Files
yonks 906b02ed7a ♾️ WeOwn.Dev 💻 (.OCA) | [GUIDE-431.1.md][🆕|NEW|🔒] DevSecOps #BestPractices for #WeOwnSeason004
[REF: GTM_2026-W31_3035](https://git.weown.tools/WeOwnDev/s004/src/branch/main/_GUIDES_/GUIDE-431.1.md) ♾️ WeOwn.Dev 💻 (.OCA) | [GUIDE][🆕|NEW|🔒] DevSecOps Best Practices for WeOwnSeason004 {W31 D3|29Jul2026|GUIDE-431.1} | v4.31.1-r1 | 11 Sections · 7 Commandments · 10 Agents · 8 Orgs

## @GTM Observations (Pre-Review)
- ⚠️ This document has NOT been #MetaCouncil REVIEWED — content is @GTM + AI:@GTM generated, pending council VSA
- ⚠️ This document has NOT received R-011 HUMAN APPROVAL by @GTM — currently in DRAFT state
- ⚠️ §3.1 Organization Access Model requires a Mermaid.js #OrgMap — @GTM + AI:@GTM to create ecosystem visualization
- 🔒 ORG NAME CORRECTION: `WeOwn.Dev` → `WeOwnDev` (no dot — single word Gitea org name) — L-431.10 🟡 PROPOSED
- 📋 BP-075 content hash regenerated by @GTM:ADMIN after Source of Truth URL fix: SHA256 `b3dffe75`

## Changes:
- NEW: GUIDE-431.1.md — DevSecOps #BestPractices for ♾️ WeOwnNet 🌐 #WeOwnSeason004
- NEW: §1 — Introduction: Purpose, scope (includes/excludes), relationship to GUIDE-015, BP-068, BP-075, PRJ-401, PRJ-430/431
- NEW: §2 — Core Principles: 7 DevSecOps Commandments (Least Privilege, Secrets Never in Code, Signed Commits, CI/CD Gates, Traceability, Incidents as Lessons, Authenticated Agents) + #FELG Security Alignment
- NEW: §3 — Gitea Security & Access Control: Organization Access Model (all 8 orgs with read/write perms), Access Control Rules (7 rules), Repository-Level Security (7 settings), SSH Key Management
- NEW: §4 — Secrets Management: Secret categories (Critical→Low), Storage locations (env vars for Cloudflare, Twilio, Persona, Gitea tokens, GH PAT, LLM keys), Prohibited Practices (6 rules), Rotation Schedule (7 secret types)
- NEW: §5 — Agent Security: Identity & Authentication, Agent Permission Matrix (10 agents with Gitea accounts, read/write orgs, token scopes), Behavioral Security (6 rules), Vulnerability Categories (6 with risk/mitigation)
- NEW: §6 — CI/CD & Commit Standards: TMPL-007 Commit Message Format, Branch Strategy (main/dev/feature/fix/experiment), Pull Request Requirements (8 standards), CI/CD Pipeline Stages (8 stages)
- NEW: §7 — Monitoring & Observability: Metrics by category (6), Monitoring Tools (6 tools, 5 LIVE + 1 PENDING), Alerting Rules (5 rules with channels)
- NEW: §8 — Incident Response: Severity Levels (4 levels with response times), Incident Response Flow (7 steps), Incident Logging (10 required fields), Post-Incident Review (5 steps)
- NEW: §9 — DevSecOps by Org: Per-org standards for all 8 Gitea orgs (WeOwnChat, DRPbot, F1visaNet, WeOwnAI, VSAbot, WeOwnDev, Exit, MAIT)
- NEW: §10 — Compliance & Audit: Compliance Checklist (8 items), VSA Audit Integration (5 audit types), Non-Compliance Escalation (4 severity levels × 3 offenses)
- NEW: §11 — BP-075 Footer: Self-verifying footer with SHA256, 27936 chars, 4361 words, 614 lines
- CORRECTED: Source of Truth URL — `WeOwn.Dev` → `WeOwnDev` (no dot) throughout entire document
- #masterCCC: GUIDE-431.1-v4.31.1-r1
- Source of Truth: https://git.weown.tools/WeOwnDev/s004/src/branch/main/_GUIDES_/GUIDE-431.1.md
- Parent Doc: https://git.weown.tools/WeOwnAI/s004_fedarch/src/branch/main/_GUIDES_/GUIDE-015.md
- BP-068 compliant (multi-#LLMmodel header: DeepSeek V4 Flash)
- BP-075 compliant (self-verifying footer with SHA256: b3dffe75, 27936 chars, 4361 words, 614 lines)
- PRJ-040 Elevated — Full governance standard
- ⚠️ Not yet MetaCouncil reviewed · Not yet R-011 approved · §3.1 Mermaid.js org map pending
- #HumanInTheLoop #docs REVIEW PENDING — @GTM + MetaCouncil input required before final

#FlowsBros #FedArch #WeOwnSeason004 #DevSecOps #BestPractices #GUIDE431_1 #Security #CI_CD #SecretsManagement #AccessControl #Monitoring #IncidentResponse #WeOwnDev #DRAFT #PendingReview #W31D3

♾️ WeOwnNet 🌐🏡 Real Estate and 🤝 cooperative ownership for everyone ● An 🤗 inclusive community, by 👥 invitation only.
