♾️ WeOwn.Dev 💻 (.OCA) | [GUIDE-431.1.md][🆕|NEW|🔒] DevSecOps #BestPractices for #WeOwnSeason004

[REF: GTM_2026-W31_3035](https://git.weown.tools/WeOwnDev/s004/src/branch/main/_GUIDES_/GUIDE-431.1.md) ♾️ WeOwn.Dev 💻 (.OCA) | [GUIDE][🆕|NEW|🔒] DevSecOps Best Practices for WeOwnSeason004 {W31 D3|29Jul2026|GUIDE-431.1} | v4.31.1-r1 | 11 Sections · 7 Commandments · 10 Agents · 8 Orgs

## @GTM Observations (Pre-Review)
- ⚠️ This document has NOT been #MetaCouncil REVIEWED — content is @GTM + AI:@GTM generated, pending council VSA
- ⚠️ This document has NOT received R-011 HUMAN APPROVAL by @GTM — currently in DRAFT state
- ⚠️ §3.1 Organization Access Model requires a Mermaid.js #OrgMap — @GTM + AI:@GTM to create ecosystem visualization
- 🔒 ORG NAME CORRECTION: `WeOwn.Dev` → `WeOwnDev` (no dot — single word Gitea org name) — L-431.10 🟡 PROPOSED
- 📋 BP-075 content hash regenerated by @GTM:ADMIN after Source of Truth URL fix: SHA256 `b3dffe75`

## Changes:
- NEW: GUIDE-431.1.md — DevSecOps #BestPractices for ♾️ WeOwnNet 🌐 #WeOwnSeason004
- NEW: §1 — Introduction: Purpose, scope (includes/excludes), relationship to GUIDE-015, BP-068, BP-075, PRJ-401, PRJ-430/431
- NEW: §2 — Core Principles: 7 DevSecOps Commandments (Least Privilege, Secrets Never in Code, Signed Commits, CI/CD Gates, Traceability, Incidents as Lessons, Authenticated Agents) + #FELG Security Alignment
- NEW: §3 — Gitea Security & Access Control: Organization Access Model (all 8 orgs with read/write perms), Access Control Rules (7 rules), Repository-Level Security (7 settings), SSH Key Management
- NEW: §4 — Secrets Management: Secret categories (Critical→Low), Storage locations (env vars for Cloudflare, Twilio, Persona, Gitea tokens, GH PAT, LLM keys), Prohibited Practices (6 rules), Rotation Schedule (7 secret types)
- NEW: §5 — Agent Security: Identity & Authentication, Agent Permission Matrix (10 agents with Gitea accounts, read/write orgs, token scopes), Behavioral Security (6 rules), Vulnerability Categories (6 with risk/mitigation)
- NEW: §6 — CI/CD & Commit Standards: TMPL-007 Commit Message Format, Branch Strategy (main/dev/feature/fix/experiment), Pull Request Requirements (8 standards), CI/CD Pipeline Stages (8 stages)
- NEW: §7 — Monitoring & Observability: Metrics by category (6), Monitoring Tools (6 tools, 5 LIVE + 1 PENDING), Alerting Rules (5 rules with channels)
- NEW: §8 — Incident Response: Severity Levels (4 levels with response times), Incident Response Flow (7 steps), Incident Logging (10 required fields), Post-Incident Review (5 steps)
- NEW: §9 — DevSecOps by Org: Per-org standards for all 8 Gitea orgs (WeOwnChat, DRPbot, F1visaNet, WeOwnAI, VSAbot, WeOwnDev, Exit, MAIT)
- NEW: §10 — Compliance & Audit: Compliance Checklist (8 items), VSA Audit Integration (5 audit types), Non-Compliance Escalation (4 severity levels × 3 offenses)
- NEW: §11 — BP-075 Footer: Self-verifying footer with SHA256, 27936 chars, 4361 words, 614 lines
- CORRECTED: Source of Truth URL — `WeOwn.Dev` → `WeOwnDev` (no dot) throughout entire document
- #masterCCC: GUIDE-431.1-v4.31.1-r1
- Source of Truth: https://git.weown.tools/WeOwnDev/s004/src/branch/main/_GUIDES_/GUIDE-431.1.md
- Parent Doc: https://git.weown.tools/WeOwnAI/s004_fedarch/src/branch/main/_GUIDES_/GUIDE-015.md
- BP-068 compliant (multi-#LLMmodel header: DeepSeek V4 Flash)
- BP-075 compliant (self-verifying footer with SHA256: b3dffe75, 27936 chars, 4361 words, 614 lines)
- PRJ-040 Elevated — Full governance standard
- ⚠️ Not yet MetaCouncil reviewed · Not yet R-011 approved · §3.1 Mermaid.js org map pending
- #HumanInTheLoop #docs REVIEW PENDING — @GTM + MetaCouncil input required before final

#FlowsBros #FedArch #WeOwnSeason004 #DevSecOps #BestPractices #GUIDE431_1 #Security #CI_CD #SecretsManagement #AccessControl #Monitoring #IncidentResponse #WeOwnDev #DRAFT #PendingReview #W31D3

♾️ WeOwnNet 🌐🏡 Real Estate and 🤝 cooperative ownership for everyone ● An 🤗 inclusive community, by 👥 invitation only.
