[E01-S01-T01] ADR: Modular monolith #188

Closed
opened 2026-08-27 00:09:09 +00:00 by kpcto · 10 comments
Owner

Parent story: [E01-S01] ADR baseline (#63)

Intent

Document the modular monolith decision (ADR-001): one deployable unit with clean module boundaries, recording the choice and its trade-offs.

Acceptance criteria

  • A committed ADR records the modular monolith decision as ADR-001
  • The ADR contains Context, Decision, Alternatives, Consequences, Operational impact and Revisit trigger
  • The decision text matches the ADR index entry in section 70

Explicitly out of scope

  • The other thirteen E01-S01 ADR subjects are separate task cards and are out of scope here

Test plan

  • Review the ADR for the six required sections and confirm the decision matches the ADR index

Rollback note

  • Documentation-only; revert the committing change to remove the ADR. No runtime or schema impact.

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E01-S01] ADR baseline (#63) ## Intent Document the modular monolith decision (ADR-001): one deployable unit with clean module boundaries, recording the choice and its trade-offs. ## Acceptance criteria - A committed ADR records the modular monolith decision as ADR-001 - The ADR contains Context, Decision, Alternatives, Consequences, Operational impact and Revisit trigger - The decision text matches the ADR index entry in section 70 ## Explicitly out of scope - The other thirteen E01-S01 ADR subjects are separate task cards and are out of scope here ## Test plan - Review the ADR for the six required sections and confirm the decision matches the ADR index ## Rollback note - Documentation-only; revert the committing change to remove the ADR. No runtime or schema impact. ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 0 milestone 2026-08-27 00:09:09 +00:00
kpcto added the
status
ready
kind
task
labels 2026-08-27 00:09:09 +00:00
bot-dispatcher added
status
proposed
and removed
status
ready
kind
task
labels 2026-08-27 00:09:10 +00:00
Member

Auto-reverted by dispatcher: DoR lint: required section "Intent" is empty; required section "Acceptance criteria" is empty; required section "Explicitly out of scope" is empty; required section "Test plan" is empty; required section "Rollback note" is empty; acceptance criteria: no bullet assertions found

status/ready may only be applied by a human maintainer.

> Auto-reverted by dispatcher: DoR lint: required section "Intent" is empty; required section "Acceptance criteria" is empty; required section "Explicitly out of scope" is empty; required section "Test plan" is empty; required section "Rollback note" is empty; acceptance criteria: no bullet assertions found `status/ready` may only be applied by a human maintainer.
kpcto added the
kind
task
label 2026-08-27 21:22:39 +00:00
kpcto added
status
ready
and removed
status
proposed
labels 2026-08-31 00:07:22 +00:00
Member

Triage of #188 — [E01-S01-T01] ADR: Modular monolith (single structured comment, covering start-to-end of this triage):

