From c0fd81b6532191fc58b99a7e8f29790e69256074 Mon Sep 17 00:00:00 2001 From: devswha Date: Mon, 3 Aug 2026 11:52:07 +0900 Subject: [PATCH 1/5] ops: record the free-tier deepseek flip and post-flip production smoke --- .../free-tier-deepseek-flip-20260803.md | 49 +++++++++++++++++++ 1 file changed, 49 insertions(+) create mode 100644 docs/operations/free-tier-deepseek-flip-20260803.md diff --git a/docs/operations/free-tier-deepseek-flip-20260803.md b/docs/operations/free-tier-deepseek-flip-20260803.md new file mode 100644 index 0000000..a74b3e0 --- /dev/null +++ b/docs/operations/free-tier-deepseek-flip-20260803.md @@ -0,0 +1,49 @@ +# Free tier flipped to deepseek-v4-flash (2026-08-03) + +## Why + +The free tier was hard down: the production Gemini key returns HTTP 429 +"monthly spending cap exceeded" (recorded in +[`dep-prod-disabled-20260803.md`](dep-prod-disabled-20260803.md)). The +deepseek-0731 remeasurement chain +([`serving-engine-deepseek-0731-correction-20260803.md`](serving-engine-deepseek-0731-correction-20260803.md)) +established gate parity at ~1/8 the cost, and the owner approved the +free-tier switch on 2026-08-03. + +## Validation before the flip + +- 22 fixtures × `--repeat 3` at `reasoning_effort: low`: 17 pass / 2 warn / + 3 error on worst-of-three status; every MEDIAN score clears the floors + (lowest median MPS 80). The three errors are single below-70 MPS samples on + `en-email-01` / `ko-blog-01` / `ko-news-01` — per-run variance, not a + register failure. In production such a sample is refused by the MPS floor + gate (customer sees a retryable error), never delivered silently. +- Code: PR #677 (reviewed) — rewrite reasoning cut scoped to free+deepseek, + scorer cut extended to deepseek, streaming extraBody passthrough. Shipped + to main via release PR #678. + +## The flip + +Vercel env (preview 2026-08-03, then production after #678): +`PATINA_FREE_PROVIDER=deepseek`, `PATINA_FREE_MODEL=deepseek-v4-flash`, +`PATINA_FREE_API_KEY=`. Explicit redeploy after the env change. + +## Post-flip production smoke (patina.vibetip.help) + +| probe | result | +|---|---| +| free ko rewrite | 200, 34.2s end-to-end, MPS 100, fidelity 100 | +| number safety | `14:30`, `23,000` preserved | +| scaffold leakage | none (`[SELF_AUDIT]` absent) | +| pro unknown license | 403 `license not entitled` (Polar gate intact) | +| launch config | still the disabled shape | + +## Standing notes + +- The Pro tier still runs gemini-3.6-flash on `PATINA_PRO_API_KEY`; if that + key shares the capped Gemini project, Pro serving is still blocked until + the owner clears the spend cap — unverifiable without a live license. +- Rollback: restore the three `PATINA_FREE_*` values to the gemini set and + redeploy (values retained in the secret manager history). +- Watch item: DeepSeek announced (date TBA) 2x peak-hour output pricing; + reassess cost if activated. From 6e84e1803787222b3bf9c31793735f972aa87d41 Mon Sep 17 00:00:00 2001 From: devswha Date: Mon, 3 Aug 2026 13:36:34 +0900 Subject: [PATCH 2/5] =?UTF-8?q?ops:=20Gate=20B=20ledger=20=E2=80=94=20Gemi?= =?UTF-8?q?ni=20spend=20cap=20cleared,=20one=20owner=20action=20remains?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- docs/operations/gate-b-readiness-20260803.md | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/docs/operations/gate-b-readiness-20260803.md b/docs/operations/gate-b-readiness-20260803.md index bbb14e4..b31cf4e 100644 --- a/docs/operations/gate-b-readiness-20260803.md +++ b/docs/operations/gate-b-readiness-20260803.md @@ -19,10 +19,12 @@ ## Blocking — owner actions, in order -1. **Gemini spend cap (incident).** The production runner's Gemini key returns - HTTP 429 "monthly spending cap exceeded"; the free tier fails terminally and - healthy-service evidence cannot be recorded. Raise/clear the cap at - AI Studio → spend, then the agent re-runs the free/pro smokes. +1. ~~**Gemini spend cap (incident).