Skip to content

Cockpit: full manual QA, security review, and non-Docker deployment docs #139

Description

@smota

Background & Problem Statement

Epic: #125

Cockpit needs complete validation and documentation for local and remote non-Docker use before broader rollout. Docker is intentionally second pass.

Proposed Solution

Create manual QA scripts, security review checklist, OAuth setup guide, reverse-proxy/TLS notes without Docker packaging, troubleshooting, and release readiness checklist.

Requirements

  • Manual QA: goal board, issue view, replay, markdown export, OAuth login/logout, guarded actions disabled/enabled.
  • Security checklist for OAuth, sessions, CSRF, headers, rate limits, audit logs.
  • Non-Docker deployment docs: Node service, process manager, TLS reverse proxy, env config.
  • Privacy checklist: no raw transcripts, prompts, tool inputs, secrets, or full logs.
  • Rollback/disable guide.

Acceptance criteria

  • Manual QA script exists and is runnable.
  • Security review checklist exists.
  • GitHub OAuth setup guide complete.
  • Non-Docker remote deployment guide complete.
  • Release checklist marks Docker as future pass.

Test plan

  • Docs review.
  • Manual QA execution evidence.
  • Security checklist walkthrough.

Workflow classification

Validation/docs issue. Requires human security/acceptance review before release.

Metadata

Metadata

Assignees

No one assigned

    Labels

    awaiting-releaseManaged by multi-agent-sdlc integration lifecycle automationdocumentationImprovements or additions to documentationdrafted-by:piIssue drafted by Piintegrated:developmentManaged by multi-agent-sdlc integration lifecycle automationproduct:cockpitAgentFlow Cockpit optional Goal Command Centerproduct:docsPublic documentation, onboarding, IA, examplesproduct:harnessHarness adapters, plugins, skills, settings, execution targetsqaExploratory QA sessions, QA planning/execution, or QA evidence workrelease:v1.0.0Assigned to AgentFlow SDLC v1 releasestatus:v1-readyImplemented on development and awaiting v1 release

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions