Infrastructure, CI and security
Pipelines, cloud deployments and access control.
CI/CD and tests
Unit test for the max stock drop calculation
Context: in an earlier task you implemented an algorithm for calculating the maximum stock drop and provided your own examples. Now I'd like you to implement my own unit test for this feature and verify that it passes. Don't change the existing logic. Just add a unit test and report whether or not it passes.
Use case: max stock drop is calculated for bucket 1.
For example, given the following closing price history for a stock (see attached screenshot), two declines can be seen:
- From Jan 1, 2027 through Jan 5, 2027. Drop during the period: 230 / 250 - 1 = -8%
- From Jan 6, 2027 through Jan 9, 2027. Drop during the period: 198 / 251 - 1 = -21.11%
Of these two declines, the second one (-21.11%) must be taken as the Max Stock Drop.
Size: TaskStart to finish: 1 h 23 minAgent work: 59 minQuestions asked: 2Tokens: 15.6MCost, list price: $12.05Lines added / deleted: +62 −0Pull requests: 1
Fix flaky CI/CD tests
Tests in CI/CD are almost always broken. Analyze why this happens and implement a way to stop it for good. The fix should not depend on whether the hosts are busy. Keep working on it quickly, open a PR to develop, and monitor the CI/CD tests until they pass consistently.
Size: TaskStart to finish: 13 h 42 minAgent work: 13 h 39 minQuestions asked: 0Tokens: 401.2MCost, list price: $267.73Lines added / deleted: +1,310 −374Pull requests: 1
Review the GitHub Actions setup and propose improvements
Review our GitHub Actions and propose improvements. It seems we run too much, too often, for no reason, which eats up resources without adding value.
Size: TaskStart to finish: 1 h 4 minAgent work: 59 minQuestions asked: 5Tokens: 27.3MCost, list price: $20.22Lines added / deleted: +227 −96Pull requests: 1
Cloud and deployment
Fix failing ECS deployment
Fix the failing AppName CI/CD deploy. Apparently ECS cannot start a new service task. Resolve all issues, and babysit the CI/CD pipeline and ECS until it is fully deployed.
Size: TaskStart to finish: 1 h 33 minAgent work: 1 h 33 minQuestions asked: 0Tokens: 46.7MCost, list price: $38.57Lines added / deleted: +460 −5Pull requests: 1
ECS zero-downtime deploys
With DBOS guaranteeing a single execution of each cron job firing, can we change ECS to 100% min / 200% max so that there is zero downtime of the control plane during upgrades (the risk of an incompatible DB during switchover is accepted)? If so, let's do it.
As I understand it, there is still a gap today while the two containers pass leadership, and that creates downtime. Delete all that code. There should be zero gap: one container is fully up and running, the ALB switches over, and once it's ready the other one shuts down.
Size: TaskStart to finish: 1 h 8 minAgent work: 52 minQuestions asked: 7Tokens: 48.8MCost, list price: $34.60Lines added / deleted: +339 −147Pull requests: 1
Run the backend service on several containers at once
Currently the ECS service is pinned to one task, because a registry lives in process memory.
Propose a solution and implement it.
Definition of done: multiple tasks run concurrently with all functionality available.
Size: TaskStart to finish: 3 h 38 minAgent work: 3 h 27 minQuestions asked: 4Tokens: 152.3MCost, list price: $215.95Lines added / deleted: +5,004 −945Pull requests: 1
Upgrade to the latest Python
Fix the Python version problem: we want to run on the most recent version, so upgrade whatever needs upgrading.
(see attached screenshot)
Size: TaskStart to finish: 53 minAgent work: 53 minQuestions asked: 0Tokens: 20.0MCost, list price: $13.15Lines added / deleted: +97 −76Pull requests: 1
Security and access control
Show organization names only to operators
Remove the organization name columns from every list and details page for users who aren't operators. Only operators need to see them. Reuse code and controls across the whole system instead of copying and pasting.
Size: TaskStart to finish: 4 h 18 minAgent work: 4 h 15 minQuestions asked: 0Tokens: 100.2MCost, list price: $74.61Lines added / deleted: +2,595 −226Pull requests: 1
Hide the Settings page from users without permission
The new Settings page appears in the navigation for everyone, and the permission is only fetched and checked when it is opened. Instead, fetch the permission at login, so that a user who lacks it never sees Settings in the navigation bar.
Size: TaskStart to finish: 38 minAgent work: 27 minQuestions asked: 3Tokens: 10.0MCost, list price: $7.67Lines added / deleted: +49 −26Pull requests: 1
Secure Slack profiles against ID spoofing
Slack security: in the current setup, what stops a user from adding somebody else's Slack ID to their profile, resulting in the other user receiving notifications unrelated to them, which could be exploited? Suggest a standard way (web research) to deal with this so that all users are secure.
Size: TaskStart to finish: 42 minAgent work: 19 minQuestions asked: 5Tokens: 13.2MCost, list price: $9.51Lines added / deleted: +197 −54Pull requests: 1