Three additions to agent-repos.md based on the post-A1-incident dogfood
batch (8 successes + 1 operator-induced "failure"):
1. Airouter Qwen3.6 section: pattern reconfirmed across M16 Wave A1/A2/B1
and M25 Waves A1-A5 + B1-B2. Time-to-success bands recorded for cost
calibration (1m30s for git rm; ~5 min for Pydantic regex; ~12 min for
class addition). Default --max-test-iterations 1 for cheap probes.
2. New section: Test Design for AI Agent Dogfood Pipelines. Triggered by
the M16 Wave B2 (MN-4 prompt cap) failure — a 14-minute airouter run
blamed on the agent that was actually an over-strict test asserting on
sanitised 422 body content. CP's RequestValidationError handler strips
Pydantic detail for security; tests asserting body content for that
path are structurally impossible. Rules: verify test passes against a
reference impl before pushing; status-code-only ceiling for validator-
driven 422s; model on previous successes not stricter variants; F70
retries don't recover structurally impossible tests.
3. New section: Dogfood Failure Path: Branch + Logs Lost. When all F70
retries exhaust, the agent's last attempt is not pushed to the agents
fork, the CP task record's logs field is empty, and the pod is gone.
Operator must reproduce locally — until F70 finalize-on-failure pushes
the failed branch.
BESTPRACTICES.md index updated to reflect the new sub-topics.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Eight practices for writing specs that serve as direct input to
automated test-generation agents, extracted from the M15 Mechanical
Process Nodes milestone review: module layout tables, integration
boundary marking, explicit library semantics, concrete interfaces over
"implementation detail", error messages as test data, pattern tables as
parametric matrices, scenario selection, and pre-dispatch testability
assessment.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Extends api-design.md beyond its security/operations focus with three
new dimensions:
- §0 API-First Design Process — OpenAPI 3.1 as single source of truth,
Spectral governance, dogfooding (UIs consume the public API, no
privileged backdoors), auth-required-by-default as a design stance.
- §7 Documentation and Developer Experience — Scalar/Mintlify,
RFC 9457 Problem Details error envelope, interactive playgrounds,
generated SDKs (Stainless, Speakeasy, Fern), RFC 9745 deprecation
signals and changelog UX.
- §8 Contract Testing and API Quality — schema validation in the
test suite, Pact CDC vs provider verification, Schemathesis
property-based fuzzing, oasdiff drift detection in CI, the API
test pyramid.
Intro, cross-refs in §3.1/§3.3/§4.1, and Sources block reorganised
by topic. Index entry in BESTPRACTICES.md updated. PLAN file included
for traceability.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Adds 3 new topic files (ai-parallel-agents, api-integration,
python-patterns) and extends 21 existing topic files with new gotchas
and patterns surfaced from memory across tracked projects. Index
updated accordingly.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Add 37 new entries and update 7 existing entries across 13 topic files.
Major contributions from agent-runtimes (K8s secrets, CI, Docker gotchas),
cluster-bootstrap (ArgoCD SSA, etcd tuning, DB migrations, Compose networking),
and cluster-apps/octopus-deploy (Helm vs raw manifests, ArgoCD source types).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Comprehensive guide covering task submission to the agent-runtimes
control plane, available harnesses, monitoring, multi-model workflows,
agent repo forks with workspace layout, and artifact extraction patterns.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Two new topic files from research:
- api-design.md: Transport security, OAuth2/JWT/mTLS auth, API patterns
(versioning, pagination, idempotency, rate limiting), input validation,
secrets handling, zero-trust service mesh patterns. Maps to OWASP API
Security Top 10.
- llm-code-security.md: Common vulnerabilities in LLM-generated code
(injection, hardcoded secrets, hallucinated packages, over-permissive
defaults, IaC risks, crypto mistakes). Includes per-technology review
checklists and cites 18 research sources (2024-2026).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Migrates 20 topic files from claude-foundations/best-practices/ to this
standalone repo. Adds BESTPRACTICES.md index, CLAUDE.md conventions, and
updated README.md. Container agents clone this repo to /best-practices.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>