What this proves
Six problems that only show up when you build the whole thing
Each was found here, reproduced, and fixed with a test that failed
first. Every card names the file, so the claim can be checked.
Concurrency
A race that only exists above one worker.
Choosing a provider per request meant writing to a module-level
singleton and restoring it outside a finally. The fix
was not a lock — the provider is injected once at construction, so
there is no mutable state to contend for.
Structurally impossible, rather than defended against.
src/agents/explaining/__init__.py
Determinism
The same input scored two different numbers.
Keyword extraction sliced [:20] from a set,
and Python randomises string hashing per process. Terms now rank by
frequency, tied alphabetically.
0.40 or 0.45 for one CV and job, across five processes.
src/agents/agent3_scorer.py
Idempotency
Seeding that cannot overwrite your data.
The corpus became writable through POST /jobs, and on an
ephemeral filesystem the obvious implementation reseeds every deploy.
seed_jobs writes nothing into a populated table.
A seed, not a source of truth. Redeploy is a no-op.
src/storage/database.py
Trust boundary
Rate limits charged to the right client.
Per-IP limits read the socket address, which behind a proxy is the
proxy's — so every visitor shares one bucket.
X-Forwarded-For is client-supplied, so it is believed
only when TRUST_PROXY_HEADERS says something is in front.
Off by default. Trusting it with nothing in front is the worse mistake.
src/api.py · client_address()
Honest metrics
Target leakage found in my own model.
A perfect ROC-AUC. Removing the feature I suspected changed nothing.
The label turned out to be a threshold on a column already excluded
from training, and two ordinary columns rebuild it anyway.
No accuracy figure is published, and a contract test asserts none appears.
models/production/model_metadata.json
Silent failure
A degraded run must not look like a healthy one.
A rule-based explanation and a model-written one are both fluent
paragraphs, so a dead key produces a broken demo that reads as a
working one.
Three signals: explanation_source, scoring_mode, and the provider named at /health.
src/agents/explaining/protocol.py · src/api.py