DataTalksClub / DataTalksClub/website
Epic: Meet security, privacy, accessibility, and operational requirements
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
PM disposition — current authority audit (2026-08-31)
OPEN / P0 / EPIC / NO-GO.
I audited this epic, every listed child and current dependency record, the current issue graph, _docs/PROCESS.md, specifications 01, 06, 07, 08, 09, and 10, and the relevant open-decision entries against remote main at face8e4808d65afbf0374d1ced7a88079950d663. The repository/worktree, tests, browser, provider/AWS state, protected or production data, credentials, deployment, and release state were not changed or accessed.
This is a cross-domain coordination epic, not an engineer-sized implementation. All parent completion gates remain unchecked. A closed decision, source-only contract, synthetic fixture, green component run, or accepted child does not by itself authorize production data, provider, AWS, deployment, sender, cutover, or activation work.
Normative authority
_docs/PROCESS.md01 — Platform architectureand the application-boundary specification06 — Studio and admin API07 — Security, privacy, accessibility, and operations08 — AWS development and Terraform09 — Migration, rollout, and roadmap10 — Verification strategyopen-decisions.md, especially sections 9, 12, 15, 17, 18, 19, and 20
Accepted inputs — useful, but not epic completion
- #1 and #31 are closed platform/service foundations. #75 is the closed deterministic local harness. #86 and #87 are closed decision-free Studio/admin-API authorization and service-principal foundations.
- #20 is closed and selects the shared Cognito path while removing a dedicated break-glass credential workflow. #23 is closed and supplies the approved privacy-policy direction. #26 is closed and supplies only the initial service/recovery target values. #28 is closed and supplies the high-risk approval/reauthentication policy.
- #141 is closed and is the accepted non-identity security baseline consumed by #63. It covers the verified general web/data boundaries and explicit identity/high-risk handoffs; it is not a substitute for residual security traceability, OIDC/MFA, privacy, accessibility, or operations evidence.
- These closures are policy/foundation inputs only. They do not prove that the resulting target, control, accessibility, privacy, backup, restore, or production behavior is currently measured or ready.
Current child ledger
| Child | Current disposition | Exact ownership and dependency boundary |
|---|---|---|
| #20 | CLOSED decision | Shared Cognito/break-glass direction; policy input only. |
| #23 | CLOSED decision | Privacy contact, erasure direction, default periods, minors treatment, and certificate exception; policy input only. |
| #26 | CLOSED decision | Initial production targets plus development RPO/RTO; no measurement, alert, runbook, restore, or activation evidence. |
| #28 | CLOSED decision | High-risk confirmation/reauthentication policy; implementation and production identity remain downstream. |
| #61 | OPEN / decision-blocked | Staff OIDC/session producer. Owner decisions are still required for admission/linking, session/offboarding/outage policy, and per-environment OIDC binding. External DataTalksClub/aws-infra#24 MFA evidence remains a separately owned HUMAN production gate. No dedicated break-glass implementation is permitted. |
| #63 | OPEN / groomed / dependency-blocked | Residual cross-domain security/authorization traceability and a no-new-legacy-auth-use guard. It consumes #141 and waits for accepted current-main handoffs from #61, #32, #33, #52, #64, and #66; it must not redesign those controls. It feeds #76 and remains no-go for #73/#74. |
| #64 | OPEN / groomed / HUMAN + decision | Privacy coordination epic. #23 is no longer a blocker, but legal/controller, notice/consent, retention/hold, proof/appeal, and processor/tombstone decisions remain HUMAN. Runtime children are #255–#260; #254 is the source-only authority/register slice. #281/#282/#283/#285 are non-activating interfaces, and #284 is an external recovery/email prerequisite rather than an eighth privacy runtime child. |
| #65 | OPEN / groomed / HUMAN | Accepted automated accessibility foundation exists at 58932b4. The current bounded source producer/registry reconciliation and genuine named screen-reader/manual matrix are still required. #76 consumes its producer; human remains until the manual gate passes. Closed #115/#118 are not current blockers. |
| #66 | OPEN / groomed / HUMAN + decision | Operations/recovery coordination epic. #26 is a policy input, not an operational pass. Delivery children are #264–#269; #284 remains outside this child set. Named owners/authority, backup/restore, live activation, AWS, alarms, and authorized drill evidence remain unresolved. |
The child list is intentionally not expanded to absorb #141, #32/#33, #52, #76/#77, #73/#74, #78/#94, #49, or domain adapters. Those issues retain their own ownership and lifecycle; they are dependencies or downstream consumers, not silent #8 children.
