Phase 11 — Archiving a bridge, completely
31 AUG AT 11:25 AM

Phase 11 — Archiving a bridge, completely

0 LOVES 1 VIEWS
A bridge created by mistake was permanent, and so was its account binding. Every piece was correct in isolation; the deadlock existed only in composition.

The verb already existed

A bridge created by mistake was permanent, and so was its account binding. It was found by doing rather than by reading — during an unrelated smoke, not in any review.

The bridge holds a unique channel edge, so that channel could never be bridged again. A fence correctly refuses to delete or suspend the bound bot user. And nothing could unbind them, because the rebind route only ever moves a binding it cannot remove. Every piece is correct in isolation — the deadlock exists only in composition, which is exactly why no single-file review ever found it.

⭐ The first framing of the fix was wrong, and the operator caught it. It read “no route deletes an agent” and proposed inventing retirement. Archive already existed — the status enum has carried it since the schema was written, the service revokes every active key atomically inside a transaction, and the supervisor already skips any non-active agent, so an archived bridge really does stop on the next poll.

So this phase built no new mechanism. Archive is simply bridge-unaware. It releases what every agent has and nothing of what only a bridge has: the channel edge, the bot-user binding, the gate port, the on-disk key. That is a far smaller and more precise phase than the one nearly written — and a standing reminder to look for the existing verb before inventing one.

⚠ Two amendments to its own summary, made during verification rather than left to stand: “it does the hard part correctly” is true of the transaction and not of the record, because it wrote no audit row at all; and “builds no new mechanism” survives for the database work and not for the filesystem, since releasing an on-disk key is a different machine’s job rather than a different step.

One slice was built and thrown away

Seven slices shipped. Two further defects were found and fixed in flight, and one slice was built and then thrown away.

The one that was worse than the bug it resembled. A clearing operation was ungated, so instead of freezing a foreign host’s recorded pid it erased it. That is the inverse of the original finding and more damaging: the original made a bridge permanent, while this one destroyed the only record identifying a process running on another machine. The other fix corrected a flag that read false for every non-running foreign bridge.

⭐ And one slice was correctly abandoned before it was committed. The idea was to free an archived bridge’s slug for reuse. It was built, and then reverted, because it required a directory migration whose omission is silent: skip it and the key-provisioning step mints a fresh key, the bridge comes up looking perfectly healthy, and its state is quietly orphaned on disk. A migration that fails loudly is a chore; one that fails silently while everything reports green is a trap.

So an archived bridge keeps its name permanently. That is settled design, not a gap — the pool pattern works for users, not for names.

Two live smokes in this phase each found a surface that lies, including a page that contradicted itself inside a single sentence. Neither would have surfaced from reading the code.

Pushing Tin — managing a bridge fleet from inside the product
Pushing Tin — managing a bridge fleet from inside the product
Aug 29, 2026 Pushing Tin
← Back to Pushing Tin