Files
ewoooc/docs/guides/ai_automation_mainline_work_items.md
2026-07-23 09:22:46 +08:00

19 KiB

AI Automation Mainline Work Items

Updated: 2026-07-23 Asia/Taipei Governance: global_product_governance_v2 + ADR-038 Current P0: GROWTH-P0-001 comparison coverage truth + autonomous refresh

Source Of Truth

  • Production runtime receipt/post-verifier/durable DB receipt is authoritative.
  • Gitea main, deploy marker, CD run and production readback are the only source/deploy truth; GitHub remains frozen.
  • Source/test/UI/CD green does not mean runtime closure.
  • Completion must report program, asset coverage and runtime closure separately.
  • PixelRAG visual evidence cannot write formal prices or ai_insights before identity, PromotionGate and internal RAG canary proof.

Ordered P0

Order ID Status Work item Exit evidence / next machine action
1 SEC-P0-001 Completed Deny-by-default route access control governance/evidence/SEC-P0-001-20260711T122758Z.json plus the current runtime receipt prove anonymous matrix 8/8 denied, public /metrics 404, exact internal target up, EwoooC product markers present, Prometheus identity preserved and momo-db unchanged.
2 GROWTH-P0-001 In progress (runtime_partial) Comparison coverage truth + autonomous refresh V10.815 is live and retains the growth runtime introduced at exact Gitea object 2647632660673e9f1533e61922c96e4fb4adcb40. Controlled run 34999f5314054f09909663b46fc42ee2 scanned 20, verified/wrote/read back one exact offer and raised the fixed cohort to 25 ready + 1 candidate validation + 24 unmatched, 50% count and NT$211,667 / NT$354,062 = 59.782% revenue. Follow-up run e1508ec3a49241d1965bc99d428b0325 found 19 candidates but safely wrote zero because none passed strict identity/variant/unit verification; its independent terminal is degraded_no_safe_candidate. Yahoo remains durably active + enabled + write_enabled, and the durable readback proves formal_source_activated=true even when the latest run is verified no-write. Formal runtime remains 2/15. Next: retry the unresolved revenue-weighted batch only with fresh source evidence, then add the next approved structured marketplace adapter without relaxing promotion gates.
3 SEC-P0-002 In progress (canary_ready) Database identity + least-privilege RBAC V10.789 is live and governance/auth_identity_runtime_receipt.json verifies required tables, two active admins, durable lockout, session revocation, trusted proxy policy and no-secret mutation audit readiness. Runtime is intentionally hybrid because zero database-admin success receipts have been captured; auto retires shared authority after two durable successes without a manual review gate. Next: capture database-admin login receipts and verify automatic database-only cutover.
4 SEC-P0-003 In progress Webhook trust and replay protection Telegram secret-token verification code exists; production secret activation remains unproven. Exit: secret provisioned outside source, required mode enabled, invalid-secret 401 and authorized callback canary pass.
5 SUPPLY-P0-001 In progress Gitea-only secure software supply chain Gitea-native checkout, secret-safe .dockerignore, commit-bound source receipt and governance gate are active. Exit: exact dependency lock, internal SAST/SCA/secret scan, SBOM, image digest/provenance, vulnerability SLA and production digest readback.
6 GOV-P0-001 In progress Canonical full asset graph + runtime reconciliation governance/ewoooc_asset_inventory.json seeds hosts, services, data, AI, routes, supply chain, observability and recovery. Exit: same-run probe receipt for every asset; drift auto-creates work items.
7 GOV-P0-002 Not started Unified controlled-apply envelope Introduce one trace_id/run_id/work_item_id across sensor, identity, SOT diff, decision, risk, dry-run, execution, verifier, rollback/retry and learning acknowledgement. Start with EventRouter + AutoHeal.
8 RAG-P0-001 In progress (runtime_verified_degraded_fallback_activation_blocked) Internal RAG candidate canary + NemoTron decision-only proof V10.816 is live at exact runtime marker 2757585e5e3455e96c743ddfd82d59304f32c3f0. Windows 99 run 1b335e97-fa31-418b-b925-759bc1036267 verified PixelRAG receipt -> exact-digest BGE-M3 -> read-only pgvector with ready_count=1, canary_passed_activation_blocked and zero business writes. The same run exercised all three bounded NemoTron candidates and returned canary_passed_degraded_fallback from 111 exact-digest qwen3:8b; model identity, deterministic one-call-per-SKU envelope and zero tool/DB/price/insight/Telegram execution passed. App and scheduler independently passed the shared reservation canary, cross-container visibility passed, and the four-hour side_effect_started quarantine is active. Final terminal: v10816_source_runtime_rag_nemotron_verified_no_db_mutation. Next: restore GCP-A reachability and GCP-B bounded inference capacity, then run controlled RAG_ENABLED shadow activation with query/hit/feedback telemetry before any formal product write.
9 MCP-P0-001 In progress (federation_source_ready) MCP/RAG production runtime closure V10.796 source adds a strict public aggregate receipt for canonical ewoooc and momo-pro-system identities without opening authenticated internal APIs or exposing endpoint/tool payload data. Exit still requires V10.796 production /health, two fresh AWOOOI durable receipts with fingerprint recompute, live MCP servers/router/RAG, approved caller/tool boundary and production query canary. Current source readiness must not be reported as runtime closure.
10 SEC-P0-004 Not started Security operations lifecycle and metrics Add durable security incident state and publish MTTA, MTTR, recurrence, false positive, human intervention, verifier pass, rollback and freshness. Exit: detect-to-learn production receipt.
11 REL-P0-001 In progress (v10816_runtime_verified_cd_runner_gap) Formal deploy and visible proof discipline Production V10.816 runs exact Gitea runtime marker 2757585e5e3455e96c743ddfd82d59304f32c3f0; its runtime tree was integrated to main, feature branch and dev before controlled deployment. Windows 99 run 1b335e97-fa31-418b-b925-759bc1036267 verified 20/20 changed source hashes and 30/30 runtime env contracts, recreated only app/scheduler/bot, preserved momo-db, passed independent runtime/public readback and finalized the RAG/NemoTron canaries. Rollback is retained at /home/ollama/momo-deploy-backups/ewoooc-20260723T011250Z-2757585-v10816-1b335e97; public /health reports V10.816 and the exact sales-analysis URL reaches the normal /login boundary. Host 110 still lacks a matching EwoooC runner, so formal Gitea CD remains an explicit gap rather than being conflated with the verified Windows 99 release.