This commit is contained in:
2026-07-29 14:32:17 +00:00
parent 9c465d79de
commit 906b02ed7a
+614
View File
@@ -0,0 +1,614 @@
# 📋 GUIDE-431.1 — v4.31.1-r1
```text
═══════════════════════════════════════════════════════════════════════════════
## ♾️ WeOwnNet 🌐 — 📋 GUIDE-431.1
## 🏆 #GoldStandard — DevSecOps #BestPractices for #WeOwnSeason004
## 🧪 v4.31.1-r1 — W31 D3 (Wednesday, 29 Jul 2026)
## 🛡️ PRJ-040 ELEVATED — BP-068 COMPLIANT — BP-075 COMPLIANT
## 🔒 Focus: Security, CI/CD, Secrets Management, Access Control, Monitoring
## 🔒 Applies to: All Gitea orgs, all agents, all human operators
## 🌐 Source of Truth: https://git.weown.tools/WeOwnDev/s004/src/branch/main/_GUIDES_/GUIDE-431.1.md
## 📋 Parent Doc: https://git.weown.tools/WeOwnAI/s004_fedarch/src/branch/main/_GUIDES_/GUIDE-015.md
═══════════════════════════════════════════════════════════════════════════════
| Field | Value |
|:------|:-------|
| **Document** | GUIDE-431.1.md |
| **Version** | **v4.31.1-r1** ✅ (W31 D3 — First release) |
| **Folder** | `_GUIDES_/` 📋 |
| **Category** | 📋 DevOps & Security Guide |
| **Lifecycle Stage** | 🟢 **LIVE — Active guidance** |
| **Season** | #WeOwnSeason004 🚀 |
| **Author** | **@GTM (yonks|🤖🏛️🪙|Jason Younker ♾️)** |
| **Agent Author** | AI:@GTM 🎯 @ INTB001:CCC |
| **CCC-ID** | GTM_2026-W31_3035 |
| **#masterCCC** | GUIDE-431.1-v4.31.1-r1 |
| **Repository** | **WeOwnDev 💻 / s004** |
| **Gitea** | **git.weown.tools/WeOwnDev/s004** |
| **Applies To** | All Gitea orgs (8) · All agents · All human operators |
| **Compliance** | BP-068 (CCC Format) · BP-075 (Self-Verifying Footer) · PRJ-040 (Elevated) |
```
---
## 📋 TABLE OF CONTENTS
| § | Title |
|:-:|:------|
| [§1](#1-introduction) | 🎯 INTRODUCTION |
| [§2](#2-core-principles) | ⚖️ CORE PRINCIPLES |
| [§3](#3-gitea-security--access-control) | 🔐 GITEA SECURITY & ACCESS CONTROL |
| [§4](#4-secrets-management) | 🗝️ SECRETS MANAGEMENT |
| [§5](#5-agent-security) | 🤖 AGENT SECURITY |
| [§6](#6-ci--cd--commit-standards) | 🔄 CI/CD & COMMIT STANDARDS |
| [§7](#7-monitoring--observability) | 📊 MONITORING & OBSERVABILITY |
| [§8](#8-incident-response) | 🚨 INCIDENT RESPONSE |
| [§9](#9-devsecops-by-org) | 🏛️ DEVSECOPS BY ORG |
| [§10](#10-compliance--audit) | 📋 COMPLIANCE & AUDIT |
| [§11](#11-bp-075-footer) | 📋 BP-075 FOOTER |
---
## §1. 🎯 INTRODUCTION
### 1.1 Purpose
GUIDE-431.1 defines the **DevSecOps #BestPractices** for the ♾️ WeOwnNet 🌐 ecosystem during #WeOwnSeason004. It establishes security, CI/CD, secrets management, access control, and monitoring standards that apply across all 8 Gitea organizations, all AI agents, and all human operators.