2026-07-29 14:32:17 +00:00

615 lines
29 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# 📋 GUIDE-431.1 — v4.31.1-r1
```text
═══════════════════════════════════════════════════════════════════════════════
## ♾️ WeOwnNet 🌐 — 📋 GUIDE-431.1
## 🏆 #GoldStandard — DevSecOps #BestPractices for #WeOwnSeason004
## 🧪 v4.31.1-r1 — W31 D3 (Wednesday, 29 Jul 2026)
## 🛡️ PRJ-040 ELEVATED — BP-068 COMPLIANT — BP-075 COMPLIANT
## 🔒 Focus: Security, CI/CD, Secrets Management, Access Control, Monitoring
## 🔒 Applies to: All Gitea orgs, all agents, all human operators
## 🌐 Source of Truth: https://git.weown.tools/WeOwnDev/s004/src/branch/main/_GUIDES_/GUIDE-431.1.md
## 📋 Parent Doc: https://git.weown.tools/WeOwnAI/s004_fedarch/src/branch/main/_GUIDES_/GUIDE-015.md
═══════════════════════════════════════════════════════════════════════════════
| Field | Value |
|:------|:-------|
| **Document** | GUIDE-431.1.md |
| **Version** | **v4.31.1-r1** ✅ (W31 D3 — First release) |
| **Folder** | `_GUIDES_/` 📋 |
| **Category** | 📋 DevOps & Security Guide |
| **Lifecycle Stage** | 🟢 **LIVE — Active guidance** |
| **Season** | #WeOwnSeason004 🚀 |
| **Author** | **@GTM (yonks|🤖🏛️🪙|Jason Younker ♾️)** |
| **Agent Author** | AI:@GTM 🎯 @ INTB001:CCC |
| **CCC-ID** | GTM_2026-W31_3035 |
| **#masterCCC** | GUIDE-431.1-v4.31.1-r1 |
| **Repository** | **WeOwnDev 💻 / s004** |
| **Gitea** | **git.weown.tools/WeOwnDev/s004** |
| **Applies To** | All Gitea orgs (8) · All agents · All human operators |
| **Compliance** | BP-068 (CCC Format) · BP-075 (Self-Verifying Footer) · PRJ-040 (Elevated) |
```
---
## 📋 TABLE OF CONTENTS
| § | Title |
|:-:|:------|
| [§1](#1-introduction) | 🎯 INTRODUCTION |
| [§2](#2-core-principles) | ⚖️ CORE PRINCIPLES |
| [§3](#3-gitea-security--access-control) | 🔐 GITEA SECURITY & ACCESS CONTROL |
| [§4](#4-secrets-management) | 🗝️ SECRETS MANAGEMENT |
| [§5](#5-agent-security) | 🤖 AGENT SECURITY |
| [§6](#6-ci--cd--commit-standards) | 🔄 CI/CD & COMMIT STANDARDS |
| [§7](#7-monitoring--observability) | 📊 MONITORING & OBSERVABILITY |
| [§8](#8-incident-response) | 🚨 INCIDENT RESPONSE |
| [§9](#9-devsecops-by-org) | 🏛️ DEVSECOPS BY ORG |
| [§10](#10-compliance--audit) | 📋 COMPLIANCE & AUDIT |
| [§11](#11-bp-075-footer) | 📋 BP-075 FOOTER |
---
## §1. 🎯 INTRODUCTION
### 1.1 Purpose
GUIDE-431.1 defines the **DevSecOps #BestPractices** for the ♾️ WeOwnNet 🌐 ecosystem during #WeOwnSeason004. It establishes security, CI/CD, secrets management, access control, and monitoring standards that apply across all 8 Gitea organizations, all AI agents, and all human operators.