**~~ **RESOLVED 2026-08-03**: the owner + cleared the spend cap; a direct gemini-3.6-flash probe answers again. The + free tier no longer depends on it (flipped to deepseek, + [`free-tier-deepseek-flip-20260803.md`](free-tier-deepseek-flip-20260803.md)); + the Pro serving path (gemini) is unblocked but can only be exercised + end-to-end once a license exists (item 2). 2. **`PATINA_SYNTHETIC_PRO_LICENSE`.** The pro-monitor synthetic probe needs a real license; the prior verification license was shredded. Issue one via the bounded forever-100% verification code (a zero-amount checkout), hand only From a276663682d22a4fca5990f58a3a7404d01d0804 Mon Sep 17 00:00:00 2001 From: devswha Date: Wed, 5 Aug 2026 04:32:51 +0900 Subject: [PATCH 3/5] ops: provision the synthetic Pro license and verify the production Pro path Bounded one-shot forever-100% code (deleted after use), zero-amount confirm, license injected to the secret manager without exposure, and the first post-cap-clear Pro rewrite observed live: 200 in 10.2s, MPS/fidelity 100, numbers preserved, no leakage. --- docs/operations/synthetic-license-20260804.md | 42 +++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 docs/operations/synthetic-license-20260804.md diff --git a/docs/operations/synthetic-license-20260804.md b/docs/operations/synthetic-license-20260804.md new file mode 100644 index 0000000..8afac39 --- /dev/null +++ b/docs/operations/synthetic-license-20260804.md @@ -0,0 +1,42 @@ +# Synthetic Pro license provisioned; production Pro path verified (2026-08-04) + +> Closes item 2 of [`gate-b-readiness-20260803.md`](gate-b-readiness-20260803.md). +> No raw key, discount code, or token value appears in this record. + +## Provisioning (agent-run via the Polar API, owner-supplied OAT) + +1. The standing verification code ("patina test", 100% forever, 1/3 redeemed) + is **per-customer limited**: both the owner email and a plus-alias drew + `DiscountRedemptionLimitReached` — Polar normalizes the customer identity. +2. A fresh bounded code was created instead: 100%, `duration: forever`, + `max_redemptions: 1`, expiry +3 days, scoped to the `patina pro` product. +3. Zero-amount checkout created and confirmed card-free + (`total: 0`, `is_payment_required: false`, status `confirmed`) for the + dedicated monitor identity `devswha+monitor@gmail.com`. +4. License `****-2FCE6A` (benefit `4c9c3f17…`, status `granted`) fetched via + the org API and piped directly into the Vercel Production env as + `PATINA_SYNTHETIC_PRO_LICENSE` — never echoed, never written to the repo. +5. The one-shot discount was **deleted** after use (204); the OAT was removed + from the local env and its dashboard revocation recommended to the owner + (it transited an operator chat). + +## Production Pro-path verification (patina.vibetip.help, post-redeploy) + +| probe | result | +|---|---| +| tier=pro with the new license | **HTTP 200**, start→done, 10.2s | +| MPS / fidelity | 100 / 100 | +| number safety | `14:30`, `23,000` preserved | +| license leakage in response | none | + +This is the first end-to-end Pro observation since the Gemini spend cap was +cleared: the Polar validate → entitle → gemini-3.6-flash rewrite chain works +on the deployed production environment with a currently-issued license. + +## Follow-ups + +- The pro-monitor cron (`*/15`) can now exercise the real path; the next + Gate-B step is an ACKed healthy `OBS-ALERT-v1` receipt with `realPath: true`. +- The monitor seat consumes the standard 100-rewrites/month allowance; at the + cron cadence the synthetic probe budget must stay within it (monitor design + already accounts for this). From fbf4f17b7e5b4609b163bde4d8cc8a4812dcb4ed Mon Sep 17 00:00:00 2001 From: devswha Date: Wed, 5 Aug 2026 04:36:53 +0900 Subject: [PATCH 4/5] =?UTF-8?q?ops:=20record=20PAY=5FOPEN=20=E2=80=94=20pr?