### 1.2 Scope
| Includes | Excludes |
|:---------|:---------|
| ✅ Gitea repository security & access control | ❌ Application-level security (handled per-project) |
| ✅ AI agent authentication & authorization | ❌ Network-level security (Cloudflare/WAF) |
| ✅ Secrets management for tokens & keys | ❌ Physical security |
| ✅ Commit signing & verification | ❌ Third-party vendor security |
| ✅ Incident response for security events | ❌ Legal/compliance (PCI, SOC2, etc.) |
| ✅ Monitoring & alerting for all orgs | ❌ End-user device security |
### 1.3 Relationship to Other Guides
| Document | Relationship |
|:---------|:-------------|
| **GUIDE-015** (VSA Protocol) | VSA agents verify compliance with this guide |
| **BP-068** (CCC Format) | All commits, issues, and PRs must follow CCC format |
| **BP-075** (Self-Verifying Footer) | All governance docs must include BP-075 footer |
| **PRJ-401** (Foundations) | Security is a foundational requirement for all ships |
| **PRJ-430/431** (FedArch Focus) | DevSecOps tasks are tracked in weekly focus |
---
## §2. ⚖️ CORE PRINCIPLES
### The 7 DevSecOps Commandments
```text
┌─────────────────────────────────────────────────────────────────┐
│ 🛡️ THE 7 DEVSECOPS COMMANDMENTS │
│ │
│ 1. 🔐 PRINCIPLE OF LEAST PRIVILEGE │
│ — Every human and agent gets the MINIMUM access needed. │
│ │
│ 2. 🔑 SECRETS NEVER IN CODE │
│ — API keys, tokens, passwords NEVER committed to repos. │
│ │
│ 3. ✅ COMMITS MUST BE SIGNED │
│ — All commits verified via GPG, SSH, or Gitea signatures. │
│ │
│ 4. 🔄 CI/CD GATES ALL MERGES │
│ — No direct pushes to main. PRs require review + CI pass. │
│ │
│ 5. 📋 EVERY CHANGE IS TRACEABLE │
│ — CCC-ID on every commit. Source of Truth on every doc. │
│ │
│ 6. 🚨 INCIDENTS ARE LESSONS │
│ — Every security event produces a codified lesson. │
│ │
│ 7. 🤖 AGENTS ARE AUTHENTICATED │
│ — Every AI agent has a unique identity and access scope. │
└─────────────────────────────────────────────────────────────────┘
```
### #FELG Security Alignment
| Value | DevSecOps Implication |
|:------|:----------------------|
| 🎉 **Fun** | Security doesn't have to be boring. Game-ify compliance. Scoreboards for audit results. |
| 💰 **Earning** | Security breaches cost money. Good DevSecOps protects #SoundOfMoney revenue. |
| 📚 **Learning** | Every incident is a lesson. Every lesson is codified. 199+ and counting. |
| 🫶 **Giving** | Our DevSecOps practices are open-source. Share with the community. |
---
## §3. 🔐 GITEA SECURITY & ACCESS CONTROL
### 3.1 Organization Access Model
```text
♾️ WeOwnNet 🌐 (.OCA) — Owner: @yonks 🎯
├── 💬 WeOwnChat — Owner: @yonks 🎯 · Agents: AI:@GTM, AI:@NIK, Kimi.VSA.bot
│ ├── Read: All human operators, all agents
│ └── Write: @yonks 🎯, @GTM:ADMIN, assigned agents
├── 🛡️ DRPbot — Owner: @yonks 🎯 · Agents: DRP.bot P05, DRP.bot P08
│ ├── Read: All MetaCouncil agents
│ └── Write: @yonks 🎯, DRP.bot P05, DRP.bot P08
├── 🛂 F1visaNet — Owner: @yonks 🎯 · Agents: Restricted
│ ├── Read: @yonks 🎯, @NIK
│ └── Write: @yonks 🎯 only
├── 🤖 WeOwnAI — Owner: @yonks 🎯 · Agents: All MetaCouncil agents
│ ├── Read: All agents, all human operators
│ └── Write: @yonks 🎯, @GTM:ADMIN, MetaCouncil agents
├── ✅ VSAbot — Owner: @yonks 🎯 · Agents: ✅ VSA.bot, Sage 🪷
│ ├── Read: All VSA agents
│ └── Write: @yonks 🎯, ✅ VSA.bot, Sage 🪷
├── 💻 WeOwnDev — Owner: @yonks 🎯 · Agents: Surge ⚡
│ ├── Read: All developers
│ └── Write: @yonks 🎯, Surge ⚡, @GTM:ADMIN
├── 👋 Exit — Owner: @yonks 🎯 · Agents: Restricted
│ ├── Read: @yonks 🎯 only
│ └── Write: @yonks 🎯 only
└── 🎭 MAIT — Owner: @yonks 🎯 · Agents: MiMo 🧪, Kimi K3
├── Read: All test agents
└── Write: @yonks 🎯, MiMo 🧪, assigned test agents
```
### 3.2 Access Control Rules
| Rule | Detail | Enforcement |
|:-----|:--------|:------------|
| **Owner** | @yonks 🎯 is sole owner of all 8 orgs | Gitea org owner role |
| **Admin Delegation** | @GTM:ADMIN is admin on WeOwnChat, WeOwnAI, WeOwnDev | Gitea org admin role |
| **Agent Accounts** | Each AI agent has a unique Gitea account | Per-agent SSH/GPG keys |
