<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Plans on ZTD — Zero Trust Dev</title><link>https://ztd-98a2ef.gitlab.io/plans/</link><description>Recent content in Plans on ZTD — Zero Trust Dev</description><generator>Hugo</generator><language>en</language><atom:link href="https://ztd-98a2ef.gitlab.io/plans/index.xml" rel="self" type="application/rss+xml"/><item><title>vz — macOS backend (lima)</title><link>https://ztd-98a2ef.gitlab.io/plans/vz-macos-backend/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://ztd-98a2ef.gitlab.io/plans/vz-macos-backend/</guid><description>&lt;h2 id="plan--the-vz-macos-local-backend-lima"&gt;Plan — the &lt;code&gt;vz&lt;/code&gt; macOS local backend (lima)&lt;a class="anchor" href="#plan--the-vz-macos-local-backend-lima"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;This plan delivers &lt;strong&gt;&lt;code&gt;vz&lt;/code&gt;&lt;/strong&gt;, ZTD&amp;rsquo;s fourth backend and its first for macOS
operators: a disposable, isolated Linux guest running locally on
Apple&amp;rsquo;s Virtualization.framework, driven by &lt;a href="https://lima-vm.io"&gt;&lt;code&gt;lima&lt;/code&gt;&lt;/a&gt;. It is
the headline item of Phase 3 (&lt;a href="https://ztd-98a2ef.gitlab.io/explanation/roadmap/"&gt;roadmap&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;It is delivered as a sequence of &lt;strong&gt;phases&lt;/strong&gt;, each executed as one
Opus-orchestrated &lt;strong&gt;red/green/verify&lt;/strong&gt; cycle — see the &lt;code&gt;red-green-verify&lt;/code&gt; skill.
Do not attempt the whole backend in one pass; lock one behavioral contract per
phase.&lt;/p&gt;</description></item><item><title>Standalone CLI (install + run anywhere)</title><link>https://ztd-98a2ef.gitlab.io/plans/standalone-cli/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://ztd-98a2ef.gitlab.io/plans/standalone-cli/</guid><description>&lt;h2 id="plan--the-standalone-installable-ztd-cli"&gt;Plan — the standalone, installable &lt;code&gt;ztd&lt;/code&gt; CLI&lt;a class="anchor" href="#plan--the-standalone-installable-ztd-cli"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Turn &lt;code&gt;ztd&lt;/code&gt; from &amp;ldquo;a binary that must run inside a checkout of this repo&amp;rdquo; into a
&lt;strong&gt;self-contained CLI&lt;/strong&gt; you install (Homebrew on macOS, a downloaded binary on
Linux) and run from &lt;em&gt;any&lt;/em&gt; project directory: &lt;code&gt;brew install ztd&lt;/code&gt; → &lt;code&gt;cd my-project&lt;/code&gt;
→ &lt;code&gt;ztd init&lt;/code&gt; → &lt;code&gt;ztd up&lt;/code&gt;. The binary carries everything it needs; the only config a
user ever touches is a single &lt;strong&gt;&lt;code&gt;ztd.toml&lt;/code&gt;&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title>Backend cohesion &amp; parity</title><link>https://ztd-98a2ef.gitlab.io/plans/backend-cohesion/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://ztd-98a2ef.gitlab.io/plans/backend-cohesion/</guid><description>&lt;h2 id="plan--backend-cohesion--parity"&gt;Plan — backend cohesion &amp;amp; parity&lt;a class="anchor" href="#plan--backend-cohesion--parity"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Keep the backends (&lt;code&gt;kvm&lt;/code&gt;, &lt;code&gt;proxmox&lt;/code&gt;, &lt;code&gt;ec2&lt;/code&gt;, &lt;code&gt;vz&lt;/code&gt;) sharing one pipeline, branching
&lt;strong&gt;only where the mechanism genuinely differs&lt;/strong&gt; — so functionality and testing stay
in parity as the set grows. Delivered as red/green/verify phases with an
independent review, like the &lt;a href="https://ztd-98a2ef.gitlab.io/plans/vz-macos-backend/"&gt;vz backend&lt;/a&gt;
and &lt;a href="https://ztd-98a2ef.gitlab.io/plans/standalone-cli/"&gt;standalone CLI&lt;/a&gt; plans.&lt;/p&gt;
&lt;h3 id="the-decision-centralize-at-the-contract-not-at-terraform"&gt;The decision: centralize at the contract, NOT at Terraform&lt;a class="anchor" href="#the-decision-centralize-at-the-contract-not-at-terraform"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;A tempting way to &amp;ldquo;unify&amp;rdquo; would be to route &lt;code&gt;vz&lt;/code&gt; through Terraform too. &lt;strong&gt;Rejected&lt;/strong&gt;,
because it &lt;em&gt;adds&lt;/em&gt; branching rather than removing it:&lt;/p&gt;</description></item></channel></rss>