Client engagement · 2026
Hardening a Developer Platform for Beta
A contracted engagement taking a multi-tier developer platform — a hub service, a daemon running on each enrolled device, and a browser dashboard streaming live terminals — from working prototype to something that survives a real beta: no silent crashes, no untraceable errors, and a deployment path anyone on the team can run.
Client, product name, source code, and commercial terms are covered by an NDA and are not published here. What follows is the shape of the work and the measurable bar it had to clear — available in detail on request, where the agreement allows.
Role
Contract engineer
Surface
Hub · agents · dashboard
Focus
Reliability & beta readiness
Basis
Fixed-scope SOW
System
Three tiers, one wire protocol
Expand any tier to see what it owns and how it talks to the others. Implementation detail and client identifiers are withheld under NDA.
Responsibilities
- Authenticates users and issues device certificates during pairing.
- Routes frames between dashboards and agents, scoped per account.
- Persists devices, sessions, allowed roots, and audit events.
- Proxies TCP traffic to device-local ports and exposes health and readiness endpoints.
Interfaces
- Inbound: dashboard WebSocket and REST API, both auth-enforced and rate-limited.
- Inbound: agent WebSocket authenticated by a signed device certificate.
- Outbound: pooled connections to the relational database via a shared client.
Scope
Six workstreams, one written scope
The engagement was defined up front as discrete, testable workstreams rather than open-ended hours.
Core hardening
01A single shared database client across the service instead of one per frame, a fixed startup race between the socket layer and the filesystem channel, agent reconnect with unbounded exponential backoff and hello re-send, no unhandled promise rejections on send, and clean crash recovery with reporting.
File workflow
02Beyond directory listing: inline file viewing and editing with save-back over the wire protocol, drag-and-drop upload and download inside defined size limits, a stated strategy for large files, and permission and error states users can actually act on.
Session creation UX
03A create-session dialog covering every runtime driver, with working directory, environment overrides, and extra-argument input, inline validation, sane defaults, and end-to-end launch coverage for each session kind.
Security baseline
04Per-user relay filtering so a dashboard only receives frames for its own devices, enforced WebSocket auth in production, server-side rate limits on auth, pairing, and filesystem channels, secure environment defaults, fail-fast on missing or weak production secrets, and a dependency audit pass.
Debuggability & logging
05Structured logs across dashboard, hub, and agent with correlation IDs tying a request to its frames, user, device, and session; surfaced protocol-parse failures instead of silent frame drops; health and readiness endpoints; and a runbook for the top failure scenarios.
Deployment pack
06Reproducible dev and beta environment scripts, verified container images and compose config behind a TLS reverse proxy, dynamic proxy configuration as tunnels open and close, seeded test data, and one-command bootstrap.
Diagnosis
Four bugs that looked like four different problems
Each one presented as a vague timeout or hang. Each one had a specific, findable root cause.
Filesystem requests timing out
Home-directory paths resolved against the process working directory on one OS, and the agent's allowed-roots set was never persisted, so the dashboard kept requesting a path that could not exist. Fixed by expanding the path correctly agent-side and persisting allowed roots, merged with live registry data in API responses.
Silently dropped protocol frames
Schema validation errors in the multiplexer were caught into a no-op handler, so malformed or unrouted frames vanished without a trace. Parse failures and missing channel handlers now surface as real, traceable errors.
Unhandled rejections on disconnect
Sends issued while the socket was down threw into nothing, leaving the caller to time out. Every send now goes through a guarded path that fails loudly and fast.
Connection pool exhaustion
Each inbound event frame constructed and discarded its own database client. Replaced with a shared singleton reused across handlers.
Results
What changed, measured
Same four fixes, shown as a before-and-after. The numbers are chosen to prove the outcome without exposing anything the NDA covers.
Filesystem timeouts
afterBefore
First filesystem request after a reconnect intermittently timed out, so a freshly connected dashboard kept requesting a path that could not exist.
After
The first request succeeds in 100 of 100 consecutive reconnect cycles — a hard, repeatable bar rather than a flaky symptom.
Dropped protocol frames
afterBefore
Schema-validation errors were caught into a no-op handler, so malformed or unrouted frames vanished without a trace.
After
Parse failures and missing channel handlers now surface as real errors. Zero silent frame drops in the soak window.
Unhandled rejections
afterBefore
Sends issued while the socket was down threw into nothing, leaving the caller to time out with no signal.
After
Every send goes through a guarded path that fails loudly and fast — zero unhandled rejections over a 24-hour soak.
Connection pool exhaustion
afterBefore
Each inbound event frame constructed and discarded its own database client, exhausting the pool under load.
After
One shared singleton reused across all handlers — per-event client churn eliminated.
What changed in interfaces
The contracts behind the fixes
Each failure was a boundary that let the wrong thing happen. Each fix redefined that boundary so the failure cannot recur — described here without client or product identifiers.
Filesystem timeouts
Responsibility shiftPath resolution now happens agent-side, against a persisted, explicitly stated set of allowed roots, rather than the dashboard requesting whatever path it guessed. The interface no longer accepts a raw path from a client without first checking it against the agent's declared roots.
Dropped protocol frames
Interface adjustmentFrame dispatch gained an explicit error contract: a parse failure or an unrouted message returns a typed error frame to the caller instead of being consumed by a no-op handler. A message that cannot be handled is now a response, not a silence.
Unhandled rejections
Send contractThe send API was changed to always settle. Instead of throwing into the void when the socket is down, every send resolves or rejects through a guarded path, so the caller gets a definitive outcome and can react to it.
Connection pool exhaustion
Data-access boundaryHandlers no longer construct their own database client. A single shared client is provided through the request context, so the interface exposes one way to reach the data layer and every handler uses it.
Acceptance
Done meant a number, not an opinion
Every workstream shipped against criteria written before the work started.
- 24-hour soak test with zero crashes, zero restarts, and zero unhandled rejections.
- First filesystem request after connect succeeds in 100 of 100 consecutive reconnect cycles.
- File suite passes for list, read, write, upload, download, and conflict cases.
- Session create, restart, close, and interrupt paths all covered by passing end-to-end tests.
- A dashboard receives frames only for devices belonging to its own account.
- Dependency and security scans report no open critical or high issues.
- Health and readiness endpoints return correct status under normal and degraded conditions.
- Beta plan, triage policy, severity definitions, and a signed-off go/no-go checklist.
Why it matters
This is the work most teams skip
Prototypes demo well and fall over in front of users. This engagement was the gap between the two.
Reliability
Reconnects, restarts, and recovery treated as features
Observability
Correlation IDs so an error report becomes a trace
Security
Fail-fast secrets, rate limits, dependency remediation
Operability
One-command bootstrap and a verified container path