Skip to content

Latest commit

 

History

History
86 lines (70 loc) · 5.62 KB

File metadata and controls

86 lines (70 loc) · 5.62 KB

Knowledge Transfer and Handover Plan

1. Handover Objectives & Philosophy

The objective of this knowledge transfer plan is to enable any engineer or IT maintainer at Pine Brook Technologies (pinebrooktechnologies.com) to independently develop, operate, diagnose, deploy, and secure the ISSA Foundation platform without requiring assistance from previous authors.


2. Structured Knowledge Transfer Curriculum

The handover is structured into seven focused 60-minute technical sessions:

Session # Domain / Topic Curriculum & Live Demonstrations Hands-On Verification Exercise
Session 1 Product & Domain Walkthrough Public user journeys, program structures, stories CMS, careers pipeline, and staff role tiers. Incoming engineer explains the public-to-panel workflow and data boundaries.
Session 2 Codebase & Architecture Next.js 16 App Router, Server Components, Server Actions, domain services (lib/*), middleware, and session guard. Trace a contact form submission from UI button to database row.
Session 3 Database, Migrations & Files Neon PostgreSQL serverless pooling, 18-table schema, JSONB columns, BYTEA resume storage, and migration runner. Create and execute a mock schema migration script against a test database branch.
Session 4 Deployment & CI/CD Vercel Git-driven deployments, environment variable scoping, build pipeline, and Vercel Instant Rollback. Execute a staging deployment and perform a live rollback.
Session 5 Operations & Troubleshooting Monitoring dashboards, server_logs, audit_events, error triage, and runbooks (DB drop, auth loops, upload bugs). Simulate and resolve a database cold-start / connection error.
Session 6 Security & Credential Vault Secret management, zero-trust password vault, HMAC resume tokens, secret rotation, and JML offboarding. Execute a non-production rotation of RESUME_SIGNING_SECRET.
Session 7 Disaster Recovery & Acceptance Point-In-Time Recovery (PITR) in Neon, logical pg_dump backups, and emergency break-glass procedure. Perform a full backup restore drill into an isolated staging database.

3. Practical Acceptance Exercises (Unprompted Test)

To achieve formal sign-off, the incoming Pine Brook engineer must execute the following 10 tasks independently:

  1. Local Environment Bootstrap:
    • Clone the repository from GitHub.
    • Configure .env.local and launch the local development server on port 5000 using Bun.
  2. Execute Automated Quality Gates:
    • Run bun run lint, bun run test, and bun run build successfully.
  3. Database Migration Execution:
    • Apply a new chronological SQL migration to a test database using node scripts/migrate.js.
  4. Deploy & Rollback Staging Release:
    • Trigger a preview deployment on Vercel and verify edge delivery.
    • Execute an instant rollback to the previous deployment SHA.
  5. Staff Access & RBAC Administration:
    • Authenticate with an eligible @pinebrooktechnologies.com email via OTP.
    • Log in as an Administrator, locate the pending account, and promote it from NO_ACCESS to CONTENT.
  6. Publish & Restore CMS Content:
    • Create a draft blog post, submit it for review, publish it, and verify visibility on /stories.
    • Edit the published post and use the Revision History module to restore the prior version.
  7. Process Career Application & Download Resume:
    • Submit a test job application with a valid PDF resume on /careers.
    • Log into /panel/careers and download the candidate's resume using the expiring HMAC link.
  8. Audit Trail Inspection:
    • Open /panel → Audit tab and verify that all actions performed in Steps 5–7 generated structured audit_events.
  9. Disaster Recovery Drill:
    • Restore a PostgreSQL logical dump into an isolated Neon branch and verify table counts.
  10. Emergency Secret Rotation Drill:
    • Rotate NEON_AUTH_COOKIE_SECRET in staging and verify that active sessions are gracefully invalidated.

4. Formal Handover Sign-Off Record

Role / Responsibility Assigned Signatory Organization Handover Evidence Pack Acceptance Status
Business Owner Pine Brook Executive Lead Pine Brook Technologies Ownership register & SLA review Pending Final Signature
Outgoing Lead Engineer Lead System Architect Pine Brook Technologies Technical documentation & repo transfer Approved & Transferred
Incoming Lead Engineer Incoming Technical Lead Pine Brook Technologies Completed 10 Practical Exercises Verified & Accepted
Security & Data Owner Information Security Officer Pine Brook Technologies Secret vault access & credential handover Verified & Accepted
DevOps & Operations Lead Infrastructure Lead Pine Brook Technologies Vercel, Neon, Cloudflare console access Verified & Accepted

5. 30-Day Transition Roadmap

gantt
    title 30-Day Knowledge Transfer & Transition Timeline
    dateFormat  YYYY-MM-DD
    section Phase 1: Onboarding
    Sessions 1-4 (Arch, Code, DB, Deploy) :2026-09-01, 5d
    Console & Vault Provisioning          :2026-09-01, 5d
    section Phase 2: Shadowing
    Shadow Outgoing Lead on Deployments   :2026-09-06, 7d
    Sessions 5-7 (Ops, Security, DR)      :2026-09-06, 5d
    section Phase 3: Reverse Shadowing
    Incoming Lead Executes Releases       :2026-09-13, 10d
    Complete 10 Acceptance Exercises      :2026-09-18, 5d
    section Phase 4: Final Sign-Off
    Sign Formal Acceptance & Revoke Outgoing Access :2026-09-25, 5d
Loading