Files
tessera-ctl/.planning/phases/09-cert-manager-module/09-VALIDATION.md
T

4.0 KiB

phase, slug, status, nyquist_compliant, wave_0_complete, created
phase slug status nyquist_compliant wave_0_complete created
9 cert-manager-module draft false false 2026-07-01

Phase 9 — Validation Strategy

Per-phase validation contract for feedback sampling during execution.


Test Infrastructure

Property Value
Framework Vitest 3.x
Config file apps/api/vitest.config.ts / apps/web/vitest.config.ts
Quick run command pnpm --filter api test --run apps/api/src/modules/cert-manager
Full suite command pnpm --filter api test --run && pnpm --filter web test --run
Estimated runtime ~30 seconds

Sampling Rate

  • After every task commit: Run pnpm --filter api test --run apps/api/src/modules/cert-manager
  • After every plan wave: Run pnpm --filter api test --run && pnpm --filter web test --run
  • Before /gsd-verify-work: Full suite must be green
  • Max feedback latency: 30 seconds

Per-Task Verification Map

Task ID Plan Wave Requirement Threat Ref Secure Behavior Test Type Automated Command File Exists Status
09-01-01 01 0 CERT-01 — node-forge installs without native build unit pnpm --filter api test --run ❌ W0 ⬜ pending
09-01-02 01 1 CERT-01 — PEM/DER/PFX parsed → subject/issuer/validity/SANs/fingerprint returned unit pnpm --filter api test --run apps/api/src/modules/cert-manager ❌ W0 ⬜ pending
09-02-01 02 1 CERT-02 T-09-01 Split returns correct number of certs; each is valid PEM unit pnpm --filter api test --run apps/api/src/modules/cert-manager ❌ W0 ⬜ pending
09-03-01 03 2 CERT-03 T-09-01 Merge produces valid PEM chain; PFX password-protected unit pnpm --filter api test --run apps/api/src/modules/cert-manager ❌ W0 ⬜ pending
09-04-01 04 2 CERT-04 — Round-trip PEM→DER→PEM produces identical cert unit pnpm --filter api test --run apps/api/src/modules/cert-manager ❌ W0 ⬜ pending
09-05-01 05 2 CERT-05 T-09-02 Wrong PFX password returns 400, not 500 unit pnpm --filter api test --run apps/api/src/modules/cert-manager ❌ W0 ⬜ pending
09-06-01 06 3 CERT-06 — Module appears in registry with slug cert-manager integration pnpm --filter api test --run apps/api/src/modules/cert-manager ❌ W0 ⬜ pending

Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky


Wave 0 Requirements

  • apps/api/src/modules/cert-manager/__tests__/cert-processor.service.spec.ts — unit test stubs for CERT-01 through CERT-05
  • apps/api/src/modules/cert-manager/__tests__/cert-manager.controller.spec.ts — controller test stubs
  • node-forge package installed in apps/api

Wave 0 installs node-forge and creates RED test stubs before implementation begins.


Manual-Only Verifications

Behavior Requirement Why Manual Test Instructions
Module activatable via Marketplace UI CERT-06 Requires DB + running app + UI interaction Navigate to Marketplace, activate cert-manager, verify /modules/cert-manager route loads
File download (binary formats DER/PFX) CERT-04 Browser Blob-URL behavior requires visual check Upload PEM cert, convert to DER, verify download triggers correct binary file
Password prompt UX for PFX open CERT-05 Interactive UI flow Upload password-protected PFX, verify modal appears, enter correct password, verify parse success

Validation Sign-Off

  • All tasks have <automated> verify or Wave 0 dependencies
  • Sampling continuity: no 3 consecutive tasks without automated verify
  • Wave 0 covers all MISSING references
  • No watch-mode flags
  • Feedback latency < 30s
  • nyquist_compliant: true set in frontmatter

Approval: pending