Skip to content

I13: The watcher #51

Description

@lex00

Lesson

The watcher has an empty card, so goal and done_when are written with the body. The desk on a schedule turns drift, expired grants and unused-access findings into reconcile and burndown PRs. One PR per finding, a cap on open PRs, and declines stick under Rounds' rules. Rounds as-is can enroll the repo for what its catalogs cover, and the IAM projections use the same form. The lesson demonstrates property XIII and closes no prescription. It enacts estate.md scenario 2, the drift, on a schedule rather than by hand, and backstops scenario 3 by flagging a leftover break-glass artifact.

Build

  • the schedule on the same teammate, 0 6 * * 1-5, with the prompt "run the watch"
  • terraform plan -detailed-exitcode per workspace and the aws-drift block emitted from the plan JSON
  • one PR per changed or deleted owned resource on desk/drift/<workspace>/<address> with a marker in the body, never a second while one is open, never a foreign resource, at most N open, and desk:reconsider to reopen a decline (decision 28)
  • burndown PRs on the same path for expired grants from scripts/expiring and for Access Analyzer unused-access findings
  • the Drift pane on the desk page, each row linking its PR
  • Rounds enrolled on the repo for the lint tier it already covers, so the lesson shows both
  • Lesson body written to the page model and verified on a live Floci stack per the authoring checklist in project/page-model.md

Done when

done_when is empty and the lesson closes no prescription, so prescriptions.md names no check for it. The archive has the long form. An unused grant becomes a removal PR citing the finding, volume respects the cap, and no PR is opened for a foreign resource.

Source material

Decision 28 governs the rules. Decision 14 keeps the watcher a proposer.

Open

D3 is filed needs-design on cadence and volume caps, and agentic.md repeats it, calling forty PRs on day one noise rather than hygiene, so N is unfixed. aws-desk.md leaves open whether enforcing the cap outside the prompt needs a small propose endpoint in Rounds' shape.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    I13IAM course lesson I13course-2The IAM course backlog

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions