Federated identity, zero secrets
Identity is OIDC-federated — no client secrets anywhere in CI/CD, from Challenge 00 onward.
One validator, two places
The same validate code path runs on a laptop and in CI — no surprises between local and pipeline.
Drift runs nightly
Out-of-band portal changes surface automatically as GitHub issues — provable "no ClickOps".
Skills do the heavy lifting
Skills for Fabric ship medallion, Eventhouse, Power BI, and Activator work — wrapped in the PR loop so the frame still holds.
Agents accelerate, never bypass
GitHub Copilot and Fabric MCP speed authoring and review. Every change is still a reviewed PR applied by a service principal.
Each delivery feeds the next
Customer feedback becomes PRs that add or adapt challenges, so the blueprint compounds value over time.
Bug or doc rot in an existing challenge — a broken link in 03, an outdated screenshot in 07.
Sharpen an existing challenge — a new policy rule in 01, clearer success criteria in 04.
A customer-specific variant kept alongside the original — a regulated-insurance take on 06.
A brand-new challenge — e.g. data-mesh federated governance for multi-domain tenants.
Every PR that adds or changes challenge content keeps the contract: each challenge demonstrates ≥ 1 MCP server and ≥ 1 Skill, and policy / schema changes need CODEOWNERS review.
- →Empty tenant → fully governed, PR-driven control plane in under two days.
- →Auditable, replayable artifacts — no ClickOps, no long-lived secrets.
- →Customer-owned repo and repeatable templates to continue immediately.