA/secret scan, SBOM, image digest/provenance, vulnerability SLA and production digest readback. |
| 6 | GOV-P0-001 |
In progress | Canonical full asset graph + runtime reconciliation | governance/ewoooc_asset_inventory.json seeds hosts, services, data, AI, routes, supply chain, observability and recovery. Exit: same-run probe receipt for every asset; drift auto-creates work items. |
| 7 | GOV-P0-002 |
Not started | Unified controlled-apply envelope | Introduce one trace_id/run_id/work_item_id across sensor, identity, SOT diff, decision, risk, dry-run, execution, verifier, rollback/retry and learning acknowledgement. Start with EventRouter + AutoHeal. |
| 8 | RAG-P0-001 |
Not started | Internal RAG candidate canary | V10.770 stops at candidate preview. Exit: bounded pgvector candidate canary, signature/readback/feedback receipt, no price write and no premature ai_insights promotion. Next: run_internal_rag_candidate_canary. |
| 9 | MCP-P0-001 |
In progress (federation_source_ready) |
MCP/RAG production runtime closure | V10.796 source adds a strict public aggregate receipt for canonical ewoooc and momo-pro-system identities without opening authenticated internal APIs or exposing endpoint/tool payload data. Exit still requires V10.796 production /health, two fresh AWOOOI durable receipts with fingerprint recompute, live MCP servers/router/RAG, approved caller/tool boundary and production query canary. Current source readiness must not be reported as runtime closure. |
| 10 | SEC-P0-004 |
Not started | Security operations lifecycle and metrics | Add durable security incident state and publish MTTA, MTTR, recurrence, false positive, human intervention, verifier pass, rollback and freshness. Exit: detect-to-learn production receipt. |
| 11 | REL-P0-001 |
In progress | Formal deploy and visible proof discipline | Gitea main is 4670f80f98f705050784f26adf7797b54e4c409f; Action #1132 is waiting because no matching ewoooc-host runner is online and therefore provides no CD execution evidence. A bounded exact-Git-object fallback deployed V10.800 from archive SHA-256 d660339f30727f62bf2f39eae2665fe6b832f77e6743743bc8ea85b6206dbc05; check/apply/hash/preflight/canary receipts are under /home/ollama/momo-deploy-backups/ewoooc-20260715T045049Z-4670f80/. Production internal/external /health is healthy at V10.800, all 16 runtime hashes match the exact object, three application containers are healthy, and momo-db remained unchanged at cd092451cb5fd555d0ffff70642e109f3b742882c418beeab631793d1e9dc55d. Next: deploy the tested V10.801 promotion-policy fix through the same bounded path, then complete authenticated desktop/mobile visible smoke; runner recovery remains a release-governance gap. |
GROWTH-P0-001 Fixed Execution Lanes
These lanes are one ordered current P0, not optional side work. They must advance in this order and keep formal-price writes behind verified same-item evidence.
| Lane | Status | Production baseline | Next machine action |
|---|---|---|---|
| A. Sales freshness | In progress (sla_runtime_closed_source_redundancy_partial) |
Latest sales date 2026-07-13; before the 2026-07-15 20:00 cutoff, raw lag is 2 but SLA lag is 0, state is grace and decisions remain released. Scheduler receipt 0f24219e0bbb4740b7ad6645e7952296 and explicit canary receipt 6e2df008f65544fe8e557c11ff0dbb93 both persisted completed_no_write; durable decision is no_candidate_fresh_no_write. Live and persisted readiness now agree at Google Drive 1/4; HTTPS, IMAP and local remain disabled. |
Continue automatic report-arrival reconciliation. At/after 20:00 require 2026-07-14 or automatically block decision use, emit the bounded upstream action and verify the next arrival receipt; keep source redundancy partial until another approved source is live. |
| B. Verified same-item evidence | In progress | TOP50 fixed cohort: 21 verified, 1 candidate/source validation, 28 unmatched. Count coverage is 42%; revenue-weighted coverage is NT$180,667 / NT$354,062 = 51.0%. V10.797 outer-pack false exact candidates were quarantined without deletion; V10.798 normalizes nested quantity, and V10.799 prevents mapping status from changing cohort membership. Runs 58bb702057284cd382c82314b418d713 and cb40a5dcdaa045c69bf9611ebb13bba2 wrote/read back five verified offers; run 14d4aac64d434e34bfbd0f0edb7ef1eb closed no-write after zero safe candidates. |
Wait for fresh source evidence before retrying the same unresolved subset, broaden approved structured platform adapters, preserve deterministic identity/unit/variant gates, and publish both count and revenue coverage deltas with the same scope fingerprint per run. |
| C. Platform runtime coverage | In progress (runtime_canary_no_write) |
V10.800 is live, scheduler registration is verified and two production runs persisted durable receipts. Limit 8 closed no-write; limit 20 found 3 exact + 1 unit-price, and check-mode stopped the mixed batch before DB write. Formal runtime remains 1/15; PixelRAG remains evidence-only. |
Deploy V10.801 source-profile promotion partition, rerun limit 20, write/read back exact only, retain unit-price as candidate-only, then require at least two exact readbacks before atomically enabling active + enabled + write_enabled. |
P1
| Order | ID | Status | Work item | Exit evidence / next machine action |
|---|---|---|---|---|
| 12 | RES-P1-001 |
Not started | Backup/offsite/restore automation | Fresh checksum and offsite coverage plus isolated non-destructive restore drill with measured RPO/RTO. |