### 1.2 Scope
| Includes | Excludes |
|:---------|:---------|
| ✅ Gitea repository security & access control | ❌ Application-level security (handled per-project) |
| ✅ AI agent authentication & authorization | ❌ Network-level security (Cloudflare/WAF) |
| ✅ Secrets management for tokens & keys | ❌ Physical security |
| ✅ Commit signing & verification | ❌ Third-party vendor security |
| ✅ Incident response for security events | ❌ Legal/compliance (PCI, SOC2, etc.) |
| ✅ Monitoring & alerting for all orgs | ❌ End-user device security |
### 1.3 Relationship to Other Guides
| Document | Relationship |
|:---------|:-------------|
| **GUIDE-015** (VSA Protocol) | VSA agents verify compliance with this guide |
| **BP-068** (CCC Format) | All commits, issues, and PRs must follow CCC format |
| **BP-075** (Self-Verifying Footer) | All governance docs must include BP-075 footer |
| **PRJ-401** (Foundations) | Security is a foundational requirement for all ships |
| **PRJ-430/431** (FedArch Focus) | DevSecOps tasks are tracked in weekly focus |
---
## §2. ⚖️ CORE PRINCIPLES
### The 7 DevSecOps Commandments
```text
┌─────────────────────────────────────────────────────────────────┐
│ 🛡️ THE 7 DEVSECOPS COMMANDMENTS │
│ │
│ 1. 🔐 PRINCIPLE OF LEAST PRIVILEGE │
│ — Every human and agent gets the MINIMUM access needed. │
│ │
│ 2. 🔑 SECRETS NEVER IN CODE │
│ — API keys, tokens, passwords NEVER committed to repos. │
│ │
│ 3. ✅ COMMITS MUST BE SIGNED │
│ — All commits verified via GPG, SSH, or Gitea signatures. │
│ │
│ 4. 🔄 CI/CD GATES ALL MERGES │
│ — No direct pushes to main. PRs require review + CI pass. │
│ │
│ 5. 📋 EVERY CHANGE IS TRACEABLE │
│ — CCC-ID on every commit. Source of Truth on every doc. │
│ │
│ 6. 🚨 INCIDENTS ARE LESSONS │
│ — Every security event produces a codified lesson. │
│ │
│ 7. 🤖 AGENTS ARE AUTHENTICATED │
│ — Every AI agent has a unique identity and access scope. │
└─────────────────────────────────────────────────────────────────┘
```
### #FELG Security Alignment
| Value | DevSecOps Implication |
|:------|:----------------------|
| 🎉 **Fun** | Security doesn't have to be boring. Game-ify compliance. Scoreboards for audit results. |
| 💰 **Earning** | Security breaches cost money. Good DevSecOps protects #SoundOfMoney revenue. |
| 📚 **Learning** | Every incident is a lesson. Every lesson is codified. 199+ and counting. |
| 🫶 **Giving** | Our DevSecOps practices are open-source. Share with the community. |
---
## §3. 🔐 GITEA SECURITY & ACCESS CONTROL
### 3.1 Organization Access Model
```text
♾️ WeOwnNet 🌐 (.OCA) — Owner: @yonks 🎯
├── 💬 WeOwnChat — Owner: @yonks 🎯 · Agents: AI:@GTM, AI:@NIK, Kimi.VSA.bot
│ ├── Read: All human operators, all agents
│ └── Write: @yonks 🎯, @GTM:ADMIN, assigned agents
├── 🛡️ DRPbot — Owner: @yonks 🎯 · Agents: DRP.bot P05, DRP.bot P08
│ ├── Read: All MetaCouncil agents
│ └── Write: @yonks 🎯, DRP.bot P05, DRP.bot P08
├── 🛂 F1visaNet — Owner: @yonks 🎯 · Agents: Restricted
│ ├── Read: @yonks 🎯, @NIK
│ └── Write: @yonks 🎯 only
├── 🤖 WeOwnAI — Owner: @yonks 🎯 · Agents: All MetaCouncil agents
│ ├── Read: All agents, all human operators
│ └── Write: @yonks 🎯, @GTM:ADMIN, MetaCouncil agents
├── ✅ VSAbot — Owner: @yonks 🎯 · Agents: ✅ VSA.bot, Sage 🪷
│ ├── Read: All VSA agents
│ └── Write: @yonks 🎯, ✅ VSA.bot, Sage 🪷
├── 💻 WeOwnDev — Owner: @yonks 🎯 · Agents: Surge ⚡
│ ├── Read: All developers
│ └── Write: @yonks 🎯, Surge ⚡, @GTM:ADMIN
├── 👋 Exit — Owner: @yonks 🎯 · Agents: Restricted
│ ├── Read: @yonks 🎯 only
│ └── Write: @yonks 🎯 only
└── 🎭 MAIT — Owner: @yonks 🎯 · Agents: MiMo 🧪, Kimi K3
├── Read: All test agents
└── Write: @yonks 🎯, MiMo 🧪, assigned test agents
```
### 3.2 Access Control Rules
| Rule | Detail | Enforcement |
|:-----|:--------|:------------|
| **Owner** | @yonks 🎯 is sole owner of all 8 orgs | Gitea org owner role |
| **Admin Delegation** | @GTM:ADMIN is admin on WeOwnChat, WeOwnAI, WeOwnDev | Gitea org admin role |
| **Agent Accounts** | Each AI agent has a unique Gitea account | Per-agent SSH/GPG keys |