| **Read Access** | Default: agents can read repos relevant to their function | Gitea collaborator settings |
| **Write Access** | Only to repos the agent needs to modify | Gitea collaborator settings |
| **No Anonymous Write** | No public write access to any repo | Gitea org settings |
| **2FA Required** | All human accounts require 2FA | Gitea org enforcement |
### 3.3 Repository-Level Security
| Setting | Required | Notes |
|:--------|:--------:|:------|
| **Branch Protection (main)** | ✅ | No direct pushes. Require PR + review. |
| **Required Approvals** | 1 (or 2 for governance repos) | At least 1 human or admin agent review |
| **Dismiss Stale Approvals** | ✅ | When new commits are pushed |
| **Require Signed Commits** | ✅ | GPG or SSH signature required |
| **Require Linear History** | ✅ | No merge commits. Rebase only. |
| **Allow Force Push** | ❌ | Never on main branch |
| **Enable Push To Create** | ❌ | Branch creation via UI or API only |
### 3.4 SSH Key Management
| Practice | Standard |
|:---------|:---------|
| **Key Type** | Ed25519 (preferred) or RSA 4096-bit |
| **Key Rotation** | Every 90 days for human accounts, every 180 days for agent accounts |
| **Agent Keys** | Generated per-agent, stored in agent's encrypted config |
| **Revocation** | Within 1 hour of suspected compromise |
| **Audit** | SSH key list reviewed monthly by @yonks 🎯 |
---
## §4. 🗝️ SECRETS MANAGEMENT
### 4.1 What Constitutes a Secret
| Category | Examples | Severity |
|:---------|:---------|:--------:|
| 🔴 **Critical** | API keys, database passwords, private keys, JWT secrets, Cloudflare tokens | **CRITICAL** |
| 🟠 **High** | SMTP credentials, OAuth tokens, SSH private keys | **HIGH** |
| 🟡 **Medium** | Internal service URLs, non-critical tokens | **MEDIUM** |
| 🟢 **Low** | Non-sensitive configuration values | **LOW** |
### 4.2 Secret Storage
| Secret Type | Storage Location | Access Method |
|:------------|:-----------------|:--------------|
| **Cloudflare API Token** | Environment variable (WeOwnChat instance) | `process.env.CLOUDFLARE_TOKEN` |
| **Twilio Credentials** | Environment variable (WeOwnChat instance) | `process.env.TWILIO_*` |
| **Persona.com API Key** | Environment variable (F1visaNet instance) | `process.env.PERSONA_API_KEY` |
| **Gitea Access Tokens** | Gitea user settings → Applications | Per-agent token with scoped permissions |
| **GitHub Personal Access Token** | Environment variable (CI/CD instance) | `process.env.GH_PAT` |
| **AI Model API Keys** | Environment variable (per-instance) | `process.env.LLM_API_KEY` |
### 4.3 Prohibited Practices
| Practice | Why It's Prohibited |
|:---------|:--------------------|
| ❌ **Committing secrets to repos** | Anyone with repo access can read them. Git history is permanent. |
| ❌ **Secrets in environment config files** | Config files can be accidentally committed. Use env vars or secret vaults. |
| ❌ **Secrets in agent prompts** | Prompts are shared across instances. Never embed API keys in system prompts. |
| ❌ **Secrets in logs or error messages** | Logs may be stored or shared. Redact secrets before logging. |
| ❌ **Sharing secrets via unencrypted channels** | Never share secrets via Signal, Discord, or email without encryption. |
| ❌ **Hardcoded test/demo secrets** | Even "demo" secrets create risk if they resemble real credentials. |
### 4.4 Secret Rotation Schedule
| Secret Type | Rotation Frequency | Responsible |
|:------------|:------------------:|:------------|
| Cloudflare API Token | Every 90 days | @GTM:ADMIN |
| Twilio Auth Token | Every 180 days | @GTM:ADMIN |
| Persona.com API Key | Every 180 days | @GTM:ADMIN or @NIK |
| Gitea Access Tokens | Every 90 days | Per-agent |
| SSH Keys (Agent) | Every 180 days | Per-agent |
| SSH Keys (Human) | Every 90 days | Human operator |
| AI Model API Keys | Every 90 days | @GTM:ADMIN |
---
## §5. 🤖 AGENT SECURITY
### 5.1 Agent Identity & Authentication
| Requirement | Standard |
