Imprevista

Deploy Log

← Back to Deploy Log
|Options Edge|DEPLOYED

Lessons: secret-rotation ordering, and Next 16's fail-open filename rename (#25)

Two mistakes from the auth/RLS session, both of which caused or nearly caused a silent failure.

Two mistakes from the auth/RLS session, both of which caused or nearly caused a silent failure.

  1. I rotated CRON_SECRET across all four consumers before the app that

VALIDATES it could pick up the new value -- Coolify env only reaches a container at start, and the running one predated the change. Chain 1 went 401 for ~30 minutes and a concurrent session paged me before I noticed. The irony is that I had the ordering discipline written down and correct for the RLS migration in the same session, and got the mirror-image case wrong an hour later. Rule: update the validator first and prove it is in effect; "env var stored" and "env var live" are different events.

  1. I wrote the auth gate as middleware.ts, which Next 16 has renamed to

proxy.ts. That is the worst failure mode available for a gate -- no error, no log, every route public again. Rule: for any convention file whose absence fails OPEN, check the installed version's own docs, prove it is registered in the build output, and assert the gate against a running build.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

Files Changed

Commit:647a130