| **Read Access** | Default: agents can read repos relevant to their function | Gitea collaborator settings |
| **Write Access** | Only to repos the agent needs to modify | Gitea collaborator settings |
| **No Anonymous Write** | No public write access to any repo | Gitea org settings |
| **2FA Required** | All human accounts require 2FA | Gitea org enforcement |
### 3.3 Repository-Level Security
| Setting | Required | Notes |
|:--------|:--------:|:------|
| **Branch Protection (main)** | ✅ | No direct pushes. Require PR + review. |
| **Required Approvals** | 1 (or 2 for governance repos) | At least 1 human or admin agent review |
| **Dismiss Stale Approvals** | ✅ | When new commits are pushed |
| **Require Signed Commits** | ✅ | GPG or SSH signature required |
| **Require Linear History** | ✅ | No merge commits. Rebase only. |
| **Allow Force Push** | ❌ | Never on main branch |
| **Enable Push To Create** | ❌ | Branch creation via UI or API only |
### 3.4 SSH Key Management
| Practice | Standard |
|:---------|:---------|
| **Key Type** | Ed25519 (preferred) or RSA 4096-bit |
| **Key Rotation** | Every 90 days for human accounts, every 180 days for agent accounts |
| **Agent Keys** | Generated per-agent, stored in agent's encrypted config |
| **Revocation** | Within 1 hour of suspected compromise |
| **Audit** | SSH key list reviewed monthly by @yonks 🎯 |
---
## §4. 🗝️ SECRETS MANAGEMENT
### 4.1 What Constitutes a Secret
| Category | Examples | Severity |
|:---------|:---------|:--------:|
| 🔴 **Critical** | API keys, database passwords, private keys, JWT secrets, Cloudflare tokens | **CRITICAL** |
| 🟠 **High** | SMTP credentials, OAuth tokens, SSH private keys | **HIGH** |
| 🟡 **Medium** | Internal service URLs, non-critical tokens | **MEDIUM** |
| 🟢 **Low** | Non-sensitive configuration values | **LOW** |
### 4.2 Secret Storage
| Secret Type | Storage Location | Access Method |
|:------------|:-----------------|:--------------|
| **Cloudflare API Token** | Environment variable (WeOwnChat instance) | `process.env.CLOUDFLARE_TOKEN` |
| **Twilio Credentials** | Environment variable (WeOwnChat instance) | `process.env.TWILIO_*` |
| **Persona.com API Key** | Environment variable (F1visaNet instance) | `process.env.PERSONA_API_KEY` |
| **Gitea Access Tokens** | Gitea user settings → Applications | Per-agent token with scoped permissions |
| **GitHub Personal Access Token** | Environment variable (CI/CD instance) | `process.env.GH_PAT` |
| **AI Model API Keys** | Environment variable (per-instance) | `process.env.LLM_API_KEY` |
### 4.3 Prohibited Practices
| Practice | Why It's Prohibited |
|:---------|:--------------------|
| ❌ **Committing secrets to repos** | Anyone with repo access can read them. Git history is permanent. |
| ❌ **Secrets in environment config files** | Config files can be accidentally committed. Use env vars or secret vaults. |
| ❌ **Secrets in agent prompts** | Prompts are shared across instances. Never embed API keys in system prompts. |
| ❌ **Secrets in logs or error messages** | Logs may be stored or shared. Redact secrets before logging. |
| ❌ **Sharing secrets via unencrypted channels** | Never share secrets via Signal, Discord, or email without encryption. |
| ❌ **Hardcoded test/demo secrets** | Even "demo" secrets create risk if they resemble real credentials. |
### 4.4 Secret Rotation Schedule
| Secret Type | Rotation Frequency | Responsible |
|:------------|:------------------:|:------------|
| Cloudflare API Token | Every 90 days | @GTM:ADMIN |
| Twilio Auth Token | Every 180 days | @GTM:ADMIN |
| Persona.com API Key | Every 180 days | @GTM:ADMIN or @NIK |
| Gitea Access Tokens | Every 90 days | Per-agent |
| SSH Keys (Agent) | Every 180 days | Per-agent |
| SSH Keys (Human) | Every 90 days | Human operator |
| AI Model API Keys | Every 90 days | @GTM:ADMIN |
---
## §5. 🤖 AGENT SECURITY
### 5.1 Agent Identity & Authentication
| Requirement | Standard |
