Walk the stale gates in launch-readiness.md #76

Closed
opened 2026-09-21 18:07:09 +01:00 by cruelacid · 1 comment
Owner

Part of #37.

Why

docs/launch-readiness.md says it of itself: "Gates A, B and C have not been
re-checked against the code since they were written, and are known to understate
what exists"
— requireAccountAdmin, /api/health, TRUSTED_PROXIES, seeded
tiers, metrics, GlitchTip and continuous deployment are all built and all left
unticked.

Leaving them unticked was the right call — "a gate is a claim somebody checked,
and ticking one because it is probably true is how the list stops meaning
anything."
But the product is now live and taking downloads, which makes an
unwalked readiness list a different kind of liability than it was when the list
was written.

What to do

Walk A, B and C and tick from observation. CLAUDE.md's rule governs:
assert through an API that can actually observe the thing. That document
already records what happens otherwise — a cleanup called complete on two
ListObjectsV2 calls against a versioned bucket, with versioning: Enabled
printed a few lines below in the same run.

The rows that matter most now that we are live

  • Gate B: status = 'suspended' is refused across the REST surface, not only on
    the WebSocket upgrade. It is the documented non-payment lever and it currently
    leaks — a suspended tenant keeps uploading and reading.
  • Gate C: a backup has been restored into a clean instance and a real client
    synced against it. Recorded as "Never restored". Under this repo's central
    principle an unrehearsed backup is a hypothesis.
  • Gate D: the control-plane invariant — stop the identity service entirely and a
    running customer still syncs. Structurally true, never asserted.
  • Gate E: docs/terms.md liability section still reads "Left for review.", and
    the quota clause Phase 8 depends on is still missing.

Per the document: an unticked box does not block other gates. They are jointly
the definition of ready, and we are already selling.

Part of #37. ## Why `docs/launch-readiness.md` says it of itself: *"Gates A, B and C have not been re-checked against the code since they were written, and are known to understate what exists"* — `requireAccountAdmin`, `/api/health`, `TRUSTED_PROXIES`, seeded tiers, metrics, GlitchTip and continuous deployment are all built and all left unticked. Leaving them unticked was the right call — *"a gate is a claim somebody checked, and ticking one because it is probably true is how the list stops meaning anything."* But the product is now **live and taking downloads**, which makes an unwalked readiness list a different kind of liability than it was when the list was written. ## What to do Walk A, B and C and tick from observation. `CLAUDE.md`'s rule governs: **assert through an API that can actually observe the thing.** That document already records what happens otherwise — a cleanup called complete on two `ListObjectsV2` calls against a versioned bucket, with `versioning: Enabled` printed a few lines below in the same run. ## The rows that matter most now that we are live - Gate B: `status = 'suspended'` is refused across the REST surface, not only on the WebSocket upgrade. It is the documented non-payment lever and it currently **leaks** — a suspended tenant keeps uploading and reading. - Gate C: **a backup has been restored** into a clean instance and a real client synced against it. Recorded as "Never restored". Under this repo's central principle an unrehearsed backup is a hypothesis. - Gate D: the control-plane invariant — stop the identity service entirely and a running customer still syncs. Structurally true, never asserted. - Gate E: `docs/terms.md` liability section still reads *"Left for review."*, and the quota clause Phase 8 depends on is still missing. Per the document: an unticked box does not block other gates. They are jointly the definition of ready, and we are already selling.
Author
Owner

Moved to the Vikunja board as NEC-52: https://projectron.nerchure.com/tasks/52

Moved to the Vikunja board as **NEC-52**: https://projectron.nerchure.com/tasks/52
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda#76
No description provided.