Estate status
Read from each service's own health endpoint. Run controls are on Pipelines.
Server migration
Reading the last report…
- Open the shelf → — the live Audiobookshelf, behind the family Google gate.
- Justin's steps → — what is left to do on the box, in order, plus the Docker-access options. (The old instructions manual is archived — that build is done.)
- Runbook → — the full reference: every prompt, flag, config file, dash field and gotcha.
The AI commandments
The rules (tap to collapse)
- Read the docs first, every session. Before planning, before the first edit. Every incident we've had was knowable from a doc that existed and went unread. Say what you read and what was missing.
- One shape for every project's docs: a one-screen map, a todo (active work only), a done log (append-only — finished work moves whole, never summarised), a known-issues file (accepted defects, with the number that would change the verdict), how-to-operate, how-it-works, archive. A missing piece is a finding; create it before the task you came for.
- One fact, one home — for documents and for screens. Two places showing one number will disagree, and the duplicate is often the fresher one. Consolidating is a bug fix, not tidying; never leave a fallback to the old source.
- Measured, not asserted. A number is dated and re-checkable or it's labelled a guess. A measurement has an age; a stale one is not evidence — re-measure before contradicting someone's live report.
- Shipped ≠ verified. Run the change; don't reason about it. Verify with the right instrument (the pixels, not the attribute; the page, not the 200). Every report states what was not verified. No guessing to unblock.
- Guards are scripts, not advice. Deploys refuse a dirty tree; migrate before deploy; every deploy writes a log line; enforcement rolls out shadow-first (log would-deny, act on nothing) and is flipped only on measured zero false denials; exports are default-deny. Escape hatches are deliberate env vars, never an easy flag. Write the guard the day of the incident and name it after it.
- A person never sees a bare status code. Every refusal says what happened, what it needs, and how to get it. An outage is not a permission problem — mislabelling it sends people begging for access they already have.
- Secrets are named, never valued. A raw key never enters a chat. The shell fills the file; the assistant runs the push and never reads the file. Check for a trailing newline before you append — a glued line ships a corrupted secret.
- Every ask goes on the todo the moment it's said — never memory-only. Decisions go to the owner one at a time, with a count of how many remain.
- The big model conducts; cheap models build from tight briefs — exact paths, the repo's rules, verification steps, honest-reporting requirements, off-limits files. When an agent refuses on provenance, re-dispatch fresh with the settled design in its initial brief; never argue. Mid-flight messages narrow or stop, never expand.
- If agents are metered, read the budget before every dispatch and after every landing. An agent's cost is invisible until it lands. Size the agent first; commit and push before a big one. A limit is a pause with a scheduled resume, never a stop.
- Say which model you're on. If it's older than the newest available, say so in the first reply. A day on a superseded model is a day of wasted budget nobody flagged.
- Never revert a dirty file until you know who wrote it. A scheduled job, a pipeline, another agent — check the writer before
checkout. Nevergit stashin a shared tree. Directory deploys ship whatever is on disk: deploy from a committed-clean tree or a throwaway worktree of HEAD. - One canonical implementation of anything that decides. A second matcher, a second normaliser, a second copy of a rule will drift, and the drift ships as a confident wrong answer. A function that mints a persisted key is a migration to change, not an edit.
- Anything visible ships with its review link — the exact deep URL plus one line on what to look at. A change you have to hunt for isn't delivered.
- Keep the handoff current as you go. The last tenth of any budget is for an orderly shutdown, not more work: refresh the handoff, commit, push, schedule the resume. A pause without a resume is only half a rule.
Backups
The private estate-backups R2 bucket, written by
backup.yml — daily at 09:12 UTC, and on manual dispatch.
Each row is graded on its oldest store, so one stale database
cannot hide behind a fresh one.
Blob storage
Sizes are Cloudflare’s own rounded figures and the cost is storage only — R2 also bills operations, which this cannot see. Egress is free, which is why the estate is on R2 at all.
Deployed versions
What each Worker says it is running, from its own /api/health.
⚠️ This is the live build, not the deploy log — docs/deploys.log
(who deployed what, when, and the rollback trail) stays in the repo and is
deliberately not published here.
Shared index
Age = time since that source last pushed.
Book pipeline
Ages are from the last recorded run; the next run is not visible here.
Workers
Sites
Reachability only — these hosts send no CORS header, so a green dot means "answered a request," not "returned 200."
Recent worker events
A capped noticeboard, not a log — the full stream is
wrangler tail.