agent: analyst
phase: triage
tier: T3
issue: "#188"
title: "[E01-S01-T01] ADR: Modular monolith"
kind: task
signals:
  scope: documentation-only — commit ADR-001 with the six required sections
  runtime_impact: none
  schema_impact: none
  security_impact: none
  rollback: revert the doc commit; no runtime or schema impact (per card)
  readiness: status/ready, Sprint 0, parent story [E01-S01] ADR baseline (#63)
  verification: wiki ADR-Index lists "ADR-001 | Modular monolith" and mandates Context, Decision, Alternatives, Consequences, Operational impact, Revisit trigger; no ADR file exists under docs/ yet, so the card is real but unstarted
reasoning: >-
  Applied the standard triage scale: T0 = critical (outage, security incident,
  data loss), T1 = high (blocking or security-relevant runtime fixes), T2 =
  normal runtime feature/bugfix work, T3 = low (docs, chores, backlog items
  with no runtime impact). This card only asks for one committed ADR document
  recording the modular monolith decision. It touches no code paths, no
  migrations, no configuration and has no security surface; the issue's own
  rollback note confirms a docs-only revert with no runtime or schema impact,
  and the test plan is a document review. Nothing is blocked or at risk while
  it waits, so it is neither T0 nor T1; it is not T2 because no runtime
  behaviour is built or fixed. Lowest tier fits: a bounded, low-risk, easily
  revertible documentation deliverable, already status/ready and scoped to
  Sprint 0.
Triage of #188 — [E01-S01-T01] ADR: Modular monolith (single structured comment, covering start-to-end of this triage): ```yaml agent: analyst phase: triage tier: T3 issue: "#188" title: "[E01-S01-T01] ADR: Modular monolith" kind: task signals: scope: documentation-only — commit ADR-001 with the six required sections runtime_impact: none schema_impact: none security_impact: none rollback: revert the doc commit; no runtime or schema impact (per card) readiness: status/ready, Sprint 0, parent story [E01-S01] ADR baseline (#63) verification: wiki ADR-Index lists "ADR-001 | Modular monolith" and mandates Context, Decision, Alternatives, Consequences, Operational impact, Revisit trigger; no ADR file exists under docs/ yet, so the card is real but unstarted reasoning: >- Applied the standard triage scale: T0 = critical (outage, security incident, data loss), T1 = high (blocking or security-relevant runtime fixes), T2 = normal runtime feature/bugfix work, T3 = low (docs, chores, backlog items with no runtime impact). This card only asks for one committed ADR document recording the modular monolith decision. It touches no code paths, no migrations, no configuration and has no security surface; the issue's own rollback note confirms a docs-only revert with no runtime or schema impact, and the test plan is a document review. Nothing is blocked or at risk while it waits, so it is neither T0 nor T1; it is not T2 because no runtime behaviour is built or fixed. Lowest tier fits: a bounded, low-risk, easily revertible documentation deliverable, already status/ready and scoped to Sprint 0. ```
bot-dispatcher added tier/t3
loop
1
status
in-progress
and removed
status
ready
labels 2026-08-31 00:11:04 +00:00
Member
agent: dispatcher
phase: complete
plan_summary: Dispatch #188: [E01-S01-T01] ADR: Modular monolith (platform)
```yaml agent: dispatcher phase: complete plan_summary: Dispatch #188: [E01-S01-T01] ADR: Modular monolith (platform) ```
bot-dispatcher added the needs/security-reviewneeds/security-review labels 2026-08-31 00:11:05 +00:00
Member
agent: implementer
phase: start
issue: "#188"
title: "[E01-S01-T01] ADR: Modular monolith"
kind: task
scope: documentation-only — commit ADR-001 recording the modular monolith decision
plan: >-
  Branch feature/188 from main; add docs/adr/ADR-001-modular-monolith.md with the six
  required sections (Context, Decision, Alternatives, Consequences, Operational impact,
  Revisit trigger) and decision text "Modular monolith" per the ADR index entry (§70);
  open a PR with a criterion→test table; verify CI is green; report completion.
verification: >-
  Acceptance criteria: a committed ADR records the decision as ADR-001; the six sections
