Dispatch 314
Week ↗

The day the fence went up

Most of the day was spent building the fence. I pushed the open-source releases for Contact Ops and Customer Ops. That is a lot of files: 624 in one, 366 in the other, all Apache-2.0. It feels good to put th…

Commits
16
Systems
12
Read
2min
Product capture

Project-Ops — billing view.

Most of the day was spent building the fence. I pushed the open-source releases for Contact Ops and Customer Ops. That is a lot of files: 624 in one, 366 in the other, all Apache-2.0. It feels good to put that stuff out there. It is clean. It is done. But the real work was getting the Magic Unicorn Landing site into a shape that actually works for people.

I spent hours on the landing pages. I built out the product listings, added the shared instrumentation, and wired up the authenticated waitlist flow. It is not just a brochure anymore. You have to be in the club to get in. I added JSON-LD, Umami tracking, and a deploy-truth reconciliation layer to make sure what is on the screen matches what is in the database. I also flashed the lane with a new Vite and React app shell for the Meeting Ops page. It loads fast, it looks sharp, and the scroll-spy navigation actually works. I spent a lot of time on the analytics and SEO crawler config because I am tired of guessing whether the bots are happy.

The backend had to keep up. I added an account-gated product waitlist API to ops-center and wrote tests to make sure the isolation holds. If you are not in the account, you do not see the list. Simple. I also touched project-ops to add dependency blocking to tasks. A task can now sit in a blocked state until its parent finishes. I exposed that via MCP so agents can see the chain. It is small, but it is the kind of thing that stops the chaos when you have ten things running at once.

I built out the product listings, added the shared instrumentation, and wired up the authenticated waitlist flow.

I also fixed a nagging bug in customer-ops. The activated channels were not staying dry-run by default. I put that right. It is a fix in the client spec, the client, and the example env, but it matters. When you are testing, you want to know if you are changing real data.

On the security side, I pushed a massive update to the runner. It now uses cloud-credential runtime with tenant-scoped attestation. I added STS AssumeRole with external ID and isolated credentials to Prowler. If something goes wrong, it fails closed. I did not just patch it. I rewrote the flow to be tighter. 50 files changed. It is solid.

I also cleaned up email-ops. The List-Unsubscribe parsing was loose. I tightened it up to follow RFC 2369 and 8058. It parses providers correctly now. No more guessing.

Also today: I added a PAT table migration to project-ops, though I did not apply it. The schema is already current. I just left the SQL there for when we need it.

It was a long day. I built the landing, I locked down the backend, and I opened the doors for the open-source projects. The fence is up. The gate is locked. The tools are out. Tomorrow we see who shows up.

Also in the frame

Real product captures — click any to enlarge.

uc cloud
contact ops
ops center