ทดสอบ Internal Tool ที่ AI ช่วยสร้าง
เรียนรู้ “ทดสอบ Internal Tool ที่ AI ช่วยสร้าง” เพื่อสร้างเครื่องมือที่ตรวจสอบ ปลอดภัย และดูแลต่อได้
เป้าหมาย: พาเครื่องมือจากโจทย์ถึง pilot โดยมีหลักฐานและความรับผิดชอบ · ใช้เวลาประมาณ 16 นาที
Specify → Build → Verify → Operate
ความเร็วสร้างโค้ดต้องมาพร้อมหลักฐานว่าเครื่องมือแก้ปัญหาและปลอดภัย
Specify
นิยาม user, data, states, permission และ acceptance
Build
เปลี่ยนทีละส่วนใน sandbox พร้อม reviewable diff
Verify
run tests, security checks และ user task
Operate
release จำกัด monitor support และ rollback
Artifact ที่ต้องมี
test
สร้าง test ที่ทีมตรวจและทำซ้ำได้
เก็บเป็น artifact ไม่ใช่แค่ข้อความแชต
regression
สร้าง regression ที่ทีมตรวจและทำซ้ำได้
ใช้ unit, integration, permission, failure, accessibility และ end-to-end tests พร้อม fixtures ที่ปลอดภัย และดู RED ก่อน GREEN
fixture
สร้าง fixture ที่ทีมตรวจและทำซ้ำได้
ใช้ unit, integration, permission, failure, accessibility และ end-to-end tests พร้อม fixtures ที่ปลอดภัย และดู RED ก่อน GREEN
accessibility
สร้าง accessibility ที่ทีมตรวจและทำซ้ำได้
ใช้ unit, integration, permission, failure, accessibility และ end-to-end tests พร้อม fixtures ที่ปลอดภัย และดู RED ก่อน GREEN
ทางลัดที่กลายเป็นหนี้
ให้ AI แก้หลายไฟล์โดยไม่อ่าน diff
behavior และ dependency แฝง
small changes and review
test ด้วย production data
เสี่ยง PDPA และเปลี่ยนข้อมูลจริง
synthetic fixtures/sandbox
ไม่มี owner หลัง demo
ช่องโหว่และ bug ไม่มีคนแก้
operational ownership
วางแผน Prototype ถึง Pilot
ฟอร์มผ่าน happy path แต่กดซ้ำแล้วสร้างรายการสองครั้ง
กำหนด spec, schema, environment, review, tests, release และ rollback
ดูคำตอบตัวอย่าง
เขียน spec และ acceptance แยก non-goal ออกแบบ schema/source/state/permission ใช้ sandbox กับ synthetic data และ secret manager ให้ AI ทำ diff เล็กผ่าน code review รัน unit/integration/permission/failure/E2E เปิด pilot ด้วย feature flag monitor และมี rollback กับ owner
- spec/acceptance
- schema/state
- sandbox/secrets
- review
- tests
- pilot/rollback
บันทึกช่วยจำ
- ห้ามใช้ credential หรือข้อมูลจริงในบริการที่ไม่ได้รับอนุมัติ
- การ deploy ระบบสำคัญควรมีผู้เชี่ยวชาญตรวจ code และ security
สรุปบทเรียนนี้
- spec ก่อน code
- sandbox review test
- pilot monitor rollback