docs(13): add phase 13 planning artifacts — virtual local cloud operations

Plans 01–11, CONTEXT, PATTERNS, RESEARCH, REVIEW-FIX, and updated
SUMMARY and CONTEXT for the virtual-local-cloud-operations phase.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
curo1305
2026-06-23 20:34:57 +02:00
co-authored by Claude Sonnet 4.6
parent 73328eee0b
commit b67e77dd69
16 changed files with 3114 additions and 0 deletions
@@ -0,0 +1,175 @@
---
phase: "13"
plan: "11"
type: execute
wave: 8
depends_on:
- "13-03"
- "13-04"
- "13-05"
- "13-06"
- "13-07"
- "13-08"
- "13-09"
- "13-10"
files_modified:
- .planning/ROADMAP.md
- AGENTS.md
- README.md
- RUNBOOK.md
- SECURITY.md
- backend/main.py
- frontend/package.json
autonomous: true
requirements:
- CONN-01
- CONN-02
- CONN-03
- CLOUD-02
- CLOUD-03
- CLOUD-04
- CLOUD-05
- CLOUD-06
- CLOUD-07
- CLOUD-09
must_haves:
truths:
- "Phase 13 closeout is isolated from implementation work."
- "Documentation, security evidence, version bumps, and ship gates happen only after all scoped behavior exists."
- "Full backend verification uses direct containerized pytest commands only, and the hardcoded-secret scan is non-skippable."
artifacts:
- path: "AGENTS.md"
provides: "Updated current-state line and shared-module guidance for shipped Phase 13 behavior."
- path: "SECURITY.md"
provides: "Phase 13 gate evidence for IDOR, CSRF, SSRF, typed conflict handling, audit secrecy, no-probe behavior, and the passing secret scan."
- path: ".planning/ROADMAP.md"
provides: "Phase 13 plan list and closeout status updates."
key_links:
- from: "completed Phase 13 behavior"
to: "docs, versions, and security evidence"
via: "final closeout-only plan"
pattern: "Phase 13"
---
<objective>
Run the Phase 13 closeout only after all implementation plans are complete: update roadmap and docs, bump versions, run the full suites and security gates, execute a non-skippable hardcoded-secret scan, and prepare the phase for atomic commit and push.
Purpose: Keep documentation, versioning, security review, and ship gates isolated in one bounded final plan.
Output: Ready-to-ship Phase 13 documentation and validation state.
</objective>
<execution_context>
@$HOME/.codex/gsd-core/workflows/execute-plan.md
@$HOME/.codex/gsd-core/templates/summary.md
</execution_context>
<context>
@AGENTS.md
@.planning/ROADMAP.md
@.planning/REQUIREMENTS.md
@README.md
@RUNBOOK.md
@SECURITY.md
@backend/main.py
@frontend/package.json
</context>
## Artifacts this phase produces
- Updated roadmap and phase-close documentation.
- Version bumps for the shipped Phase 13 user-facing behavior.
- Full Phase 13 validation, dependency-audit, and security-gate evidence collected in one place, including a passing hardcoded-secret scan.
## Pattern analogs
- `.planning/phases/12.1-fix-nextcloud-root-listing-and-sync-visibility/12.1-04-SUMMARY.md` — bounded closeout-only phase finish.
- `AGENTS.md` documentation protocol — required current-state, shared-module, and version-bump updates.
<tasks>
<task type="auto">
<name>Task 1: Update roadmap, docs, versions, and closeout evidence to match the shipped Phase 13 behavior</name>
<files>.planning/ROADMAP.md, AGENTS.md, README.md, RUNBOOK.md, SECURITY.md, backend/main.py, frontend/package.json</files>
<read_first>
- AGENTS.md
- .planning/ROADMAP.md
- README.md
- RUNBOOK.md
- SECURITY.md
</read_first>
<action>
Update Phase 13 planning and closeout documentation only after Plans 03 through 10 are complete. Record the finished health, reconnect, content, upload, create-folder, rename, move, delete, broader Drive scope, binary-only preview, and no-probe-on-navigation behavior accurately. Update the AGENTS current-state line and shared module map if the cloud operations layer became a new canonical shared module. Bump backend and frontend patch versions together for the shipped user-visible behavior, and record the final gate evidence in `SECURITY.md`, including the required hardcoded-secret scan result.