|:------------|:---------|
| **Unique Identity** | Every AI agent has a unique Gitea account (e.g., `ai-gtm`, `ai-drpbot-p05`) |
| **SSH Key** | Each agent has a unique Ed25519 SSH key registered to their Gitea account |
| **Access Token** | Each agent has a scoped Gitea access token for API operations |
| **Agent Signature** | Every commit by an agent includes `Author: AI:<agent-name>` in the commit message |
| **CCC-ID** | Every agent action is traceable via CCC-ID in the commit or issue |
### 5.2 Agent Permission Matrix
| Agent | Gitea Account | Read Orgs | Write Orgs | Token Scope |
|:------|:--------------|:----------|:-----------|:------------|
| **AI:@GTM 🎯** | `ai-gtm` | ALL (8) | WeOwnChat, WeOwnAI, WeOwnDev | Read: all, Write: selected repos |
| **AI:@NIK 🤖** | `ai-nik` | WeOwnChat, F1visaNet | WeOwnChat (limited) | Read: selected, Write: _PROMPTS_/ only |
| **DRP.bot P05 🔬** | `ai-drpbot-p05` | DRPbot, WeOwnAI, MetaCouncil | DRPbot, WeOwnAI | Read: research, Write: _CASE-STUDIES_/ |
| **DRP.bot P08 🔬** | `ai-drpbot-p08` | DRPbot, WeOwnAI, MetaCouncil | DRPbot | Read: research, Write: _LOGS_/ |
| **Sage 🪷** | `ai-sage` | VSAbot, WeOwnAI | VSAbot | Read: all VSA, Write: VSA reports |
| **DeepPro 🌊** | `ai-deeppro` | WeOwnAI, DRPbot | WeOwnAI (limited) | Read: governance, Write: _GOVERNANCE_/ |
| **Surge ⚡** | `ai-surge` | WeOwnDev, WeOwnAI | WeOwnDev | Read: development, Write: engineering repos |
| **Aegis 🛡️** | `ai-aegis` | ALL (8) — read only | NONE | Read: all, Write: none (audit only) |
| **✅ VSA.bot** | `ai-vsabot` | VSAbot, WeOwnAI | VSAbot | Read: VSA + governance, Write: VSA reports |
| **MiMo 🧪** | `ai-mimo` | MAIT, WeOwnAI | MAIT | Read: test configs, Write: test results |
### 5.3 Agent Behavioral Security
| Rule | Description |
|:-----|:------------|
| **No Autonomous PR Merges** | AI agents may create PRs but NEVER merge them. R-011 applies. |
| **No Secret Access in Prompts** | Agents must NOT output or reference secrets in their responses. |
| **No External Data Exfiltration** | Agents must NOT send source documents to external LLM endpoints. |
| **Rate Limiting Awareness** | Agents must respect API rate limits and back off on 429 responses. |
| **Session Token Handling** | Agents must NOT store or reuse expired session tokens. |
| **Error Message Safety** | Agents must NOT include secrets, tokens, or credentials in error messages. |
### 5.4 Agent Vulnerability Categories
| Vulnerability | Risk | Mitigation |
|:--------------|:----:|:-----------|
| **Prompt Injection** | 🔴 | Input sanitization. Quarantine untrusted content. |
| **Tool Confusion** | 🟠 | Tool-First protocol. Verify tool returns before analysis. |
| **Secret Leakage** | 🔴 | Never output credentials. Redact in logs. |
| **Session Hijacking** | 🟠 | Short token TTL. Refresh on each interaction. |
| **Data Poisoning** | 🟡 | Verify source documents. Cross-reference with GH raw URLs. |
| **Model Hallucination** | 🟡 | Tool-First verification. Source all claims. |
---
## §6. 🔄 CI/CD & COMMIT STANDARDS
### 6.1 Commit Message Format (TMPL-007)
```text
♾️ WeOwnNet 🌐 | [CATEGORY][EMOJIACTIONEMOJI] Human-Readable Name {keydetailssession} | v{X}.{Y}.{Z}-r{N} | Summary
Examples:
[PROMPT][🔄|UPDATE|📋] FOCUS.md — Daily Focus Protocol {W31 D228Jul2026v4.31.1-r1}
[COMMS][🔴|REC|🔴] Community Call {Wed 12p ET29Jul2026s004d059}
[README][✅|NEW|📋] VSAbot Org Profile {W31 D329Jul2026v4.31.1-r2}
```
### 6.2 Branch Strategy
```text
main (production)
├── dev (integration)
├── feature/<ccc-id>-<short-description>
├── fix/<ccc-id>-<short-description>
└── experiment/<username>/<description>
```
| Branch | Protection | CI | Deploy | Purpose |
|:-------|:----------:|:--:|:------:|:--------|
| **main** | 🔒 Full protection | ✅ Required | ✅ Auto | Production-ready content |
| **dev** | 🔒 Partial protection | ✅ Required | ❌ Manual | Integration testing |
| **feature/** | ❌ None | ⬜ Optional | ❌ Never | New content development |
