conductor/docs/MVP_TRACEABILITY.md
Victor Wiebe 498003f83d
Some checks failed
Release production image / production-image (push) Has been cancelled
Prepare Conductor v1.0.0 release
2026-08-08 14:21:40 -04:00

8.0 KiB
Raw Permalink Blame History

Conductor v1.0.0 Requirements Traceability

Purpose

This matrix maps every release-critical requirement area in docs/REQUIREMENTS.md and every approved workflow in MVP_SCOPE.md to an owning slice and acceptance evidence. It is the governance bridge between product requirements, implementation plans, and validation. Detailed field-level behavior remains authoritative in the linked schema and topic documents.

Release-critical requirements

ID v1.0.0 requirement area Owning slice Validation criterion and evidence Status
R1 Browser-based application, React frontend, backend API, SQLite persistence, and Docker Compose deployment Slices 1, 6, 8 Production builds, Compose startup/health/restart/persistence, backup/restore in docs/RELEASE_VALIDATION.md and TESTING.md Accepted
R2 Canonical JSON project definition shared by Visual Editor, JSON Editor, Preview, persistence, and validation Slices 2, 5, 6 Schema matrix, canonical round trips, cross-view synchronization, save/reload/restart tests Accepted
R3 Per-page visual canvas with the eleven schema-supported components, selection, movement, resizing, deletion, properties, and basic styling Slices 1, 2, 7c Slice 1/2 component tests and accepted canvas/property/Preview/manual multi-page workflows Accepted
R4 REST actions with supported methods, URL, headers, query/path parameters, body template, description, and fixed proxy-policy timeout Slices 2, 4 Action-editor tests, proxy integration/security suites, docs/SCHEMA.md, docs/PROXY_SECURITY.md Accepted
R5 Button onClick and page onLoad execution; component/variable request templates; Table selection runtime binding Slices 2, 6 Frontend event/template/runtime tests and deterministic launcher/dashboard E2E Accepted
R6 Top-level response/component bindings to supported component properties or typed runtime variables Slices 2, 5, 6 Binding diagnostics/runtime tests, compatibility validation, dependent-data/dashboard workflows Accepted
R7 Anonymous, Basic, Bearer, API-key header, and API-key query authentication with opaque canonical references Slices 3, 6 All-mode backend integration and manual authenticated-request acceptance Accepted
R8 Encrypted server-side secret lifecycle, compatible selection, missing-reference behavior, and no browser/project exposure Slices 3, 6 docs/SECRETS.md, lifecycle tests, restart checks, manual redaction gate Accepted
R9 Default-deny server-side proxy with URL/header validation, SSRF/redirect/DNS controls, limits, safe errors, and explicit internal exceptions Slices 4, 6 docs/PROXY_SECURITY.md, proxy security/integration tests, Docker manual gate Accepted
R10 Sanitized bounded execution history with filtering, persistence, clear behavior, and no credential leakage Slices 4, 6 Backend history/redaction tests, frontend history checks, exact marker scans Accepted
R11 Central schema/semantic validation, atomic persistence, actionable cross-view diagnostics, and unsaved-edit preservation Slices 5, 6 Backend rollback/version/semantic tests and Slice 5 manual failure/recovery acceptance Accepted
R12 Preview runtime with loading, empty, success, upstream failure, mapping failure, retry/recovery, and ephemeral state Slices 2, 5, 6 Preview suites and all six deterministic manual workflows Accepted
R13 Save/load, portable JSON definition, backend/full-stack restart persistence, runtime reset, and SQLite backup/recovery Slices 2, 5, 6 Canonical round-trip tests, E2E save/reload, restart and offline backup/restore evidence Accepted
R14 Accessible, scannable Actions & Bindings authoring with progressive disclosure and preserved local drafts Slice 6a 25 frontend suites / 520 tests and the accepted manual result recorded in TESTING.md Accepted
R15 Local authentication, secure sessions, global admin/user RBAC, admin-only authoring, and user lifecycle management Slice 7a Backend integration security matrix, frontend regression suite, and accepted manual admin/user workflows Accepted
R16 Immutable standalone published applications with public/authenticated visibility and server-owned published action execution Slice 7a Server-snapshot integration coverage and accepted public/restricted publishing workflows Accepted
R17 A fresh installation creates its initial administrator through a secure browser first-run flow without requiring Docker commands Slice 7b Atomic setup/security integration tests, frontend setup/password tests, recovery verification, and accepted manual workflow Accepted
R18 Authored and published applications support multiple deep-linked pages with page-local components and explicit global/page runtime-variable scope Slice 7c Schema/editor/runtime/publishing tests, multi-page browser E2E, security validation, and manual acceptance Accepted
R19 The Visual Editor presents project, page, page-setting, and lifecycle commands in a professional, accessible, responsive command ribbon Slice 7d 28 frontend suites / 528 tests, production build, and accepted manual visual validation Accepted
R20 Public self-hosters and SkeletonWorks operators can reproducibly install, secure, upgrade, back up, restore, and roll back a production Conductor release Slice 8 Production image/Compose tests, anonymous release download, fresh-host deployment, SkeletonWorks script validation, and encrypted-data backup/restore drill Planned

Approved acceptance workflows

Workflow Primary requirements Owning validation slice Evidence
Workflow Launcher R2R6, R11R13 Slice 6 Accepted workflow result in TESTING.md and deterministic E2E
Dependent Data R5, R6, R11, R12 Slice 6 Accepted workflow result in TESTING.md and runtime tests
Read-Only Dashboard R3, R5, R6, R12 Slice 6 Accepted workflow result in TESTING.md and deterministic E2E
Authenticated Request R4, R7R10 Slice 6 Accepted workflow result in TESTING.md and backend integration
JSON Editing and Persistence R1, R2, R11, R13 Slice 6 Accepted JSON/persistence results in TESTING.md
Failure Handling R9R12 Slice 6 Accepted recovery results in TESTING.md and Slice 5 evidence

Explicit post-MVP classifications

The following capabilities are not release requirements. Their presence in future-oriented requirements or architecture text does not block v1.0.0:

  • Provider-neutral AI assistance, including chat, generation, explanation, documentation, and refactoring
  • IBM Bob, watsonx, or any provider-specific AI dependency
  • OIDC/enterprise SSO, external identity provisioning, and claim/group mapping (Slice 9)
  • Nested/dynamic page routing, page parameters, and per-page authorization
  • Direct Dropdown-triggered REST execution and general action chaining/orchestration
  • Conditions, branches, loops, parallelism, retries, workflow graphs, and long-running task orchestration
  • OAuth 2.0, IBM Cloud IAM, mTLS, and custom authentication scripts
  • OpenAPI import and generated React/static/deployment-package output
  • Per-action timeout and expected-response-format controls
  • Binding transforms, expression languages, and configurable per-binding error policies
  • Canvas zoom/pan, undo/redo, advanced JSON-editor tooling, themes, and reusable component libraries
  • Tabs, modals, date pickers, file uploads, charts, progress indicators, and advanced Table capabilities
  • Custom/per-application roles, groups, team collaboration, approval workflows, enterprise audit retention, and SIEM integration
  • PostgreSQL/high-availability/centralized multi-user deployment

Governance rule

MVP_SCOPE.md controls the release boundary. A new capability becomes release-blocking only through an explicit product-owner scope decision followed by updates to this matrix, ROADMAP.md, the owning slice, and its validation criteria. Aspirational or compatibility-only schema text does not silently expand v1.0.0.