Page 8 of 8~112 min topic

Webhook lab

Run acceptance tests and make the ship call

A second person can reproduce valid event → 202 + one queue message; replay same event_id → 202 no duplicate work from a clean checkout and name the owner for HOOK-SIG-OFF-16.

~14 min this pageProduction ship gate

1Try it yourself

Decision drill

Webhook lab

Webhooks push events — polling pulls. Verify signatures before acting.

Integration safety70%

1/3Nightly index job finished.

2Learn the idea

Read

Clean-room demo

From a fresh clone/directory, run the commands that prove valid event → 202 + one queue message; replay same event_id → 202 no duplicate work. A second person plays indexer worker waiting on provider batch.completed callbacks and follows your script without coaching. The demo includes limitations: what FastAPI receiver for batch-index completion events → durable queue still will not do.

Read

Evidence pack

Bundle: contract snippet, passing tests, metric snapshot for webhook_accept_total and duplicate_suppressed_total, security negative probe, rollback note, owner name. Reference HOOK-SIG-OFF-16 as the drill you rehearsed. If any item is missing, the ship gate fails even if the happy path dazzles.

Read

Implementation artifact

pytest tests/test_webhook_idempotency.py tests/test_webhook_sig.py

Read

Ownership and next review

For Webhook lab, name the human who gets paged, the review date for thresholds, and the condition that triggers reevaluation. Endpoint POST /webhooks/batch-index remains the production surface you operate for FastAPI receiver for batch-index completion events → durable queue — not a slide. Keep HOOK-SIG-OFF-16 in the handoff template so the next owner inherits the drill.

Read

Stage depth

After the peer demo, schedule the next threshold review date. File a short changelog that mentions HOOK-SIG-OFF-16 and the control that addresses it. Archive the evidence pack where your team already stores launch records. Resist rewriting everything “for real production” in one weekend — operate this slice until the metrics bore you, then widen. Final self-check: if telemetry vanished, would you still know to hold? If yes, you learned the operating posture this lane teaches.

Read

Field notes for `webhook-lab` / `mastery-ship`

Trim the demo script until every command is necessary. Record a peer signature line: name, date UTC, pass/fail. File known limitations as bullets, not apologies. Link the evidence pack from the README. Schedule the next game day on a calendar, even if it is solo. Archive the branch tag or release digest you actually shipped. In this chapter the product is FastAPI receiver for batch-index completion events → durable queue, the human stakeholder is indexer worker waiting on provider batch.completed callbacks, and the incident id you design against is HOOK-SIG-OFF-16. Re-state the oracle in your notes — valid event → 202 + one queue message; replay same event_id → 202 no duplicate work — and keep the invariant visible: verify HMAC signature + timestamp skew ≤ 5m; enqueue idempotent by event_id. Track webhook_accept_total and duplicate_suppressed_total as the scoreboard. Surface under change control: POST /webhooks/batch-index. If you only have forty minutes, finish the fixture for signature optional in staging config accidentally shipped to prod before polishing UI. Promotion language stays ternary: promote, hold, or roll back based on evidence, not hope.

Go deeper

Before you start

Why this matters

Draft a two-minute demo script that proves valid event → 202 + one queue message; replay same event_id → 202 no duplicate work from a clean directory. Include the failure rehearsal for signature optional in staging config accidentally shipped to prod and the rollback/owner line. If the script needs tribal knowledge, the lab is not shipped.

Check your understanding

Page assessment

Answer from memory. Completion is saved from this evidence, not from opening the next page.

1. Can a peer reproduce without coaching?
2. Does the pack include webhook_accept_total and duplicate_suppressed_total and rollback?
3. Is ownership for HOOK-SIG-OFF-16-class events explicit?

All responses are required.