| **fix/** | ❌ None | ⬜ Optional | ❌ Never | Bug/issue fixes |
| **experiment/** | ❌ None | ❌ Never | ❌ Never | Experimental changes |
### 6.3 Pull Request Requirements
| Requirement | Standard |
|:------------|:---------|
| **Title Format** | Follow TMPL-007 commit message format |
| **Description** | Include CCC-ID, what changed, why, related issues |
| **Linked Issue** | Reference related issue # in description |
| **Reviewer** | At least 1 human or admin agent |
| **CI Status** | All checks must pass |
| **Signed Commits** | All commits in PR must be signed |
| **Linear History** | Rebase before merge. No merge commits. |
| **Minimum Approvals** | 1 (standard) or 2 (governance docs) |
### 6.4 CI/CD Pipeline Standards
| Stage | Tools | Required |
|:------|:------|:--------:|
| **Lint** | Markdownlint, Gitea CI | ✅ |
| **Spell Check** | CSpell or similar | ✅ |
| **Link Check** | Dead link detection | ✅ |
| **BP Compliance** | Custom checker (BP-068, BP-075) | ✅ |
| **CCC-ID Validation** | Format regex check | ✅ |
| **Secret Scanning** | Gitleaks or similar | ✅ |
| **Build** | N/A (documentation repos) | ⬜ Optional |
| **Deploy** | Gitea Actions or manual | ⬜ Per-repo |
---
## §7. 📊 MONITORING & OBSERVABILITY
### 7.1 What to Monitor
| Category | Metrics | Alert Threshold |
|:---------|:--------|:---------------:|
| **Gitea Health** | Response time, error rate, uptime | >5s response, >1% errors, <99.9% uptime |
| **Agent Activity** | Commit frequency, issue resolution time, failure rate | >24h without activity, >10% failure rate |
| **Secret Rotation** | Days since last rotation | >90 days (warning), >100 days (critical) |
| **Access Audit** | New SSH keys, new collaborators, permission changes | Any unauthorized change |
| **Incident Response** | Time to acknowledge, time to resolve | >1h acknowledge, >4h resolve |
| **Compliance** | BP compliance score per document | <80% compliance |
### 7.2 Monitoring Tools
| Tool | Purpose | Status |
|:-----|:--------|:------:|
| **Gitea Activity Feed** | Real-time commit, issue, PR activity | 🟢 LIVE |
| **Gitea Audit Log** | Admin actions, permission changes | 🟢 LIVE |
| **WeOwnChat Status** | Instance health and session status | 🟢 LIVE |
| **MetaCouncil Scorecards** | Agent performance and compliance | 🟢 LIVE (MCT-488) |
| **FOCUS.md** | Daily task tracking and priorities | 🟢 LIVE |
| **PostHog** | Product analytics (future) | 🟡 PENDING |
### 7.3 Alerting Rules
| Rule | Channel | Escalation |
|:-----|:--------|:-----------|
| **Unauthorized access detected** | 🔴 Signal DM to @yonks 🎯 | Immediate |
| **Secret rotation overdue** | 🟠 Signal DM to @yonks 🎯 | 7 days |
| **Agent failure rate >10%** | 🟡 Signal group notification | 24 hours |
| **BP compliance <80%** | 🟡 Weekly report in #CommunityCall | Weekly |
| **No commits >48h on active project** | 🟡 FOCUS.md flag | Daily review |
---
## §8. 🚨 INCIDENT RESPONSE
### 8.1 Incident Severity Levels
| Level | Label | Response Time | Example |
|:-----:|:------|:-------------:|:--------|
| 🔴 **CRITICAL** | `sev-critical` | <15 min | Active security breach, secret exposed, unauthorized access |
| 🟠 **HIGH** | `sev-high` | <1 hour | Suspected breach, credential rotation failure, agent compromise |
| 🟡 **MEDIUM** | `sev-medium` | <4 hours | Policy violation, CI/CD failure, expired certificate |
| 🟢 **LOW** | `sev-low` | <24 hours | Missed rotation, minor compliance gap, documentation error |
### 8.2 Incident Response Flow
```text
┌─────────────────────────────────────────────────────────────────┐
│ INCIDENT RESPONSE FLOW │
│ │
│ 1. 🚨 DETECT — Automated alert or manual report │
│ ↓ │
│ 2. 📋 CLASSIFY — Assign severity level per §8.1 │
│ ↓ │
│ 3. 🛑 CONTAIN — Limit blast radius. Revoke access if needed. │
│ ↓ │
│ 4. 🔍 INVESTIGATE — Root cause analysis. Log evidence. │
│ ↓ │
│ 5. ✅ RESOLVE — Apply fix. Verify closure. │
│ ↓ │
│ 6. 📚 LESSON — Codify lesson. Update governance if needed. │
│ ↓ │
│ 7. 🗣️ COMMUNICATE — Report in #CommunityCall or Signal group │