GROWTH-P0-001 Fixed Execution Lanes

These lanes are one ordered current P0, not optional side work. They must advance in this order and keep formal-price writes behind verified same-item evidence.

Lane Status Production baseline Next machine action
A. Sales freshness In progress (sla_runtime_closed_source_redundancy_partial) Latest sales date 2026-07-13; before the 2026-07-15 20:00 cutoff, raw lag is 2 but SLA lag is 0, state is grace and decisions remain released. Scheduler receipt 0f24219e0bbb4740b7ad6645e7952296 and explicit canary receipt 6e2df008f65544fe8e557c11ff0dbb93 both persisted completed_no_write; durable decision is no_candidate_fresh_no_write. Live and persisted readiness now agree at Google Drive 1/4; HTTPS, IMAP and local remain disabled. Continue automatic report-arrival reconciliation. At/after 20:00 require 2026-07-14 or automatically block decision use, emit the bounded upstream action and verify the next arrival receipt; keep source redundancy partial until another approved source is live.
B. Verified same-item evidence In progress TOP50 fixed cohort: 25 verified, 1 candidate/source validation, 24 unmatched. Count coverage is 50%; revenue-weighted coverage is NT$211,667 / NT$354,062 = 59.782%. V10.810 preserves fingerprint 7b74504fcc1e1801c2ca2b42; run 34999f5314054f09909663b46fc42ee2 added one independently verified offer (+2.0pp count, +1.89pp revenue), while run e1508ec3a49241d1965bc99d428b0325 correctly ended no-write. Their durable artifact SHA-256 values are 994beba6dfa70ef8c50031f130916ee155657dd77ac8a2f59b6530b491d45d1e and e58be7bb07599871a8f318ad63885bd868c786b0144b81ba0980ae80cf556541. Retry unresolved candidates only after fresh evidence arrives, preserve deterministic identity/unit/variant gates, and publish count/revenue deltas against the same fingerprint per run.
C. Platform runtime coverage In progress (runtime_canary_activated) V10.815 is live. Yahoo is durably active and exact-offer canary readback remains valid; an already-active canary returns already_active_verified, state_changed=false and writes_database_count=0, while latest no-write receipts do not erase durable activation truth. Formal runtime is 2/15; PixelRAG remains evidence-only. Continue bounded refresh on schedule, monitor expiry/recurrence/rollback signals, then implement the next approved structured source contract for Shopee, Coupang, ETMall, Friday or Rakuten without treating blocked pages as product data.