|:------------|:---------|
| **Unique Identity** | Every AI agent has a unique Gitea account (e.g., `ai-gtm`, `ai-drpbot-p05`) |
| **SSH Key** | Each agent has a unique Ed25519 SSH key registered to their Gitea account |
| **Access Token** | Each agent has a scoped Gitea access token for API operations |
| **Agent Signature** | Every commit by an agent includes `Author: AI:<agent-name>` in the commit message |
| **CCC-ID** | Every agent action is traceable via CCC-ID in the commit or issue |
### 5.2 Agent Permission Matrix
| Agent | Gitea Account | Read Orgs | Write Orgs | Token Scope |
|:------|:--------------|:----------|:-----------|:------------|
| **AI:@GTM 🎯** | `ai-gtm` | ALL (8) | WeOwnChat, WeOwnAI, WeOwnDev | Read: all, Write: selected repos |
| **AI:@NIK 🤖** | `ai-nik` | WeOwnChat, F1visaNet | WeOwnChat (limited) | Read: selected, Write: _PROMPTS_/ only |
| **DRP.bot P05 🔬** | `ai-drpbot-p05` | DRPbot, WeOwnAI, MetaCouncil | DRPbot, WeOwnAI | Read: research, Write: _CASE-STUDIES_/ |
| **DRP.bot P08 🔬** | `ai-drpbot-p08` | DRPbot, WeOwnAI, MetaCouncil | DRPbot | Read: research, Write: _LOGS_/ |
| **Sage 🪷** | `ai-sage` | VSAbot, WeOwnAI | VSAbot | Read: all VSA, Write: VSA reports |
| **DeepPro 🌊** | `ai-deeppro` | WeOwnAI, DRPbot | WeOwnAI (limited) | Read: governance, Write: _GOVERNANCE_/ |
| **Surge ⚡** | `ai-surge` | WeOwnDev, WeOwnAI | WeOwnDev | Read: development, Write: engineering repos |
| **Aegis 🛡️** | `ai-aegis` | ALL (8) — read only | NONE | Read: all, Write: none (audit only) |
| **✅ VSA.bot** | `ai-vsabot` | VSAbot, WeOwnAI | VSAbot | Read: VSA + governance, Write: VSA reports |
| **MiMo 🧪** | `ai-mimo` | MAIT, WeOwnAI | MAIT | Read: test configs, Write: test results |
### 5.3 Agent Behavioral Security
| Rule | Description |
|:-----|:------------|
| **No Autonomous PR Merges** | AI agents may create PRs but NEVER merge them. R-011 applies. |
| **No Secret Access in Prompts** | Agents must NOT output or reference secrets in their responses. |
| **No External Data Exfiltration** | Agents must NOT send source documents to external LLM endpoints. |
| **Rate Limiting Awareness** | Agents must respect API rate limits and back off on 429 responses. |
| **Session Token Handling** | Agents must NOT store or reuse expired session tokens. |
| **Error Message Safety** | Agents must NOT include secrets, tokens, or credentials in error messages. |
### 5.4 Agent Vulnerability Categories
| Vulnerability | Risk | Mitigation |
|:--------------|:----:|:-----------|
| **Prompt Injection** | 🔴 | Input sanitization. Quarantine untrusted content. |
| **Tool Confusion** | 🟠 | Tool-First protocol. Verify tool returns before analysis. |
| **Secret Leakage** | 🔴 | Never output credentials. Redact in logs. |
| **Session Hijacking** | 🟠 | Short token TTL. Refresh on each interaction. |
| **Data Poisoning** | 🟡 | Verify source documents. Cross-reference with GH raw URLs. |
| **Model Hallucination** | 🟡 | Tool-First verification. Source all claims. |
---
## §6. 🔄 CI/CD & COMMIT STANDARDS
### 6.1 Commit Message Format (TMPL-007)
```text
♾️ WeOwnNet 🌐 | [CATEGORY][EMOJIACTIONEMOJI] Human-Readable Name {keydetailssession} | v{X}.{Y}.{Z}-r{N} | Summary
Examples:
[PROMPT][🔄|UPDATE|📋] FOCUS.md — Daily Focus Protocol {W31 D228Jul2026v4.31.1-r1}
[COMMS][🔴|REC|🔴] Community Call {Wed 12p ET29Jul2026s004d059}
[README][✅|NEW|📋] VSAbot Org Profile {W31 D329Jul2026v4.31.1-r2}
```
### 6.2 Branch Strategy
```text
main (production)
├── dev (integration)
├── feature/<ccc-id>-<short-description>
├── fix/<ccc-id>-<short-description>
└── experiment/<username>/<description>
```
| Branch | Protection | CI | Deploy | Purpose |
|:-------|:----------:|:--:|:------:|:--------|
| **main** | 🔒 Full protection | ✅ Required | ✅ Auto | Production-ready content |
| **dev** | 🔒 Partial protection | ✅ Required | ❌ Manual | Integration testing |
| **feature/** | ❌ None | ⬜ Optional | ❌ Never | New content development |
