FOLLOW-THROUGH — PR Gambit-Inc/gambit#396 extends this closed issue: a sweep of all ~323 backend routes for the same pattern, adding limiters to 33 more across 19 files, plus an `import_max_upload…
CORRECTION to my comment above — this was already in flight when I posted it, and the "flag first, delete after" decision it records is not what shipped.
**Lucas opened PR Gambit-Inc/gambit#407…
ADDENDUM — the remaining credential work is also already in progress, by Lucas.
Evidence, since Postgres does not timestamp role creation: gambit_app and gambit_migrate
hold OIDs 4168635 and…
MEASURED ON PROD (2026-09-04, read-only via railway ssh runrecon-back) — this issue is
substantially smaller than scoped. The groundwork already exists; the app just isn't using it.
DECIDED — the premise changed twice, so restating it.
- The GitHub Free constraint is gone: the org is on the Team plan. Required status checks
are available today.
mainsimply has no…
Delivered by #587. The pipeline exists and has promoted prod: deploy.yml builds a SHA-tagged API image to GHCR on push to main, promote-prod.yml detects a pending migration, backs up (integrity-che…
UNBLOCKED — #420 is delivered (#587), so the migrate step this was waiting on now exists.
Current measurement (2e28456): main.py still issues 147 conn.execute(text(...)) statements plus…
DECIDED — full split (all DDL out of the application). Two findings that change the scope.
FINDING 1 — runtime DDL is NOT confined to main.py. Measured on 2e28456, nine other modules issue…
DECIDED — access control, not relocation. Object storage is deferred with the rest of the scale-out work (#423/#424/#426/#427): file LOCALITY only matters once a second instance runs, and we are…
DECIDED — scope reduced deliberately, with the residual risk recorded.
We are NOT building the off-vendor backup layers yet. Railway PITR plus the rotated pre-migration dumps are the plan for…
Worth tracing the root cause one level further back: the backup volume that filled the disk today is a direct consequence of PR #406 (merged tonight), which made promote-prod/promote-web auto-fire…
Follow-up to my earlier comment on this issue (the one specifying workflow_dispatch as the ONLY trigger for staging->production, never a side effect of a merge): PR #406, merged after this issue…
GitHub PR #251 (per-condition outlier band — played conditions no longer dropped by the NM-derived band, so they stop falling back to the NM price) merged to main 2026-09-04 (74175a8), deploying…
GitHub PR #251 (per-condition outlier band — played conditions no longer dropped by the NM-derived band, so they stop falling back to the NM price) merged to main 2026-09-04 (74175a8), deploying…