AI Agent Product Integration Acceptance

This is an acceptance surface inside the current growth P0; it does not reorder the P0 queue. V10.811 source replaces class/method-presence optimism with a seven-day production telemetry readback.

Layer Current status Exit evidence
Source and scheduler wiring Source ready (4/4) Hermes, NemoTron, OpenClaw and ElephantAlpha source markers plus scheduler ownership are machine-read and reported separately from runtime.
Agent runtime activity Production partial; bounded fallback runtime verified V10.816 production exercised the actual model-aware dispatcher: GCP-A -> GCP-B -> 111, with 111 exact-digest qwen3:8b returning a valid decision envelope after three attempts. This proves decision-only fallback execution and shared dedupe boundaries, not a formal business action or four-Agent closure. Exit requires all four Agents role-active and healthy in the bounded window with linked product outcomes.
MCP/RAG dependency RAG canary verified; activation and MCP runtime still blocked Production RAG executed one read-only candidate canary successfully, but RAG_ENABLED=false continues to block activation; MCP router remains disabled and non-zero product telemetry is still absent. Exit requires approved routes enabled, live MCP health, non-zero agent/product telemetry, rollback coverage and a fresh internal RAG shadow receipt.
Controlled automation closure Runtime partial /api/ai-automation/agent-product-integration, CLI and smoke must report Detect -> Normalize -> Correlate -> Decide -> Check -> Controlled Apply -> Verify -> Retry/Rollback -> Learn/Writeback. Completion requires bounded execution, linked outcome/incident verification and durable learning evidence; aggregate source presence is insufficient.

Analytics Period-Linkage Closure

This bounded interruption is closed and control returns to GROWTH-P0-001 without changing its lane order.

Completion layer Status Production evidence
Program Completed for the four primary analysis tabs Daily sales, sales analysis, growth analysis and monthly summary now share one canonical day/month/range contract; cross-tab links preserve the selected period.
Asset coverage 4/4 pages and 2/2 sales async APIs verified Daily KPI/calendar/charts/Top 10, growth KPI/series, monthly KPI/tables/charts and sales KPI/charts/YoY/detail table all use the active period. Historical current-snapshot mixing and blank monthly charts are replaced by explicit honest states.
Runtime closure Completed in V10.815 at 283c8c80c631f5d97315708885413b62ee5a34ea The exact /sales_analysis URL with blank date fields now resolves one canonical period and applies the same metric/range/filter contract to KPI, charts, YoY and detail rows. Query, chart and export logic are split into dedicated services; repeated SKU rows are aggregated before ranking, date/range links preserve state, and invalid filters fail safely. Windows 99 independent readback verified all 36 target files, runtime env, public /health and exact JS/CSS hashes.
Verification Passed; authenticated visual proof remains pending V10.815 broad regression: 2,174 passed / 9 skipped / 0 failed; focused analytics batches: 173 passed and 70 passed, plus Python compile, Node syntax, Jinja render and diff checks. Public target route returns the expected login redirect and public assets match SHA-256 6bb4a985744917ef2243d6d055c85b6803b2baf5c571580f49ef69c536ccdf04 / d98654ddaac10a49af2351750f350bbbcfc3491d62b14c8a25d02eb4d7803186. The current browser session cannot provide authenticated chart screenshots, so that evidence is not claimed.