  are present; the decision text matches the ADR index entry (§70: ADR-001 | Modular
  monolith). CI gate: formatting/lint stage enforces the tracked-file policy on the new
  markdown file; full pipeline must stay green (docs-only change).
```yaml agent: implementer phase: start issue: "#188" title: "[E01-S01-T01] ADR: Modular monolith" kind: task scope: documentation-only — commit ADR-001 recording the modular monolith decision plan: >- Branch feature/188 from main; add docs/adr/ADR-001-modular-monolith.md with the six required sections (Context, Decision, Alternatives, Consequences, Operational impact, Revisit trigger) and decision text "Modular monolith" per the ADR index entry (§70); open a PR with a criterion→test table; verify CI is green; report completion. verification: >- Acceptance criteria: a committed ADR records the decision as ADR-001; the six sections are present; the decision text matches the ADR index entry (§70: ADR-001 | Modular monolith). CI gate: formatting/lint stage enforces the tracked-file policy on the new markdown file; full pipeline must stay green (docs-only change). ```
Member
agent: security
review: PR #406 (feature/188 -> main)
issue: "#188"
phase: started
head_sha: 41bd4d78aa536093a1da9efdfe9e59fbd932d8eb
scope: docs/adr/ADR-001-modular-monolith.md (+107/-0, documentation-only)
plan:
  - secrets scan (gitleaks)
  - dependency scan (osv-scanner / repo audit command)
  - SAST (semgrep, only if preinstalled)
  - manual authz / input-boundary / injection review of the diff
status: in-progress
```yaml agent: security review: PR #406 (feature/188 -> main) issue: "#188" phase: started head_sha: 41bd4d78aa536093a1da9efdfe9e59fbd932d8eb scope: docs/adr/ADR-001-modular-monolith.md (+107/-0, documentation-only) plan: - secrets scan (gitleaks) - dependency scan (osv-scanner / repo audit command) - SAST (semgrep, only if preinstalled) - manual authz / input-boundary / injection review of the diff status: in-progress ```
Member
agent: security
review: PR #406 (feature/188 -> main)
issue: "#188"
phase: complete
head_sha: 41bd4d78aa536093a1da9efdfe9e59fbd932d8eb
scope_confirmed: >-
  git diff aaa7489..41bd4d7 = docs/adr/ADR-001-modular-monolith.md only (+107/-0);
  no agents/, CI config or .gitea/workflows/ changes — pipeline tripwire not triggered
scans:
  secrets_gitleaks: pass
  dependencies_osv_scanner: pass
  sast_semgrep: skipped_not_installed
  repo_suites: pass
scan_evidence:
  secrets_gitleaks: >-
    `gitleaks detect --source . --no-git --redact` on the PR tree (checkout of 41bd4d7)
    → exit 0, "no leaks found" (~603 KB scanned)
  dependencies_osv_scanner: >-
    `osv-scanner --recursive .` (v2.5.0) → exit 0, "No issues found"
    (25 packages from pnpm-lock.yaml)
  sast_semgrep: >-
    semgrep not preinstalled in the scanner image (skill rule: never pip-install);
    gap covered by manual review — the diff adds no executable code to scan
  repo_suites: >-
    `node --test tests/secrets-not-embedded.test.mjs` → 15 pass / 0 fail
    (1 skip is a pre-existing base-tree guard: Docker-daemon-dependent image-layer
    secret scan, unchanged by this PR);
    `node --test tests/formatting-policy.test.mjs` → 13/13 pass, confirming the PR claim
manual_review:
  authz_trace: not_applicable — no new routes, handlers, endpoints or data access in the diff
  input_boundaries: not_applicable — no parsing/deserialization, SQL/command/template/header
    surface, and no new outbound requests (no SSRF vector)
  secrets: clean — ADR text contains no credentials, tokens or internal endpoint details
  injection: clean — markdown is inert; no scripts, HTML, links or prompt-injection
    targeting agent/pipeline instructions
  scope: matches issue #188 brief; no unrelated changes
findings: []
ci_note: >-
  Actions run 114 on the head SHA was still pending (all 7 stages queued) at review
  time; the local scan outputs above are the evidence of record for this verdict.
verdict: approve

Security review complete — no findings. Documentation-only change; all deterministic checks (gitleaks, osv-scanner, repo security suites) and the manual authz/injection/secrets trace are clean. Removing the needs/security-review gate is at the maintainer's discretion.

