# Roadmap — SDLC agentic distribué

Décision : [ADR 013](./adr/013-sdlc-agentic-distribue.md).  
Ce fichier = plan d’exécution (tickets). L’ADR reste décisionnel.

Effort : **S** ≤ 0,5 j · **M** 0,5–2 j · **L** 2–5 j.

Amendements Antigravity (2026-09-15) : DX-01, AI-05, DEVOPS-04, SEC-06 ; ordre Phase A ci-dessous. Voir section « Feedback Antigravity » dans l’ADR.

**Statut sprint Phase C (2026-09-15)** : Phase A complète ; Phase B complète côté repo (SEC-10 tokens emit + tool-policy, AI-01 hybrid opt-in, AI-11 plan/coverage déterministes) ; Phase C durcie (DEVOPS-20 quotas/pools policy, AI-20 evals+MCP CLI). Hermétisme runner / secrets scoped = ops GitLab pilote. DEVOPS-22 = décision only. Smoke vert.

---

## Ordre strict — Phase A / cette semaine

Implémenter **dans cet ordre**. Ne pas sauter une dépendance.

| # | ID | Dépend de | Statut |
|---|-----|-----------|--------|
| 1 | SEC-01 | — | ✅ fait |
| 2 | SEC-02 | SEC-01 | ✅ fait |
| 3 | SEC-03 | — | ✅ fait |
| 4 | DEVOPS-01 | — | ✅ fait |
| 5 | DEVOPS-03 | DEVOPS-01 | ✅ fait |
| 6 | DEVOPS-02 | DEVOPS-01 | ✅ fait |
| 7 | AI-01 | — | ✅ hybrid gate-first + LLM opt-in (`IASSET_HYBRID_LLM`) |
| 8 | DX-01 | SEC-01..03 | ✅ fait |
| 9 | AI-05 | AI-01 minimal | ✅ fait |
| 10 | E2E-01 | … | ✅ script local |
| 11 | SEC-04 | ADR 006 | ✅ fait |
| 12 | SEC-05 | DEVOPS-03 | ✅ fait |
| 13 | AI-02 | AI-01 | ✅ fait |
| 14 | AI-03 | SEC-02 | ✅ fait |
| 15 | DEVOPS-04 | DEVOPS-01 | ✅ fait (`one_writer` + `resource_group`) |
| 16 | SEC-06 | DEVOPS-01, SEC-02 | ✅ MVP doc + tags emit |

---

## Tickets Phase A (P0)

### SEC-01 — Restreindre `isExemptAgentWrite`

| | |
|--|--|
| **Statut** | ✅ fait (2026-09-15) |

### SEC-02 — Deny-read secrets (tools agent)

| | |
|--|--|
| **Statut** | ✅ fait (2026-09-15) |

### SEC-03 — Interdire `api_key` inline

| | |
|--|--|
| **Statut** | ✅ fait (2026-09-15) |

### SEC-04 — Pin `zot-iasset` + scanners secrets/deps obligatoires

| | |
|--|--|
| **Phase** | A |
| **Effort** | M |
| **Statut** | ✅ fait (2026-09-15) |
| **Fichiers** | `templates/gitlab-ci.iasset.yml`, `src/schemas/index.ts` (`policy.require_scanners`), `src/core/validate.ts`, `src/core/scaffold.ts`, smoke |

**Acceptance criteria**

- [x] Template pin `zot-iasset@0.4.0` (pas `@latest`).
- [x] Policy `require_scanners: [secrets, deps]` → fail `SEC_REQUIRE_SCANNER` si pas de `command`.
- [x] Scaffold placeholders secrets/deps sans command ; CLI ne shippe aucun binaire scanner.

### SEC-05 — Matrice secrets × kind

| | |
|--|--|
| **Phase** | A |
| **Statut** | ✅ fait — `docs/ci-runner-secrets.md` (modes + kinds) |

**Acceptance criteria**

- [x] Table variables × mode et × kind (review, implement, ops, spec, event, telemetry, planner, test-author).
- [x] Ops prod : pas de token merge ; review déterministe : pas de clé LLM obligatoire.

### SEC-06 — Profil runner `agent-sandbox`

| | |
|--|--|
| **Phase** | A fin / B |
| **Statut** | ✅ fait — doc + tags emit + soft-check ; isolation OS = config runner consommateur |
| **Fichiers** | `docs/ci-runner-secrets.md`, `src/core/ci.ts`, `orchestration/policy.yaml` (`agent_sandbox`), template |

**Acceptance criteria**

- [x] Tag documenté `agent-sandbox` ; jobs agent/flow/review peuvent le cibler via emit.
- [x] Doc : SEC-01/02 = defence in depth applicative ; SEC-06 = isolation exécution.
- [x] Soft-check emit (warnings / `IASSET_CI_EMIT_STRICT`).
- [ ] Hermétisme egress/env/scratch prouvé sur runner pilote (reste ops GitLab consommateur).