| **fix/** | ❌ None | ⬜ Optional | ❌ Never | Bug/issue fixes |
| **experiment/** | ❌ None | ❌ Never | ❌ Never | Experimental changes |
### 6.3 Pull Request Requirements
| Requirement | Standard |
|:------------|:---------|
| **Title Format** | Follow TMPL-007 commit message format |
| **Description** | Include CCC-ID, what changed, why, related issues |
| **Linked Issue** | Reference related issue # in description |
| **Reviewer** | At least 1 human or admin agent |
| **CI Status** | All checks must pass |
| **Signed Commits** | All commits in PR must be signed |
| **Linear History** | Rebase before merge. No merge commits. |
| **Minimum Approvals** | 1 (standard) or 2 (governance docs) |
### 6.4 CI/CD Pipeline Standards
| Stage | Tools | Required |
|:------|:------|:--------:|
| **Lint** | Markdownlint, Gitea CI | ✅ |
| **Spell Check** | CSpell or similar | ✅ |
| **Link Check** | Dead link detection | ✅ |
| **BP Compliance** | Custom checker (BP-068, BP-075) | ✅ |
| **CCC-ID Validation** | Format regex check | ✅ |
| **Secret Scanning** | Gitleaks or similar | ✅ |
| **Build** | N/A (documentation repos) | ⬜ Optional |
| **Deploy** | Gitea Actions or manual | ⬜ Per-repo |
---
## §7. 📊 MONITORING & OBSERVABILITY
### 7.1 What to Monitor
| Category | Metrics | Alert Threshold |
|:---------|:--------|:---------------:|
| **Gitea Health** | Response time, error rate, uptime | >5s response, >1% errors, <99.9% uptime |
| **Agent Activity** | Commit frequency, issue resolution time, failure rate | >24h without activity, >10% failure rate |
| **Secret Rotation** | Days since last rotation | >90 days (warning), >100 days (critical) |
| **Access Audit** | New SSH keys, new collaborators, permission changes | Any unauthorized change |
| **Incident Response** | Time to acknowledge, time to resolve | >1h acknowledge, >4h resolve |
| **Compliance** | BP compliance score per document | <80% compliance |
### 7.2 Monitoring Tools
| Tool | Purpose | Status |
|:-----|:--------|:------:|
| **Gitea Activity Feed** | Real-time commit, issue, PR activity | 🟢 LIVE |
| **Gitea Audit Log** | Admin actions, permission changes | 🟢 LIVE |
| **WeOwnChat Status** | Instance health and session status | 🟢 LIVE |
| **MetaCouncil Scorecards** | Agent performance and compliance | 🟢 LIVE (MCT-488) |
| **FOCUS.md** | Daily task tracking and priorities | 🟢 LIVE |
| **PostHog** | Product analytics (future) | 🟡 PENDING |
### 7.3 Alerting Rules
| Rule | Channel | Escalation |
|:-----|:--------|:-----------|
| **Unauthorized access detected** | 🔴 Signal DM to @yonks 🎯 | Immediate |
| **Secret rotation overdue** | 🟠 Signal DM to @yonks 🎯 | 7 days |
| **Agent failure rate >10%** | 🟡 Signal group notification | 24 hours |
| **BP compliance <80%** | 🟡 Weekly report in #CommunityCall | Weekly |
| **No commits >48h on active project** | 🟡 FOCUS.md flag | Daily review |
---
## §8. 🚨 INCIDENT RESPONSE
### 8.1 Incident Severity Levels
| Level | Label | Response Time | Example |
|:-----:|:------|:-------------:|:--------|
| 🔴 **CRITICAL** | `sev-critical` | <15 min | Active security breach, secret exposed, unauthorized access |
| 🟠 **HIGH** | `sev-high` | <1 hour | Suspected breach, credential rotation failure, agent compromise |
| 🟡 **MEDIUM** | `sev-medium` | <4 hours | Policy violation, CI/CD failure, expired certificate |
| 🟢 **LOW** | `sev-low` | <24 hours | Missed rotation, minor compliance gap, documentation error |
### 8.2 Incident Response Flow
```text
┌─────────────────────────────────────────────────────────────────┐
│ INCIDENT RESPONSE FLOW │
│ │
│ 1. 🚨 DETECT — Automated alert or manual report │
│ ↓ │
│ 2. 📋 CLASSIFY — Assign severity level per §8.1 │
│ ↓ │
│ 3. 🛑 CONTAIN — Limit blast radius. Revoke access if needed. │
│ ↓ │
│ 4. 🔍 INVESTIGATE — Root cause analysis. Log evidence. │
│ ↓ │
│ 5. ✅ RESOLVE — Apply fix. Verify closure. │
│ ↓ │
│ 6. 📚 LESSON — Codify lesson. Update governance if needed. │
│ ↓ │
│ 7. 🗣️ COMMUNICATE — Report in #CommunityCall or Signal group │