| 13 | PLAT-P1-001 |
Not started | Non-root container and capability hardening | Shadow non-root image, writable-path inventory, capability drop/read-only filesystem canary, three-app rollout. |
| 14 | APPSEC-P1-001 |
In progress | CSP and DOM/XSS hardening | Security headers are present and CSP is report-only. Collect violations, remove high-risk innerHTML/inline sinks, then enforce CSP by canary. |
| 15 | APPSEC-P1-002 |
Not started | Unsafe shared-cache serialization removal | Replace writable pickle caches in dashboard/daily-sales/EDM/sales with constrained JSON or signed schema. |
| 16 | ARCH-P1-001 |
In progress | Split oversized policy/executor/verifier modules | Current top debts include 44k-line PChome mapping and 14k-line smoke service. Split by bounded family and independent tests. |
| 17 | UX-P1-001 |
In progress | Professional full-site UI/UX | V10.800 production template leads with 業績比價覆蓋, backed by 51.0% revenue coverage and 21/50 product transparency instead of the old unqualified 10% card. External platform evidence now separates formal and candidate counts with compact chips and hidden detail text. Existing V10.795 desktop/mobile overflow smoke remains valid for layout; this release still needs a fresh authenticated production screenshot before visible closure is claimed. Continue the same first-viewport, progressive-disclosure, accessibility and state coverage across every remaining primary page. |
| 18 | PIXELRAG-P1-001 |
Not started | Ollama-first multimodal embedding benchmark | Verify approved visual embedding on GCP-A -> GCP-B -> 111 and design pgvector-compatible visual metadata; FAISS remains disallowed without ADR. |
| 19 | MARKET-P1-001 |
In progress | Marketplace source contracts | Yahoo Shopping V10.800 is live with public-boundary allowlists, bounded streaming/rate, provenance, current product-detail readback, stock/spec/variant guards and controlled canary. Production activation remains pending because mixed exact/unit promotion was safely blocked; V10.801 adds source-specific promotion partition. Shopee, Coupang, ETMall, Friday and Rakuten still require equivalent structured contracts, and blocked pages remain non-product data. |
| 20 | QA-P1-001 |
In progress | Deterministic test and CI governance | V10.801 workstation source baseline is 2,106 passed / 9 skipped / 0 failed; focused promotion-policy/Yahoo/source-readiness/same-item scope is 63 passed. V10.800 production exact-object hashes, health, scheduler registration, two no-write receipts and fixed cohort fingerprint are verified. Action #1132 remains waiting without runner execution, so CI parity is not claimed. Next: deploy V10.801 and require exact DB readback plus source activation receipt. |
P2
| Order | ID | Status | Work item | Exit evidence / next machine action |
|---|---|---|---|---|
| 21 | GOV-P2-001 |
Not started | Continuous NIST/ASVS control trend | Persist governance snapshots, compare control/asset/runtime drift and create ordered work items automatically. |
| 22 | DATA-P2-001 |
Not started | Data classification and retention enforcement | Classify business, personal, operational and model data; automate retention, deletion eligibility and audit evidence without destructive default actions. |
| 23 | CHAOS-P2-001 |
Not started | Controlled resilience exercises | Run non-destructive model-host, MCP, queue, Telegram and app-container failure drills with rollback and learning receipts. |
Completed Foundations
These are reusable foundations, not proof that the full program is complete.
| Status | Capability | Current boundary |
|---|---|---|
| Completed | Multi-commerce PixelRAG visual evidence for momo, pchome, shopee_tw, coupang_tw, yahoo_shopping_tw, etmall_tw, friday_tw, rakuten_tw | Evidence-only; blocked pages are not product data. |
| Completed | External MCP/RAG capability inventory | Registry/integration readback exists; runtime enablement remains P0. |
| Completed | PixelRAG receipt -> RAG candidate replay | Candidate-only; no formal knowledge or price write. |
| Completed | Source-contract replay worker | Public-boundary artifact receipts only. |
| Completed | Marketplace adapter preflight and dry-run | Deterministic no-write contracts. |
| Completed | Marketplace identity matcher replay | Candidate identity only. |
| Completed | PromotionGate replay | No production write. |
| Completed | Embedding-signature guard replay | Signature readiness only. |
| Completed | Candidate knowledge replay | Internal RAG preview only; canary remains P0. |
| Completed | PixelRAG application portfolio | Commerce/RAG/UX/ops/marketing/governance inventory. |
| Completed | Ollama-first VLM route readiness and replay worker | Evidence-bound artifact output; no direct price write. |
| Completed | Platform probe worker | Shopee/Coupang barriers become structured fallback/backoff receipts. |
Definition Of Done
A work item can be Completed only when the same production run contains:
- sensor/source receipt;
- normalized canonical asset identity;
- source-of-truth diff;
- AI decision and candidate action;
- risk/policy decision;
- check-mode/dry-run receipt;
- idempotent bounded execution receipt;
- independent post-verifier and rollback/no-write terminal;
- incident/Telegram/KM/RAG/MCP/PlayBook durable acknowledgement.
Missing any stage means partial, degraded or blocked_with_safe_next_action.