</action>
<acceptance_criteria>
- roadmap and docs describe the actual shipped Phase 13 scope without claiming Phase 14 cache lifecycle or deferred Collabora work
- AGENTS and README reflect the final user-visible behavior and version numbers accurately
- SECURITY captures the Phase 13 threat evidence, gate outcomes, and the passing hardcoded-secret scan
</acceptance_criteria>
<verify>
<automated>docker compose config --quiet</automated>
</verify>
<done>Phase 13 documentation, version metadata, and closeout evidence are ready for final validation.</done>
</task>
<task type="auto">
<name>Task 2: Run the full test, dependency, security, and hardcoded-secret gates before commit and push</name>
<files>.planning/ROADMAP.md, AGENTS.md, README.md, RUNBOOK.md, SECURITY.md, backend/main.py, frontend/package.json</files>
<read_first>
- AGENTS.md
- SECURITY.md
- .planning/phases/13-virtual-local-cloud-operations/13-VALIDATION.md
</read_first>
<action>
Run the full backend and frontend suites, then the focused security and dependency gates required by AGENTS.md. Every backend pytest invocation must be a direct `docker compose run --rm backend pytest ...` command. Run `docker compose run --rm backend bandit -r .`, `docker compose run --rm backend pip audit`, `cd frontend && npm audit --audit-level=high`, and the non-skippable hardcoded-secret scan `trufflehog filesystem --no-update --fail .`. Confirm the wrong-owner, admin-negative, credential-secrecy, SSRF, typed conflict, audit secrecy, and no-probe-on-navigation invariants remain green. Review the final diff for unrelated files or secret exposure, then stage, commit, and push atomically as the closeout action for the completed phase.
</action>
<acceptance_criteria>
- full backend and frontend suites pass
- backend security and dependency gates pass with direct containerized commands
- `trufflehog filesystem --no-update --fail .` passes and is recorded as closeout evidence
- the phase can be committed and pushed without unrelated files or secret exposure
</acceptance_criteria>
<verify>
<automated>docker compose run --rm backend pytest -v</automated>
<automated>cd frontend && npm run test</automated>
<automated>docker compose run --rm backend bandit -r .</automated>
<automated>docker compose run --rm backend pip audit</automated>
<automated>cd frontend && npm audit --audit-level=high</automated>
<automated>trufflehog filesystem --no-update --fail .</automated>
<automated>git diff --check</automated>
</verify>
<done>Phase 13 is fully validated, secret-scanned, and ready for atomic commit and push.</done>
</task>
</tasks>
<threat_model>
## Trust Boundaries
| Boundary | Description |
|----------|-------------|
| shipped code → documentation/security evidence | Closeout must describe only what actually shipped. |
| final diff → git history | Secret exposure and unrelated changes must be caught before commit. |
## STRIDE Threat Register
| Threat ID | Category | Component | Disposition | Mitigation Plan |
|-----------|----------|-----------|-------------|-----------------|
| T-13-33 | R | closeout docs | mitigate | Final-plan-only doc update ensures documentation follows completed implementation. |
| T-13-34 | I | release validation | mitigate | Full suites, dependency audits, and the non-skippable `trufflehog filesystem --no-update --fail .` gate run before commit and push. |
</threat_model>
<verification>
- Confirm all backend pytest commands are direct containerized invocations.
- Confirm full backend, frontend, security, dependency, and hardcoded-secret gates are isolated to this plan.
- Confirm docs and versions match the implemented Phase 13 scope and nothing deferred is claimed as shipped.
</verification>
<success_criteria>
- Docs, versions, security evidence, full gates, and the explicit hardcoded-secret scan are isolated to one bounded plan.
- Phase 13 can be closed without mixing implementation work into the same plan.
- The final plan preserves the projects commit, push, documentation, and closeout protocol exactly.
</success_criteria>
<output>
Create `.planning/phases/13-virtual-local-cloud-operations/13-11-SUMMARY.md` when done
</output>