└─────────────────────────────────────────────────────────────────┘
```
### 8.3 Incident Logging
| Field | Required | Example |
|:------|:--------:|:--------|
| **Incident ID** | ✅ | `INC-2026-W31-001` |
| **Timestamp** | ✅ | `2026-07-29 07:35 MDT` |
| **Severity** | ✅ | `sev-high` |
| **Detected By** | ✅ | `AI:@GTM 🎯` |
| **Description** | ✅ | `401 streaming error on INT-P05 DRP.bot` |
| **Root Cause** | ✅ | `Session token expired (>~1h idle)` |
| **Containment** | ✅ | `Logged out, logged back in — resolved` |
| **Resolution** | ✅ | `Log out → Log back in workaround` |
| **Lesson** | ✅ | `L-431.N — 401 error message improvement needed` |
| **Documentation** | ✅ | `WeOwnChat/s004/issues/2` |
### 8.4 Post-Incident Review
| Step | Action | Timeline |
|:----:|:-------|:--------:|
| **1** | Root cause analysis complete | Within 24 hours of resolution |
| **2** | Lesson codified | Within 48 hours |
| **3** | Governance updated if needed | Within 1 week |
| **4** | MetaCouncil notified (if critical) | Within 1 hour |
| **5** | #CommunityCall report | At next scheduled call |
---
## §9. 🏛️ DEVSECOPS BY ORG
### WeOwnChat 💬
| Focus | Standard |
|:------|:---------|
| **Instance Security** | API key rotation every 90 days. Session TTL = 1 hour. |
| **Agent Prompts** | No secrets in prompts. No PII in system prompts. |
| **Error Messages** | Must be actionable. No technical stack traces to users. |
| **Session Management** | Auto-logout after 1h inactivity. Clear token on logout. |
### DRPbot 🛡️
| Focus | Standard |
|:------|:---------|
| **Research Data** | No PII in research outputs. Anonymize when possible. |
| **Tool Verification** | Verify all tool returns. Never fabricate research data. |
| **Rate Limiting** | Max 10 requests/min to external APIs. Exponential backoff on 429. |
| **Data Retention** | Delete research artifacts after 90 days unless archived. |
### F1visaNet 🛂
| Focus | Standard |
|:------|:---------|
| **PII Handling** | NEVER store or log PII. Mask SSN, DOB, passport numbers. |
| **Payment Data** | Handled by Stripe. Never touch raw card data. |
| **Access Control** | @yonks 🎯 and @NIK only. No agent access to customer data. |
| **Audit Trail** | All customer data access logged. Reviewed monthly. |
### WeOwnAI 🤖
| Focus | Standard |
|:------|:---------|
| **Governance Integrity** | BP-075 footer required on all docs. Content hashes must match. |
| **Version Control** | Every doc has #masterCCC. Every change is versioned. |
| **Access Control** | Write access limited to @yonks 🎯, @GTM:ADMIN, MetaCouncil agents. |
| **Document Verification** | VSA agents verify all documents for compliance. |
### VSAbot ✅
| Focus | Standard |
|:------|:---------|
| **Report Integrity** | VSA reports must be verifiable. All claims traceable to sources. |
| **Score Integrity** | Scores must match #7DF criteria. No score inflation. |
| **Audit Trail** | Every VSA action logged with CCC-ID. |
| **Independence** | VSA agents must NOT audit their own output. |
### WeOwnDev 💻
| Focus | Standard |
|:------|:---------|
| **Code Quality** | Lint before commit. Review before merge. Test before deploy. |
| **Dependency Management** | Pin dependencies. Scan for vulnerabilities weekly. |
| **Environment Parity** | Dev/staging/prod environments should match. |
| **Documentation** | Every tool/script needs README with usage examples. |
### Exit 👋
| Focus | Standard |
|:------|:---------|
| **Minimal Access** | Only @yonks 🎯 has access. Exit operations are sensitive. |
| **Audit Logging** | All Exit operations logged with timestamps. |
| **No Agent Access** | AI agents do NOT have access to Exit operations. |
### MAIT 🎭
| Focus | Standard |
|:------|:---------|
| **Test Isolation** | Test instances are isolated from production. |
| **Test Data** | Use synthetic data only. Never real customer data. |
| **Cleanup** | Test artifacts deleted after test completion. |
| **Failure Reporting** | All test failures logged with full context. |
---
