Skip to main content

Infrastructure, CI and security

Pipelines, cloud deployments and access control.

CI/CD and tests​

Unit test for the max stock drop calculation​

Context: in an earlier task you implemented an algorithm for calculating the maximum stock drop and provided your own examples. Now I'd like you to implement my own unit test for this feature and verify that it passes. Don't change the existing logic. Just add a unit test and report whether or not it passes.

Use case: max stock drop is calculated for bucket 1.

For example, given the following closing price history for a stock (see attached screenshot), two declines can be seen:

  1. From Jan 1, 2027 through Jan 5, 2027. Drop during the period: 230 / 250 - 1 = -8%
  2. From Jan 6, 2027 through Jan 9, 2027. Drop during the period: 198 / 251 - 1 = -21.11%

Of these two declines, the second one (-21.11%) must be taken as the Max Stock Drop.

Size: TaskStart to finish: 1 h 23 minAgent work: 59 minQuestions asked: 2Tokens: 15.6MCost, list price: $12.05Lines added / deleted: +62 −0Pull requests: 1Attachments: 1

featurecidataattachments

Fix flaky CI/CD tests​

Tests in CI/CD are almost always broken. Analyze why this happens and implement a way to stop it for good. The fix should not depend on whether the hosts are busy. Keep working on it quickly, open a PR to develop, and monitor the CI/CD tests until they pass consistently.

Size: TaskStart to finish: 13 h 42 minAgent work: 13 h 39 minQuestions asked: 0Tokens: 401.2MCost, list price: $267.73Lines added / deleted: +1,310 −374Pull requests: 1

fixcirobust

Review the GitHub Actions setup and propose improvements​

Review our GitHub Actions and propose improvements. It seems we run too much, too often, for no reason, which eats up resources without adding value.

Size: TaskStart to finish: 1 h 4 minAgent work: 59 minQuestions asked: 5Tokens: 27.3MCost, list price: $20.22Lines added / deleted: +227 −96Pull requests: 1

investigationci

Cloud and deployment​

Fix failing ECS deployment​

Fix the failing AppName CI/CD deploy. Apparently ECS cannot start a new service task. Resolve all issues, and babysit the CI/CD pipeline and ECS until it is fully deployed.

Size: TaskStart to finish: 1 h 33 minAgent work: 1 h 33 minQuestions asked: 0Tokens: 46.7MCost, list price: $38.57Lines added / deleted: +460 −5Pull requests: 1

fixinfraci

ECS zero-downtime deploys​

With DBOS guaranteeing a single execution of each cron job firing, can we change ECS to 100% min / 200% max so that there is zero downtime of the control plane during upgrades (the risk of an incompatible DB during switchover is accepted)? If so, let's do it.

As I understand it, there is still a gap today while the two containers pass leadership, and that creates downtime. Delete all that code. There should be zero gap: one container is fully up and running, the ALB switches over, and once it's ready the other one shuts down.

Size: TaskStart to finish: 1 h 8 minAgent work: 52 minQuestions asked: 7Tokens: 48.8MCost, list price: $34.60Lines added / deleted: +339 −147Pull requests: 1

featureinfra

Run the backend service on several containers at once​

Currently the ECS service is pinned to one task, because a registry lives in process memory.

Propose a solution and implement it.

Definition of done: multiple tasks run concurrently with all functionality available.

Size: TaskStart to finish: 3 h 38 minAgent work: 3 h 27 minQuestions asked: 4Tokens: 152.3MCost, list price: $215.95Lines added / deleted: +5,004 −945Pull requests: 1

featureinfrabackendrobust

Upgrade to the latest Python​

Fix the Python version problem: we want to run on the most recent version, so upgrade whatever needs upgrading.

(see attached screenshot)

Size: TaskStart to finish: 53 minAgent work: 53 minQuestions asked: 0Tokens: 20.0MCost, list price: $13.15Lines added / deleted: +97 −76Pull requests: 1Attachments: 1

fixinfraattachments

Security and access control​

Show organization names only to operators​

Remove the organization name columns from every list and details page for users who aren't operators. Only operators need to see them. Reuse code and controls across the whole system instead of copying and pasting.

Size: TaskStart to finish: 4 h 18 minAgent work: 4 h 15 minQuestions asked: 0Tokens: 100.2MCost, list price: $74.61Lines added / deleted: +2,595 −226Pull requests: 1

featuresecurityfrontendrobust

Hide the Settings page from users without permission​

The new Settings page appears in the navigation for everyone, and the permission is only fetched and checked when it is opened. Instead, fetch the permission at login, so that a user who lacks it never sees Settings in the navigation bar.

Size: TaskStart to finish: 38 minAgent work: 27 minQuestions asked: 3Tokens: 10.0MCost, list price: $7.67Lines added / deleted: +49 −26Pull requests: 1

fixsecurityfrontend

Secure Slack profiles against ID spoofing​

Slack security: in the current setup, what stops a user from adding somebody else's Slack ID to their profile, resulting in the other user receiving notifications unrelated to them, which could be exploited? Suggest a standard way (web research) to deal with this so that all users are secure.

Size: TaskStart to finish: 42 minAgent work: 19 minQuestions asked: 5Tokens: 13.2MCost, list price: $9.51Lines added / deleted: +197 −54Pull requests: 1

fixsecurityintegration