### DX-01 — Parité local ↔ CI

| | |
|--|--|
| **Statut** | ✅ fait |

### DEVOPS-01 / 02 / 03

| | |
|--|--|
| **Statut** | ✅ fait |

### DEVOPS-04 — Concurrence writes multi-agents

| | |
|--|--|
| **Phase** | A fin / B |
| **Statut** | ✅ fait — stratégie `one_writer` + `resource_group: iasset-writer` |
| **Fichiers** | `iasset/orchestration/policy.yaml`, `src/core/ci.ts`, smoke |

**Acceptance criteria**

- [x] Stratégie documentée (`write_concurrency: one_writer`) et appliquée dans emit.
- [x] Smoke : orchestrate/implement pose `resource_group` ; test-author partage le groupe, planner read-only.

### AI-01 / AI-05 / E2E-01

| | |
|--|--|
| **Statut** | ✅ AI-01 hybrid gate-first + `IASSET_HYBRID_LLM` advisory ; AI-05 golden ; E2E script local |

### AI-02 — Budgets réels (tokens / rounds)

| | |
|--|--|
| **Statut** | ✅ fait |
| **Fichiers** | `implementer.yaml` budget, `openai-driver.ts`, `flow.ts`, smoke |

**Acceptance criteria**

- [x] Caps `max_tokens` / `max_rounds` appliqués et journalisés (trace driver / effective rounds).
- [x] Dépassement tokens → stop déterministe (message AI-02).

### AI-03 — Catalogue tools déclaratif

| | |
|--|--|
| **Statut** | ✅ fait |
| **Fichiers** | agents YAML `tools:`, `openai-driver` `selectTools` / `assertToolInCatalog` |

**Acceptance criteria**

- [x] Liste tools dans YAML agent ; hors catalogue → refus.
- [x] Aligné deny-read SEC-02.

---

## Tickets Phase B (P1)

### DEVOPS-10 — `ci emit --mode orchestrate`

| | |
|--|--|
| **Statut** | ✅ fait |
| **AC** | child pipeline flow ordonnés / `needs` selon `depends_on` ; pas d’auto-merge |

### DEVOPS-11 — `orchestration/policy.yaml`

| | |
|--|--|
| **Statut** | ✅ fait |
| **AC** | routes déclaratives ; telemetry→implement refusé |

### DEVOPS-12 — Consolidation events.jsonl + hash-chain

| | |
|--|--|
| **Statut** | ✅ fait |
| **AC** | `prev_hash`/`hash` ; `event consolidate` / `verify-chain` ; tamper détectable |

### SEC-10 — Identité agent + tool-policy + tokens LP

| | |
|--|--|
| **Statut** | ✅ fait — `IASSET_AGENT_IDENTITY` + `IASSET_TOKEN_KIND` + scrub emit + `token-policy.ts` ; secrets scoped GitLab = hors repo |
| **Fichiers** | `src/core/token-policy.ts`, `src/core/ci.ts`, `docs/ci-runner-secrets.md` |

### SEC-11 — `may_edit_with_gate` → fail CI sans HITL

| | |
|--|--|
| **Statut** | ✅ fait — erreur `ARCH_BOUNDARY_HITL_REQUIRED` sauf `IASSET_HITL_APPROVED=true` |

### AI-10 — Supervisor + run-id / context pack

| | |
|--|--|
| **Statut** | ✅ fait — `iasset context-pack` ; pack borné journalisé |

### AI-11 — Agents `test-author` + `planner`

| | |
|--|--|
| **Statut** | ✅ fait — plan topo `depends_on` + coverage suites déterministes ; LLM advisory via `IASSET_HYBRID_LLM` |
| **Fichiers** | `src/core/status.ts`, scaffold agents, emit orchestrate |

---

## Tickets Phase C (P2)

| ID | Titre | Statut | Notes |
|----|-------|--------|-------|
| DEVOPS-20 | Pools runners isolés + quotas | ✅ repo | `runner_pools` + `quotas` policy → emit budgets/tags ; isolation OS = ops GitLab |
| AI-20 | Evals full + MCP mince | ✅ repo | `iasset evals` + fixtures ; MCP `snapshot/read/list/tools` ; pas de daemon réseau |
| DEVOPS-21 | SLSA-like artifacts | ✅ MVP | `iasset reports attest` → `attestation.yaml` |
| DEVOPS-22 | Bus externe si saturation | ⏸ décision only | pas d’impl sans ADR dédiée |

---

## Hors backlog (rappel)

- Auto-merge / auto-prod / auto-flow telemetry.
- Temporal, Kafka, rewrite runtime.
- Scanners embarqués dans le package npm.
- Forcer chaque tour multi-turn LLM via child pipeline.
- RAG dans le core npm.