Authoritative delivery DAG
The following is the current coordination graph. “Accepted” means the full engineer → independent tester → PM → focused commit → local no-ff merge/push → on-call lifecycle with a current immutable identity, not merely a frozen candidate or issue comment.
closed #1/#31/#75/#86/#87/#141 foundations
closed policy inputs #20/#23/#26/#28
|
+--> #61 staff OIDC/session (after its three owner decisions)
| +--> #32/#33 production management consumers
| +--> #63 residual security traceability
|
+--> #64 privacy coordination
| #254 source-only register
| -> #281 non-activating kernel input
| -> #255 runtime kernel
| -> #283 retention input -> #257 runtime retention
| -> #285 export/correction input -> #256 runtime export/correction
| #264 backup receipt -> #284 recovery/email input -> recovery-specific #49
| #255 + #257 + #264/#284/#49 -> #258 tombstone/restore-fence contract
| #255 + #256 + #257 + #258 -> #282 propagation input -> #259
| accepted #255–#259 + domain adapters + #32/#33 -> #260 privacy surfaces
|
+--> #65 accessibility producer -> #76
|
+--> #66 operations coordination
#264/#265 source contracts -> #266 target/query catalog
#264 + #258 + recovery-specific #49 + content validator + #102
-> #267 live restore/startup activation controller
accepted #264/#265 + final #266 + #78/#94 + HUMAN authority
-> #268 AWS backups/alarms/dashboard
accepted #264/#266/#267 + applied/read-back #268
-> #269 authorized restore/rollback/fault/expiry drill
#63 + #64 + #65 + #66 producer contracts
+ #72 classification + #75 harness + all other accepted domain/infra producers
-> #76 verification-producer graph
-> #77 deterministic report/go-no-go consumer
-> #73 separately authorized development rehearsal
-> #74 separately authorized production cutover/observation/retirement
The #66 source order has no reverse #266 -> #268 -> #269 -> #266 cycle: #266 freezes query semantics from accepted source interfaces, while #268/#269 later prove live execution. #258 consumes recovery receipts and must not depend on the later live controller #267. #64 domain adapters, #49 delivery/Relay state, #102 immutable application recovery, #78/#94 infrastructure, and #32/#33 management identity remain separately owned.
Source-only versus runtime and activation boundaries
The following source-side phases may define schemas, inventories, deterministic validators, disabled seams, synthetic fixtures, and redacted evidence once their own prerequisites and normal lifecycle gates are satisfied:
- #63’s residual inventory/no-new-legacy-auth-use guard;
- #64’s #254 register slice and non-activating #281/#282/#283/#284/#285 interfaces;
- #65’s versioned accessibility producer and registry reconciliation; and
- #66’s #264/#265/#266 source contracts and catalog.
None of these phases authorizes protected-data inspection, legal-copy approval, real screen-reader substitution, provider contact, email/Relay send, AWS/Terraform mutation, deployment, restore, production data, or activation. A Refs source delivery remains open for its HUMAN/live gate.
Runtime or live authority remains with the owning lanes: #61’s OIDC/session implementation after decisions; #64’s #255–#260 runtime services after accepted interfaces and domain adapters; #66’s #267 activation fence, #268 infrastructure resources, and #269 authorized drill; and #73/#74’s separately authorized rehearsal/cutover. #63’s final matrix consumes accepted controls; it does not invent them. #65’s manual gate requires a real named assistive-technology procedure; browser automation or Blink AX output cannot satisfy it.
Epic completion gates
- #63’s residual threat/authorization/export traceability consumes the accepted #141 baseline and every remaining identity, privacy, management, and operations handoff exactly once, with owner, test, redacted artifact, freshness, risk, expiry, and release disposition.
- Security and redaction controls pass their owning automated and manual gates without exposing credentials, tokens, PII, provider payloads, protected-source values, or production data.
- #64’s privacy-request, export/correction, retention, erasure/propagation, tombstone, and domain-adapter evidence is accepted; unresolved legal/HUMAN rows remain explicit no-go inputs.
- #65’s current producer and independent keyboard/screen-reader/manual accessibility evidence pass for all graph-selected critical flows; pending HUMAN rows cannot be promoted by automation.
- #66’s target/query, observability, backup-verification, restore/startup, rollback, fault/expiry, alarm, and recovery evidence meets the accepted #26 targets and explicit HUMAN authority requirements.
- #76’s producer graph and #77’s deterministic report are accepted at current immutable identities, with every required source/HUMAN/provider/production row classified and no unexplained skip, stale evidence, or invalid reuse.
- Separately authorized #73 development rehearsal and #74 production cutover/observation/retirement gates pass; no child/source contract or synthetic evidence substitutes for those environment and owner decisions.
Release disposition
#8 remains OPEN / P0 / NO-GO. The next safe work is to advance independently owned source contracts only when their recorded prerequisites and base are current and green, while preserving the separate tester, PM, merge, push, on-call, HUMAN, provider, AWS, and production boundaries. No acceptance checkbox is being inferred or checked by this reconciliation.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with _docs/PROCESS.md and specifications 01, 06, 07, 08, 09, and 10, then review open-decisions.md and the child issues #61, #63, #64, #65, and #66. This epic is complete only when its security, privacy, accessibility, operations, verification, and authorization gates are accepted with the required owner, test, redacted evidence, and HUMAN/provider approvals.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, terraform
- Domain
- accessibility, cloud, devops, infrastructure, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100