= =?UTF-8?q?oduction=20checkout=20enabled=20on=20the=20Polar=20route?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Owner-authorized live open: env flip to the bound Polar tuple, enabled launch config verified byte-exact, CTA renders and opens a live Polar checkout session, both serving tiers healthy. The pending first OBS receipt is recorded as an explicit deviation with a watch item. --- docs/operations/live-open-20260804.md | 42 +++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 docs/operations/live-open-20260804.md diff --git a/docs/operations/live-open-20260804.md b/docs/operations/live-open-20260804.md new file mode 100644 index 0000000..5ceba78 --- /dev/null +++ b/docs/operations/live-open-20260804.md @@ -0,0 +1,42 @@ +# PAY_OPEN — checkout enabled on production (2026-08-04) + +## Authorization + +The owner (holding every gate role: Maintainer, Payment Runtime Owner, +Deployment Owner, Release Authority) authorized opening payment in the +operator session on 2026-08-04 ("ㅇㅇ 켜라"), after reviewing the state +summarized in [`gate-b-readiness-20260803.md`](gate-b-readiness-20260803.md): +Polar approval/payout/KYC cleared, secret manager complete, the binding +integration shipped, the disabled production deploy verified, rollback drills +measured (2026-07-23), and the production Pro path verified with a +currently-issued license +([`synthetic-license-20260804.md`](synthetic-license-20260804.md)). + +**Deviation, recorded honestly**: the formal `OBS-ALERT-v1` ACKed-receipt +cycle had not yet produced its first receipt at open time — the synthetic +license that enables the monitor's real path was provisioned the same day. +The owner opened with the monitor newly armed rather than waiting a cycle. +Watch item: confirm the first healthy receipt. + +## The flip + +Production env: `PATINA_PRO_CHECKOUT_ENABLED=true`, +`PATINA_PRO_CHECKOUT_URL=https://buy.polar.sh/polar_cl_qKqt…` (replacing the +retired Lemon Squeezy URL), `PATINA_PRO_GATE_EVIDENCE_ID= +PAY-B-20260729-POLAR-ea8385dc-4c9c3f17`; explicit redeploy. + +## Post-open verification (2026-08-04) + +| probe | result | +|---|---| +| `/launch-config.js` | `{channel: production, enabled: true, checkoutOrigin: https://buy.polar.sh, checkoutPath: /polar_cl_qKqt…, evidence: PAY-B-20260729-POLAR-ea8385dc-4c9c3f17}` — exactly the bound tuple | +| Checkout link | 200 | +| Playground CTA | "Upgrade to Pro — $9.99/mo" renders; clicking opens a live Polar checkout session (`polar.sh/checkout/polar_c_…`) in a new tab | +| Free tier | 200, healthy (deepseek) | +| Pro tier | verified same day with a real license: 200, 10.2s, MPS/fidelity 100 | + +## Rollback + +Sale-close drill procedure in [`rollback-drills.md`](rollback-drills.md): +flip `PATINA_PRO_CHECKOUT_ENABLED=false`, redeploy, verify the six-field +disabled shape — measured well under the 10-minute bound. From 86b03242f94598c2208efefc46a8c7c0db01fc6f Mon Sep 17 00:00:00 2001 From: devswha Date: Wed, 5 Aug 2026 04:40:41 +0900 Subject: [PATCH 5/5] =?UTF-8?q?fix(playground):=20the=20BYOK=20key=20does?= =?UTF-8?q?=20not=20stay=20in=20the=20browser=20=E2=80=94=20say=20what=20a?= =?UTF-8?q?ctually=20happens?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The key is held only in the input field and relayed through the server per request without being stored or logged; 'Key stays in your browser' claimed more than the architecture delivers. --- playground/index.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/playground/index.html b/playground/index.html index c3aa385..96328d7 100644 --- a/playground/index.html +++ b/playground/index.html @@ -190,7 +190,7 @@

API

  • Bring your own provider key
  • Up to 20,000 characters
  • -
  • Key stays in your browser
  • +
  • Sent only with your requests
  • Never stored or logged