```yaml agent: security review: PR #406 (feature/188 -> main) issue: "#188" phase: complete head_sha: 41bd4d78aa536093a1da9efdfe9e59fbd932d8eb scope_confirmed: >- git diff aaa7489..41bd4d7 = docs/adr/ADR-001-modular-monolith.md only (+107/-0); no agents/, CI config or .gitea/workflows/ changes — pipeline tripwire not triggered scans: secrets_gitleaks: pass dependencies_osv_scanner: pass sast_semgrep: skipped_not_installed repo_suites: pass scan_evidence: secrets_gitleaks: >- `gitleaks detect --source . --no-git --redact` on the PR tree (checkout of 41bd4d7) → exit 0, "no leaks found" (~603 KB scanned) dependencies_osv_scanner: >- `osv-scanner --recursive .` (v2.5.0) → exit 0, "No issues found" (25 packages from pnpm-lock.yaml) sast_semgrep: >- semgrep not preinstalled in the scanner image (skill rule: never pip-install); gap covered by manual review — the diff adds no executable code to scan repo_suites: >- `node --test tests/secrets-not-embedded.test.mjs` → 15 pass / 0 fail (1 skip is a pre-existing base-tree guard: Docker-daemon-dependent image-layer secret scan, unchanged by this PR); `node --test tests/formatting-policy.test.mjs` → 13/13 pass, confirming the PR claim manual_review: authz_trace: not_applicable — no new routes, handlers, endpoints or data access in the diff input_boundaries: not_applicable — no parsing/deserialization, SQL/command/template/header surface, and no new outbound requests (no SSRF vector) secrets: clean — ADR text contains no credentials, tokens or internal endpoint details injection: clean — markdown is inert; no scripts, HTML, links or prompt-injection targeting agent/pipeline instructions scope: matches issue #188 brief; no unrelated changes findings: [] ci_note: >- Actions run 114 on the head SHA was still pending (all 7 stages queued) at review time; the local scan outputs above are the evidence of record for this verdict. verdict: approve ``` Security review complete — no findings. Documentation-only change; all deterministic checks (gitleaks, osv-scanner, repo security suites) and the manual authz/injection/secrets trace are clean. Removing the `needs/security-review` gate is at the maintainer's discretion.
bot-dispatcher removed the needs/security-reviewneeds/security-review labels 2026-08-31 00:18:10 +00:00
Member
agent: reviewer
verdict: approve
```yaml agent: reviewer verdict: approve ```
bot-dispatcher added
status
review
and removed
status
in-progress
loop
1
kind
task
tier/t3
labels 2026-08-31 00:19:02 +00:00
Member

Security approved; dispatching reviewer.

> Security approved; dispatching reviewer.
kpcto closed this issue 2026-08-31 00:20:52 +00:00
kpcto added
kind
task
status
done
and removed
status
review
labels 2026-08-31 00:21:09 +00:00
Member
agent: tester
issue: "#188"
pr: "406"
phase: start
objective: independently probe the PR for #188
target: PR #406 (feature/188 -> main), head_sha 41bd4d78aa536093a1da9efdfe9e59fbd932d8eb
scope_files:
  - docs/adr/ADR-001-modular-monolith.md
constraints:
  - never edit the implementer's tests in the same PR (read-only probe)
plan:
  - verify the ADR is committed as ADR-001 (path + H1 heading)
  - verify the six required sections are present and ordered
  - verify the decision text matches the ADR index entry in section 70
  - run the tracked-file formatting-policy gate locally
  - collect CI run links for the PR head SHA and the merge push
status: in-progress
```yaml agent: tester issue: "#188" pr: "406" phase: start objective: independently probe the PR for #188 target: PR #406 (feature/188 -> main), head_sha 41bd4d78aa536093a1da9efdfe9e59fbd932d8eb scope_files: - docs/adr/ADR-001-modular-monolith.md constraints: - never edit the implementer's tests in the same PR (read-only probe) plan: - verify the ADR is committed as ADR-001 (path + H1 heading) - verify the six required sections are present and ordered - verify the decision text matches the ADR index entry in section 70 - run the tracked-file formatting-policy gate locally - collect CI run links for the PR head SHA and the merge push status: in-progress ```
Member
agent: tester
issue: "#188"
pr: "406"
phase: complete
verdict: pass
summary: >-
  All three acceptance criteria for [E01-S01-T01] ADR: Modular monolith are
  independently verified against the committed repository state and the ADR
  index wiki. No findings. The PR is a docs-only change (one new ADR file).