P1

Order ID Status Work item Exit evidence / next machine action
12 RES-P1-001 Not started Backup/offsite/restore automation Fresh checksum and offsite coverage plus isolated non-destructive restore drill with measured RPO/RTO.
13 PLAT-P1-001 Not started Non-root container and capability hardening Shadow non-root image, writable-path inventory, capability drop/read-only filesystem canary, three-app rollout.
14 APPSEC-P1-001 In progress CSP and DOM/XSS hardening Security headers are present and CSP is report-only. Collect violations, remove high-risk innerHTML/inline sinks, then enforce CSP by canary.
15 APPSEC-P1-002 Not started Unsafe shared-cache serialization removal Replace writable pickle caches in dashboard/daily-sales/EDM/sales with constrained JSON or signed schema.
16 ARCH-P1-001 In progress Split oversized policy/executor/verifier modules Current top debts include 44k-line PChome mapping and 14k-line smoke service. Split by bounded family and independent tests.
17 UX-P1-001 In progress Professional full-site UI/UX V10.815 closes the exact sales-analysis period/filter linkage and keeps the prior four-tab rendering guards: real payload values, visible single points, bounded extreme percentages, date-label auto-skip, zoom bounds and explicit loading/error/empty states. Public assets are hash-verified; authenticated V10.815 visual proof and the broader site-wide first-viewport, progressive-disclosure, accessibility and loading/error/degraded-state audit remain in progress.
18 PIXELRAG-P1-001 Not started Ollama-first multimodal embedding benchmark Verify approved visual embedding on GCP-A -> GCP-B -> 111 and design pgvector-compatible visual metadata; FAISS remains disallowed without ADR.
19 MARKET-P1-001 In progress Marketplace source contracts Yahoo Shopping remains active in V10.810 production with public-boundary allowlists, bounded streaming/rate, provenance, current product-detail readback, stock/spec/variant guards, source-specific promotion partition, idempotent exact canary activation and durable activation readback across no-write runs. Four fresh verified Yahoo offers now contribute formal evidence across completed batches; non-exact and unit-price candidates do not. Shopee, Coupang, ETMall, Friday and Rakuten still require equivalent structured contracts, and blocked pages remain non-product data.
20 QA-P1-001 In progress Deterministic test and CI governance V10.816 broad regression is 2,223 passed / 15 skipped / 0 failed; focused model/dedupe regression is 93 passed, and independent ninth-round review found no material issue. Production parity is verified for all 20/20 changed source hashes and 30/30 runtime env contracts, with an independent Windows 99 verifier plus RAG/NemoTron canaries. No matching EwoooC runner executed V10.816, so formal Gitea CI/CD remains missing even though the bounded production release is verified.

P2

Order ID Status Work item Exit evidence / next machine action
21 GOV-P2-001 Not started Continuous NIST/ASVS control trend Persist governance snapshots, compare control/asset/runtime drift and create ordered work items automatically.
22 DATA-P2-001 Not started Data classification and retention enforcement Classify business, personal, operational and model data; automate retention, deletion eligibility and audit evidence without destructive default actions.
23 CHAOS-P2-001 Not started Controlled resilience exercises Run non-destructive model-host, MCP, queue, Telegram and app-container failure drills with rollback and learning receipts.

Completed Foundations

These are reusable foundations, not proof that the full program is complete.

Status Capability Current boundary
Completed Multi-commerce PixelRAG visual evidence for momo, pchome, shopee_tw, coupang_tw, yahoo_shopping_tw, etmall_tw, friday_tw, rakuten_tw Evidence-only; blocked pages are not product data.
Completed External MCP/RAG capability inventory Registry/integration readback exists; runtime enablement remains P0.
Completed PixelRAG receipt -> RAG candidate replay Candidate-only; no formal knowledge or price write.
Completed Source-contract replay worker Public-boundary artifact receipts only.
Completed Marketplace adapter preflight and dry-run Deterministic no-write contracts.
Completed Marketplace identity matcher replay Candidate identity only.
Completed PromotionGate replay No production write.
Completed Embedding-signature guard replay Signature readiness only.
Completed Candidate knowledge replay Internal RAG preview only; no DB/model call.
Production verified; degraded fallback Model-aware NemoTron dispatcher fallback V10.816 production uses one modular exact-digest candidate registry for production and canary: GCP-A/GCP-B qwen3:14b with 60-second attempts, then 111 qwen3:8b with 45 seconds, think=false, fixed num_ctx=4096 / num_predict=512 and one total deadline. Run 1b335e97-fa31-418b-b925-759bc1036267 passed the shared app/scheduler and cross-container reservation canaries, then produced a valid decision from ollama_111_fallback after three attempts with no tool or business-data writes. Privacy-safe state hashes SKU values and the four-hour side_effect_started quarantine remains fail-closed after durable-effect uncertainty. GCP-A replacement, GCP-B capacity and controlled RAG activation remain unresolved and are not hidden by the fallback.
Completed PixelRAG application portfolio Commerce/RAG/UX/ops/marketing/governance inventory.
Completed Ollama-first VLM route readiness and replay worker Evidence-bound artifact output; no direct price write.
Completed Platform probe worker Shopee/Coupang barriers become structured fallback/backoff receipts.

Definition Of Done

A work item can be Completed only when the same production run contains:

  1. sensor/source receipt;
  2. normalized canonical asset identity;
  3. source-of-truth diff;
  4. AI decision and candidate action;
  5. risk/policy decision;
  6. check-mode/dry-run receipt;
  7. idempotent bounded execution receipt;
  8. independent post-verifier and rollback/no-write terminal;
  9. incident/Telegram/KM/RAG/MCP/PlayBook durable acknowledgement.

Missing any stage means partial, degraded or blocked_with_safe_next_action.