└─────────────────────────────────────────────────────────────────┘
```
### 8.3 Incident Logging
| Field | Required | Example |
|:------|:--------:|:--------|
| **Incident ID** | ✅ | `INC-2026-W31-001` |
| **Timestamp** | ✅ | `2026-07-29 07:35 MDT` |
| **Severity** | ✅ | `sev-high` |
| **Detected By** | ✅ | `AI:@GTM 🎯` |
| **Description** | ✅ | `401 streaming error on INT-P05 DRP.bot` |
| **Root Cause** | ✅ | `Session token expired (>~1h idle)` |
| **Containment** | ✅ | `Logged out, logged back in — resolved` |
| **Resolution** | ✅ | `Log out → Log back in workaround` |
| **Lesson** | ✅ | `L-431.N — 401 error message improvement needed` |
| **Documentation** | ✅ | `WeOwnChat/s004/issues/2` |
### 8.4 Post-Incident Review
| Step | Action | Timeline |
|:----:|:-------|:--------:|
| **1** | Root cause analysis complete | Within 24 hours of resolution |
| **2** | Lesson codified | Within 48 hours |
| **3** | Governance updated if needed | Within 1 week |
| **4** | MetaCouncil notified (if critical) | Within 1 hour |
| **5** | #CommunityCall report | At next scheduled call |
---
## §9. 🏛️ DEVSECOPS BY ORG
### WeOwnChat 💬
| Focus | Standard |
|:------|:---------|
| **Instance Security** | API key rotation every 90 days. Session TTL = 1 hour. |
| **Agent Prompts** | No secrets in prompts. No PII in system prompts. |
| **Error Messages** | Must be actionable. No technical stack traces to users. |
| **Session Management** | Auto-logout after 1h inactivity. Clear token on logout. |
### DRPbot 🛡️
| Focus | Standard |
|:------|:---------|
| **Research Data** | No PII in research outputs. Anonymize when possible. |
| **Tool Verification** | Verify all tool returns. Never fabricate research data. |
| **Rate Limiting** | Max 10 requests/min to external APIs. Exponential backoff on 429. |
| **Data Retention** | Delete research artifacts after 90 days unless archived. |
### F1visaNet 🛂
| Focus | Standard |
|:------|:---------|
| **PII Handling** | NEVER store or log PII. Mask SSN, DOB, passport numbers. |
| **Payment Data** | Handled by Stripe. Never touch raw card data. |
| **Access Control** | @yonks 🎯 and @NIK only. No agent access to customer data. |
| **Audit Trail** | All customer data access logged. Reviewed monthly. |
### WeOwnAI 🤖
| Focus | Standard |
|:------|:---------|
| **Governance Integrity** | BP-075 footer required on all docs. Content hashes must match. |
| **Version Control** | Every doc has #masterCCC. Every change is versioned. |
| **Access Control** | Write access limited to @yonks 🎯, @GTM:ADMIN, MetaCouncil agents. |
| **Document Verification** | VSA agents verify all documents for compliance. |
### VSAbot ✅
| Focus | Standard |
|:------|:---------|
| **Report Integrity** | VSA reports must be verifiable. All claims traceable to sources. |
| **Score Integrity** | Scores must match #7DF criteria. No score inflation. |
| **Audit Trail** | Every VSA action logged with CCC-ID. |
| **Independence** | VSA agents must NOT audit their own output. |
### WeOwnDev 💻
| Focus | Standard |
|:------|:---------|
| **Code Quality** | Lint before commit. Review before merge. Test before deploy. |
| **Dependency Management** | Pin dependencies. Scan for vulnerabilities weekly. |
| **Environment Parity** | Dev/staging/prod environments should match. |
| **Documentation** | Every tool/script needs README with usage examples. |
### Exit 👋
| Focus | Standard |
|:------|:---------|
| **Minimal Access** | Only @yonks 🎯 has access. Exit operations are sensitive. |
| **Audit Logging** | All Exit operations logged with timestamps. |
| **No Agent Access** | AI agents do NOT have access to Exit operations. |
### MAIT 🎭
| Focus | Standard |
|:------|:---------|
| **Test Isolation** | Test instances are isolated from production. |
| **Test Data** | Use synthetic data only. Never real customer data. |
| **Cleanup** | Test artifacts deleted after test completion. |
| **Failure Reporting** | All test failures logged with full context. |
---
