Use this checklist before sharing the Passport with students. Automated tests prove deterministic contracts; they do not prove current GitHub credentials, Cloudflare wiring, institutional systems, or novice comprehension. Never record credentials, private keys, broad logs, real research data, or unnecessary personal information.
1. Fresh-Computer First Contact#
Repeat on a clean Windows 11 account, macOS account, and Ubuntu user:
-
/getting-started/opens without GitHub authentication. - The learner identifies the correct OS tab and runs one command at a time.
- Missing Git/GitHub CLI recovery works without changing security policy.
-
gh auth login --web --git-protocol httpsuses the intended personal account. - The pinned extension installs and
gh passport startopens localhost. - No fork or public record exists before the public-content confirmation.
- The learner can explain what is public before consenting.
- The route uses responsibilities, not degree or job title.
- The dashboard gives one current mission and one next action.
- Closing browser/terminal and running
gh passport openfrom an unrelated folder resumes without reinstalling, cloning, orcd. - Deleting local state loses drafts/navigation only; trusted GitHub status reconstructs submitted completion.
2. Mission And Practice UX#
Use one genuine beginner and one experienced non-admin tester:
- Both can distinguish preview, local draft, submitted, needs work, passed, awaiting operational approval, and complete.
- Each page answers Outcome, Concept, Example, Trap, Action, Expected result, Check, Recovery, and Continue without maintainer translation.
- Failed critical answers explain the misconception, clear the old answers, and present the same skills in a different question and option order.
- Submit mission commits only generated submission and declared synthetic artifacts; unrelated staged or local files are untouched.
- Python fixtures run without PyPI/network and fail on the intended defect.
- Git practice uses the separate visible folder; the learner creates one non-interactive draft practice PR and understands it is not transport.
- GitHub rejects a wrong author, fork, branch, SHA, file, commit message, or non-draft practice PR.
- AI practice leaves canaries unchanged, shows the diff, and runs real tests.
- No mission requires free-form Markdown unless writing that document is the assessed competency.
Record each confusing step, expected behavior, observed behavior, severity, and resulting issue. Do not mark learner usability as measured without these pilots.
3. Signed GitHub/Cloudflare Transaction#
- Controller App is installed only on
passport-exerciseswith reviewed least privilege and Pull request subscription. - Dispatch App is installed only on
onboarding-controlwith Actions write. - Worker secrets exist only in Cloudflare; controller key exists only in the private control repository.
- GitHub webhook delivery shows valid signature and
202response. - One learner push starts one targeted private workflow for the exact PR/SHA.
- Wrong signature, installation, repository, base, branch, draft state, and malformed/oversized bodies start no workflow.
- Untrusted checkout contains no persisted token and runs with no network.
- Secret detection stops before parsing, execution, or optional AI use.
- Redelivery and controller retry are idempotent by exact SHA.
- Five synthetic learners remain within the projected Actions budget.
- Completion writes one private record and closes the transport PR unmerged.
- A completed learner can reopen the dashboard from that closed PR.
4. Windows SSH And VS Code#
Use an account with an unrelated SSH host already configured:
- Password login works before key setup.
- Dedicated key creation never overwrites an existing private key.
- Public-key installation sends only
.pub;IdentityFilenames the private key. - ACLs are accepted by Windows OpenSSH.
- Key-only login prints
key-okwithout an ETH password prompt. - Existing SSH hosts remain unchanged and
ssh -Gparses the new aliases. - Euler tunnel login succeeds before VS Code is opened.
- VS Code installs its server, opens the compute node, and shows
SLURM_JOB_ID; stopping the tunnel releases the allocation.
5. Euler#
Use harmless bounded jobs; do not allocate a GPU merely to validate prose:
-
my_share_infoconfirms the expected share. -
sbatch --test-onlyaccepts CPU, capped-array, RTX 4090, RTX 3090, andpro_6000profiles under current Euler identifiers. - One tiny CPU job is observed with
squeue, completes, and produces expectedsacctandsefffields. - The local verifier confirms account, user, state, exit code, CPU, memory, elapsed time, and expected output without publishing job ID or logs.
- Array fixture enforces
%Nand aggregate concurrency reasoning. - GPU smoke allocation remains optional; a busy queue cannot block training.
- Storage/checksum exercise uses only approved synthetic paths and content.
6. NAS And Blade#
- On ETH network/VPN, Windows and macOS resolve the approved supervisor Projects share.
- The learner creates only the approved username folder, writes/reads one nonce file, removes it, and publishes only a one-way digest.
-
C:,G:,H:, andT:are rejected as project locations. - Blade reports the intended host;
D:is temporary andP:is durable. - One harmless file is copied from
D:toP:, read back, and removed fromD:without publishing its path. - Installed Blade software/hardware claims are rechecked before release.
7. Cost And Operations#
- No payment method exists, or an Actions hard-stop budget is active.
- Larger runners are disabled and controller jobs retain strict timeouts.
- Recovery cron runs four times daily and unchanged assignments do not assess.
-
operations/needs-attention.mdcontains only exact asynchronous exceptions or operational decisions, not routine mission approvals. - Public help requests prohibit secrets, private identifiers, logs, and screenshots.
- Maintainer recovery never force-pushes or deletes public/private history.
Sign-Off#
Passport commit and version:
Static site URL:
Worker deployment version:
GitHub App IDs and repository scopes checked:
Platforms and tracks tested:
Automated report:
External tests passed:
Blocking failures/issues:
Release decision and approver:
Date:
Verified as a checklist: 2026-09-03. Re-run before student cutover. Owner: IDEAL Lab IT administrator.