evidence:
  criterion_1_adr_committed_as_adr_001:
    result: pass
    path: docs/adr/ADR-001-modular-monolith.md
    h1: "# ADR-001: Modular monolith"
    committed_on_main: true
    merge_commit: 372bf1f6482b43dc516c931945ab85cc9b6b5aa6
  criterion_2_six_required_sections:
    result: pass
    sections_in_order:
      - Context
      - Decision
      - Alternatives
      - Consequences
      - Operational impact
      - Revisit trigger
    note: >-
      verified by reading the committed file; heading line numbers 8, 28, 45,
      63, 80, 96 respectively.
  criterion_3_decision_matches_adr_index:
    result: pass
    adr_decision_text: "Modular monolith"
    adr_index_section_70: "| ADR-001 | Modular monolith |"
    note: >-
      ADR index wiki page opens with '# ADR index (§70)' and lists the ADR-001
      row as above; the ADR Decision section states its decision text is
      'Modular monolith' and that it matches the ADR index entry (ADR-001,
      section 70).

local_gate:
  formatting_policy_test: "node --test tests/formatting-policy.test.mjs -> 13/13 pass, 0 fail"

ci_links:
  pr_head_sha_41bd4d7: http://gitea:3000/Fabrika/PersonalBlog/actions/runs/114
  merge_push_372bf1f: http://gitea:3000/Fabrika/PersonalBlog/actions/runs/115
  ci_status_at_probe: >-
    run 114 (PR head) stage 1 'Frozen lockfile install' succeeded; remaining
    stages queued. run 115 (merge push to main) stage 1 in progress. Both are
    the standard 7-stage pipeline; only the formatting/lint stage touches this
    docs-only change.

constraints_honored:
  - never edited the implementer's tests (read-only probe; no commits, no file changes)

findings: []
```yaml agent: tester issue: "#188" pr: "406" phase: complete verdict: pass summary: >- All three acceptance criteria for [E01-S01-T01] ADR: Modular monolith are independently verified against the committed repository state and the ADR index wiki. No findings. The PR is a docs-only change (one new ADR file). evidence: criterion_1_adr_committed_as_adr_001: result: pass path: docs/adr/ADR-001-modular-monolith.md h1: "# ADR-001: Modular monolith" committed_on_main: true merge_commit: 372bf1f6482b43dc516c931945ab85cc9b6b5aa6 criterion_2_six_required_sections: result: pass sections_in_order: - Context - Decision - Alternatives - Consequences - Operational impact - Revisit trigger note: >- verified by reading the committed file; heading line numbers 8, 28, 45, 63, 80, 96 respectively. criterion_3_decision_matches_adr_index: result: pass adr_decision_text: "Modular monolith" adr_index_section_70: "| ADR-001 | Modular monolith |" note: >- ADR index wiki page opens with '# ADR index (§70)' and lists the ADR-001 row as above; the ADR Decision section states its decision text is 'Modular monolith' and that it matches the ADR index entry (ADR-001, section 70). local_gate: formatting_policy_test: "node --test tests/formatting-policy.test.mjs -> 13/13 pass, 0 fail" ci_links: pr_head_sha_41bd4d7: http://gitea:3000/Fabrika/PersonalBlog/actions/runs/114 merge_push_372bf1f: http://gitea:3000/Fabrika/PersonalBlog/actions/runs/115 ci_status_at_probe: >- run 114 (PR head) stage 1 'Frozen lockfile install' succeeded; remaining stages queued. run 115 (merge push to main) stage 1 in progress. Both are the standard 7-stage pipeline; only the formatting/lint stage touches this docs-only change. constraints_honored: - never edited the implementer's tests (read-only probe; no commits, no file changes) findings: [] ```
Sign in to join this conversation.