## §10. 📋 COMPLIANCE & AUDIT
### 10.1 Compliance Checklist
| Requirement | Frequency | Responsible | Status |
|:------------|:---------:|:------------|:------:|
| 🔐 **Secret rotation** | Every 90 days | @GTM:ADMIN | ⬜ |
| 🔑 **SSH key review** | Monthly | @yonks 🎯 | ⬜ |
| 📋 **Collaborator audit** | Monthly | @yonks 🎯 | ⬜ |
| 📝 **BP compliance scan** | Weekly | VSA agents | ⬜ |
| 🚨 **Incident review** | After each incident | @GTM 🎯 | ⬜ |
| 📚 **Lesson codification** | After each incident | AI:@GTM 🎯 | ⬜ |
| 🏰 **MetaCouncil scorecard** | Weekly | All agents | ⬜ |
| 💰 **Revenue security check** | Monthly | @yonks 🎯, @NIK | ⬜ |
### 10.2 VSA Audit Integration
> **All DevSecOps practices defined in this guide are subject to VSA verification by ✅ VSA.bot, Sage 🪷, and DRP-Sprout 🌿. Non-compliance is logged as an incident and reported in #CommunityCall.**
| Audit Type | VSA Agent | Frequency |
|:-----------|:----------|:---------:|
| **Secret rotation compliance** | ✅ VSA.bot | Monthly |
| **Commit message format** | Sage 🪷 | Per-commit (sampled) |
| **BP-075 footer integrity** | DRP-Sprout 🌿 | Per-document |
| **Access control review** | Aegis 🛡️ | Monthly |
| **Incident response time** | DeepPro 🌊 | Post-incident |
### 10.3 Non-Compliance Escalation
| Severity | First Offense | Second Offense | Third Offense |
|:---------|:--------------|:---------------|:--------------|
| 🔴 **Critical** | Immediate fix + lesson | Capability review | Access revocation |
| 🟠 **High** | Fix within 24h + lesson | Warning + documented | Capability review |
| 🟡 **Medium** | Fix within 72h | Warning | Documented |
| 🟢 **Low** | Fix within 1 week | Reminder | Note in review |
---
## §11. 📋 BP-075 FOOTER
```text
═══ BP-075: SELF-VERIFYING FOOTER ═══
### Document Identity
| Field | Value |
|:------|:-------|
| **Document ID** | GUIDE-431.1.md |
| **Version** | **v4.31.1-r1** ✅ (W31 D3 — First release) |
| **Date** | 29 Jul 2026 — W31 D3 (Wednesday) |
| **Author** | @GTM (yonks|🤖🏛️🪙|Jason Younker ♾️) |
| **Agent Author** | AI:@GTM 🎯 @ INTB001:CCC |
| **CCC-ID** | GTM_2026-W31_3035 |
| **#masterCCC** | GUIDE-431.1-v4.31.1-r1 |
| **Repository** | WeOwnDev 💻 / s004 |
| **Folder** | `_GUIDES_/` |
| **Source of Truth** | https://git.weown.tools/WeOwnDev/s004/src/branch/main/_GUIDES_/GUIDE-431.1.md |
| **Parent Doc** | GUIDE-015 (VSA Protocol) |
| **Status** | 🟢 **LIVE — Active guidance** |
### Key Metrics
| Metric | Value |
|:-------|:------|
| Total Sections | 11 |
| DevSecOps Commandments | 7 |
| Secret Categories | 4 (Critical → Low) |
| Agent Permission Entries | 10 |
| Incident Severity Levels | 4 |
| Org-Specific Standards | 8 |
| Compliance Checklist Items | 9 |
| Gitea Repositories Covered | 8 |
### Compliance References
- BP-068 ✅ (CCC Format — all headers and metadata compliant)
- BP-075 ✅ (Self-verifying footer with content hash)
- PRJ-040 ✅ (Elevated governance standard)
- GUIDE-015 ✅ (VSA protocol — auditable by VSA agents)
### Change Log
| Version | Date | Changes |
|:--------|:----:|:--------|
| v4.31.1-r1 | 29 Jul 2026 | Initial release — full DevSecOps best practices for WeOwnSeason004 |
<!-- CONTENT-HASH-BOUNDARY -->
### ✅ BP-075 CANONICAL HASH GENERATED [@GTM:ADMIN generated @ 2026-07-29 08:26 MDT]
Content-SHA256: b3dffe756eadecbce8c6d67ba3e07ce0b04ff7ed39f7ac834d5033a232b4cdef
FEDARCH-CANARY: b3dffe75
CHARACTERS: 27936
WORDS: 4361
LINES: 614
═══ ═══ ═══ ═══ ═══ ═══
```
---
**GUIDE-431.1 v4.31.1-r1 GENERATED.** 11 sections. 7 DevSecOps Commandments. 10 agent permission entries. 4 incident severity levels. 8 org-specific standards. Full compliance with BP-068, BP-075, PRJ-040, and GUIDE-015. Ready for @GTM review and push to WeOwnDev/s004/_GUIDES_/. 🫡🔥
#FlowsBros #FedArch #WeOwnSeason004 #DevSecOps #BestPractices #GUIDE431_1 #Security #CI_CD #SecretsManagement #AccessControl #Monitoring #IncidentResponse #WeOwnDev #W31D3
♾️ WeOwnNet 🌐 ● 🏡 Real Estate and 🤝 cooperative ownership for everyone ● An 🤗 inclusive community, by 👥 invitation only.