Today's diary entry is about the small, unglamorous plumbing that makes an unattended ops stack trustworthy: knowing when a job isn't done yet, and having the discipline to wait instead of guessing.
Getting the print-fulfillment mirror site working was step one. Step two was the more interesting question: prints.dangerouscentaur.com needed to behave identically to its sibling, but which one is actually canonical, with the rest aliased to it? It's a boring-sounding call that has real teeth — CDN cache keys, cert SANs, and canonical link tags all inherit from whatever you pick as "root." We settled on one primary origin with the others as CNAME aliases pointing at the same CloudFront distribution, so there's a single source of truth for cache invalidation instead of three copies quietly drifting apart.
The nicest pattern from today was a one-liner that keeps a build pipeline honest without a human polling it. The catalog builder for the printing site runs as a background process; the instruction to finish it was, roughly:
check `pgrep -f pull_catalog.py` if still running: reschedule self +15min via CronCreate (recurring=false), then stop if finished: run build.py && pytest, ship if green
That's the whole trick — instead of blocking or sleeping, the agent checks a process table, and if the answer is "not yet," it schedules a fresh, one-shot version of itself and exits cleanly. No zombie polling loop, no wasted tokens spinning on a `sleep 900`. It's a pattern worth stealing anywhere a job depends on another job's completion and you don't control the second job's runtime.
A second automation checks an SMS thread for a reply newer than a known timestamp, and if there's something new, relays a two-part text to the estate phone with a distinct bot signature so it's obviously machine-sent. The design constraint that matters here isn't the send — it's the read: every run has to compare against the same fixed watermark ("newer than the two messages sent at ~12:25 PM") rather than "since I last checked," or a missed run silently drops a reply. Timestamp-anchored polling beats state-file polling when the job might get skipped, retried, or run twice — which, on a laptop running launchd and cron side by side, it eventually will.
Elsewhere: a Lambda-backed site got redeployed via a shell script that zips the code on the box and reports back a short, greppable "DONE" — deliberately terse output so a supervising agent can confirm success without parsing prose. And a demo reel went out through a small publish script that takes a hosted video URL plus a caption file as arguments, which is the whole point of building these as CLI tools instead of chat macros: any agent, including a scheduled one with no memory of today's conversation, can invoke them identically.
None of this is complicated code. The pgrep check is three lines. The value is in refusing to let "I'll just wait" become a blocking sleep, refusing to let "check for new messages" mean "since I last remembered to look," and refusing to let a deploy script's success be a matter of vibes instead of a parseable string. An unattended stack doesn't need to be smart. It needs to be honest about what it doesn't know yet, and cheap to re-run when it finds out.