All projects
In Progress2026 – present· System & Architecture Design · Implementation

Tsubasa — Capstone Engineering Training System

A generative agent can finish an individual coding assignment, so an individual program shows little about the student. This project makes the team engineering cycle the deliverable. It runs as the PolyU COMP5585 cloud project for 2026 to 2027, with 60 students in 20 teams of three. Two teams form a twin unit, and there are ten twin units. Each team writes one bounded component in safe Rust against a frozen WIT world. The team then deploys the component on Azure and connects it to one trusted core, which the teaching team operates. The student component has no capabilities: no network, no file system, no database, no clock, no environment, and no secrets. A staff gateway supplies HTTPS, authentication, health checks, value translation, and resource metering. The cohort tests one claim. An independent team can implement the same frozen contract and deploy it under a different cloud service model. The same core then accepts it, and the business semantics do not change. The staff run the acceptance procedure, because a self-reported result is not evidence.

Highlights

  • The graded path is the work that an AI cannot do for the team: requirement decomposition, interface agreement, peer review, integration, and diagnosis of CI failures. A component that looks correct still fails without this cycle.
  • The design separates the trusted core from the untrusted component, and enforces the separation twice. The core owns identity, authorization, workflow state, persistence, audit, secrets, redaction, and every final decision. The component receives canonical pseudonymous values and returns a proposal. The core validates that proposal again before any effect.
  • The student component is a WebAssembly component without capabilities, and a staff gateway stands in front of it. Student code gets no network, file system, database, clock, environment, or secret access, and this is what makes independent deployment safe.
  • Two tracks make the comparison. Ten teams use raw Azure infrastructure with a virtual machine, Docker, and systemd. Ten teams use managed AKS. Both tracks implement the same four frozen worlds: parser normalizer, matcher allocator, supervisor rules, and KPI aggregator. The application contract does not change between the tracks.
  • The acceptance procedure is uniform, and the staff run it. A hermetic build produces an artifact with the exact world and no imports. The record binds the source, the artifact, the gateway, the image, and the live endpoint. The suites cover public examples, private examples, properties, and resources. The staff also inject faults and measure performance and the real cost on Azure.
  • The course permits AI assistance and does not try to detect it. A detector score is not evidence for a grade. The staff establish ownership from the repository history and from peer review. Each student also explains randomly selected code and evidence, and makes a small change that keeps the contract.
  • A course result and production authority stay separate. Acceptance shows that the submission met the frozen educational contract in the course environment. It gives no production deployment, no access to real data, and no business decision.
  • The cohort writes a book of ten chapters as the engineering record. Each twin unit writes one comparative chapter from its own source, deployments, and staff evidence. A contribution statement names the work of each person.

Tags

Engineering EducationWebAssembly ComponentsCapability SecurityAzureKubernetesHermetic CIRust