Client engagement · 2026

Hardening a Developer Platform for Beta

A contracted engagement taking a multi-tier developer platform — a hub service, a daemon running on each enrolled device, and a browser dashboard streaming live terminals — from working prototype to something that survives a real beta: no silent crashes, no untraceable errors, and a deployment path anyone on the team can run.

Client, product name, source code, and commercial terms are covered by an NDA and are not published here. What follows is the shape of the work and the measurable bar it had to clear — available in detail on request, where the agreement allows.

Role

Contract engineer

Surface

Hub · agents · dashboard

Focus

Reliability & beta readiness

Basis

Fixed-scope SOW

System

Three tiers, one wire protocol

Expand any tier to see what it owns and how it talks to the others. Implementation detail and client identifiers are withheld under NDA.

Responsibilities

  • Authenticates users and issues device certificates during pairing.
  • Routes frames between dashboards and agents, scoped per account.
  • Persists devices, sessions, allowed roots, and audit events.
  • Proxies TCP traffic to device-local ports and exposes health and readiness endpoints.

Interfaces

  • Inbound: dashboard WebSocket and REST API, both auth-enforced and rate-limited.
  • Inbound: agent WebSocket authenticated by a signed device certificate.
  • Outbound: pooled connections to the relational database via a shared client.

Scope

Six workstreams, one written scope

The engagement was defined up front as discrete, testable workstreams rather than open-ended hours.

Core hardening

01

A single shared database client across the service instead of one per frame, a fixed startup race between the socket layer and the filesystem channel, agent reconnect with unbounded exponential backoff and hello re-send, no unhandled promise rejections on send, and clean crash recovery with reporting.

File workflow

02

Beyond directory listing: inline file viewing and editing with save-back over the wire protocol, drag-and-drop upload and download inside defined size limits, a stated strategy for large files, and permission and error states users can actually act on.

Session creation UX

03

A create-session dialog covering every runtime driver, with working directory, environment overrides, and extra-argument input, inline validation, sane defaults, and end-to-end launch coverage for each session kind.

Security baseline

04

Per-user relay filtering so a dashboard only receives frames for its own devices, enforced WebSocket auth in production, server-side rate limits on auth, pairing, and filesystem channels, secure environment defaults, fail-fast on missing or weak production secrets, and a dependency audit pass.

Debuggability & logging

05

Structured logs across dashboard, hub, and agent with correlation IDs tying a request to its frames, user, device, and session; surfaced protocol-parse failures instead of silent frame drops; health and readiness endpoints; and a runbook for the top failure scenarios.

Deployment pack

06

Reproducible dev and beta environment scripts, verified container images and compose config behind a TLS reverse proxy, dynamic proxy configuration as tunnels open and close, seeded test data, and one-command bootstrap.

Diagnosis

Four bugs that looked like four different problems

Each one presented as a vague timeout or hang. Each one had a specific, findable root cause.

Filesystem requests timing out

Home-directory paths resolved against the process working directory on one OS, and the agent's allowed-roots set was never persisted, so the dashboard kept requesting a path that could not exist. Fixed by expanding the path correctly agent-side and persisting allowed roots, merged with live registry data in API responses.

Silently dropped protocol frames

Schema validation errors in the multiplexer were caught into a no-op handler, so malformed or unrouted frames vanished without a trace. Parse failures and missing channel handlers now surface as real, traceable errors.

Unhandled rejections on disconnect

Sends issued while the socket was down threw into nothing, leaving the caller to time out. Every send now goes through a guarded path that fails loudly and fast.

Connection pool exhaustion

Each inbound event frame constructed and discarded its own database client. Replaced with a shared singleton reused across handlers.

Results

What changed, measured

Same four fixes, shown as a before-and-after. The numbers are chosen to prove the outcome without exposing anything the NDA covers.

Filesystem timeouts

after

Before

First filesystem request after a reconnect intermittently timed out, so a freshly connected dashboard kept requesting a path that could not exist.

After

The first request succeeds in 100 of 100 consecutive reconnect cycles — a hard, repeatable bar rather than a flaky symptom.

Dropped protocol frames

after

Before

Schema-validation errors were caught into a no-op handler, so malformed or unrouted frames vanished without a trace.

After

Parse failures and missing channel handlers now surface as real errors. Zero silent frame drops in the soak window.

Unhandled rejections

after

Before

Sends issued while the socket was down threw into nothing, leaving the caller to time out with no signal.

After

Every send goes through a guarded path that fails loudly and fast — zero unhandled rejections over a 24-hour soak.

Connection pool exhaustion

after

Before

Each inbound event frame constructed and discarded its own database client, exhausting the pool under load.

After

One shared singleton reused across all handlers — per-event client churn eliminated.

What changed in interfaces

The contracts behind the fixes

Each failure was a boundary that let the wrong thing happen. Each fix redefined that boundary so the failure cannot recur — described here without client or product identifiers.

Filesystem timeouts

Responsibility shift

Path resolution now happens agent-side, against a persisted, explicitly stated set of allowed roots, rather than the dashboard requesting whatever path it guessed. The interface no longer accepts a raw path from a client without first checking it against the agent's declared roots.

Dropped protocol frames

Interface adjustment

Frame dispatch gained an explicit error contract: a parse failure or an unrouted message returns a typed error frame to the caller instead of being consumed by a no-op handler. A message that cannot be handled is now a response, not a silence.

Unhandled rejections

Send contract

The send API was changed to always settle. Instead of throwing into the void when the socket is down, every send resolves or rejects through a guarded path, so the caller gets a definitive outcome and can react to it.

Connection pool exhaustion

Data-access boundary

Handlers no longer construct their own database client. A single shared client is provided through the request context, so the interface exposes one way to reach the data layer and every handler uses it.

Acceptance

Done meant a number, not an opinion

Every workstream shipped against criteria written before the work started.

  • 24-hour soak test with zero crashes, zero restarts, and zero unhandled rejections.
  • First filesystem request after connect succeeds in 100 of 100 consecutive reconnect cycles.
  • File suite passes for list, read, write, upload, download, and conflict cases.
  • Session create, restart, close, and interrupt paths all covered by passing end-to-end tests.
  • A dashboard receives frames only for devices belonging to its own account.
  • Dependency and security scans report no open critical or high issues.
  • Health and readiness endpoints return correct status under normal and degraded conditions.
  • Beta plan, triage policy, severity definitions, and a signed-off go/no-go checklist.

Why it matters

This is the work most teams skip

Prototypes demo well and fall over in front of users. This engagement was the gap between the two.

Reliability

Reconnects, restarts, and recovery treated as features

Observability

Correlation IDs so an error report becomes a trace

Security

Fail-fast secrets, rate limits, dependency remediation

Operability

One-command bootstrap and a verified container path