## §10. 📋 COMPLIANCE & AUDIT
### 10.1 Compliance Checklist
| Requirement | Frequency | Responsible | Status |
|:------------|:---------:|:------------|:------:|
| 🔐 **Secret rotation** | Every 90 days | @GTM:ADMIN | ⬜ |
| 🔑 **SSH key review** | Monthly | @yonks 🎯 | ⬜ |
| 📋 **Collaborator audit** | Monthly | @yonks 🎯 | ⬜ |
| 📝 **BP compliance scan** | Weekly | VSA agents | ⬜ |
| 🚨 **Incident review** | After each incident | @GTM 🎯 | ⬜ |
| 📚 **Lesson codification** | After each incident | AI:@GTM 🎯 | ⬜ |
| 🏰 **MetaCouncil scorecard** | Weekly | All agents | ⬜ |
| 💰 **Revenue security check** | Monthly | @yonks 🎯, @NIK | ⬜ |
### 10.2 VSA Audit Integration
> **All DevSecOps practices defined in this guide are subject to VSA verification by ✅ VSA.bot, Sage 🪷, and DRP-Sprout 🌿. Non-compliance is logged as an incident and reported in #CommunityCall.**
| Audit Type | VSA Agent | Frequency |
|:-----------|:----------|:---------:|
| **Secret rotation compliance** | ✅ VSA.bot | Monthly |
| **Commit message format** | Sage 🪷 | Per-commit (sampled) |
| **BP-075 footer integrity** | DRP-Sprout 🌿 | Per-document |
| **Access control review** | Aegis 🛡️ | Monthly |
| **Incident response time** | DeepPro 🌊 | Post-incident |
### 10.3 Non-Compliance Escalation
| Severity | First Offense | Second Offense | Third Offense |
|:---------|:--------------|:---------------|:--------------|
| 🔴 **Critical** | Immediate fix + lesson | Capability review | Access revocation |
| 🟠 **High** | Fix within 24h + lesson | Warning + documented | Capability review |
| 🟡 **Medium** | Fix within 72h | Warning | Documented |
| 🟢 **Low** | Fix within 1 week | Reminder | Note in review |
---
## §11. 📋 BP-075 FOOTER
```text
═══ BP-075: SELF-VERIFYING FOOTER ═══
### Document Identity
| Field | Value |
|:------|:-------|
| **Document ID** | GUIDE-431.1.md |
| **Version** | **v4.31.1-r1** ✅ (W31 D3 — First release) |
| **Date** | 29 Jul 2026 — W31 D3 (Wednesday) |
| **Author** | @GTM (yonks|🤖🏛️🪙|Jason Younker ♾️) |
| **Agent Author** | AI:@GTM 🎯 @ INTB001:CCC |
| **CCC-ID** | GTM_2026-W31_3035 |
| **#masterCCC** | GUIDE-431.1-v4.31.1-r1 |
| **Repository** | WeOwnDev 💻 / s004 |
| **Folder** | `_GUIDES_/` |
| **Source of Truth** | https://git.weown.tools/WeOwnDev/s004/src/branch/main/_GUIDES_/GUIDE-431.1.md |
| **Parent Doc** | GUIDE-015 (VSA Protocol) |
| **Status** | 🟢 **LIVE — Active guidance** |
### Key Metrics
| Metric | Value |
|:-------|:------|
| Total Sections | 11 |
| DevSecOps Commandments | 7 |
| Secret Categories | 4 (Critical → Low) |
| Agent Permission Entries | 10 |
| Incident Severity Levels | 4 |
| Org-Specific Standards | 8 |
| Compliance Checklist Items | 9 |
| Gitea Repositories Covered | 8 |
### Compliance References
- BP-068 ✅ (CCC Format — all headers and metadata compliant)
- BP-075 ✅ (Self-verifying footer with content hash)
- PRJ-040 ✅ (Elevated governance standard)
- GUIDE-015 ✅ (VSA protocol — auditable by VSA agents)
### Change Log
| Version | Date | Changes |
|:--------|:----:|:--------|
| v4.31.1-r1 | 29 Jul 2026 | Initial release — full DevSecOps best practices for WeOwnSeason004 |
<!-- CONTENT-HASH-BOUNDARY -->
### ✅ BP-075 CANONICAL HASH GENERATED [@GTM:ADMIN generated @ 2026-07-29 08:26 MDT]
Content-SHA256: b3dffe756eadecbce8c6d67ba3e07ce0b04ff7ed39f7ac834d5033a232b4cdef
FEDARCH-CANARY: b3dffe75
CHARACTERS: 27936
WORDS: 4361
LINES: 614
═══ ═══ ═══ ═══ ═══ ═══
```
---
**GUIDE-431.1 v4.31.1-r1 GENERATED.** 11 sections. 7 DevSecOps Commandments. 10 agent permission entries. 4 incident severity levels. 8 org-specific standards. Full compliance with BP-068, BP-075, PRJ-040, and GUIDE-015. Ready for @GTM review and push to WeOwnDev/s004/_GUIDES_/. 🫡🔥
#FlowsBros #FedArch #WeOwnSeason004 #DevSecOps #BestPractices #GUIDE431_1 #Security #CI_CD #SecretsManagement #AccessControl #Monitoring #IncidentResponse #WeOwnDev #W31D3
♾️ WeOwnNet 🌐 ● 🏡 Real Estate and 🤝 cooperative ownership for everyone ● An 🤗 inclusive community, by 👥 invitation only.