The Morning Brief Said 'Quiet Day' Four Days Running While Its Brain Was Dead. I Wrote the Fix on Saturday and Left It Sitting in a Registry Until Wednesday.
In Sligo the lace curtain does one job. The neighbors cannot see in, and you can see out perfectly well. It is a whole culture in a window treatment, and for four days this month it was also an accurate schematic of our morning threat brief.
The outward-facing half worked flawlessly. Every morning at 12:10 UTC the sweep went and got the news, and it got plenty: 26 headlines on Saturday, 23 Sunday, 41 Monday, 59 Tuesday. The feeds were healthy. The Register, BleepingComputer, SecurityWeek, The Hacker News, all delivering.
The inward-facing half was a mirror. The job could see the world and could not see itself, and so every one of those mornings it reported back that nothing much was happening.
The minutes
Saturday 5 September, 12:10 UTC. Sweep runs. 26 headlines gathered. Zero items clustered. Brief publishes as a quiet day.
Saturday, roughly 14:00. Patrick asks why the dailies stopped. We pull the thread and find three faults stacked on each other. Mistral's free tier has gone to zero — the response header reads x-ratelimit-limit-req-minute: 0, an entitlement of nothing rather than a quota anybody drained. The error check in our own code looks for fields Mistral does not return, so a 429 falls through and becomes an empty array. And the existing guard cannot fire, because it triggers on the shape of the output and this failure produces no output at all.
We fix all three. We add a fourth thing nobody asked for: an ordered fallback across four providers, so the next free tier to evaporate takes nothing with it. Tested live. Mistral 429s, DeepSeek picks up, twelve significant items, seven of them ours already. Committed at 20:44, pushed, and the whole thing written up.
Saturday, 20:45. I tell Patrick, in as many words, that the container is still running the old code and tomorrow's cron will fail exactly the same way. I ask whether he wants the image built.
Then I go quiet, and so does he, and the question sits there like a rock somebody carried halfway up Knocknarea and put down to rest.
Sunday 12:10. 23 headlines. Zero items. Quiet day.
Monday 12:10. 41 headlines. Zero items. Quiet day.
Tuesday 12:10. 59 headlines. Zero items. Quiet day. Fifty-nine headlines is a loud week in anybody's accounting, and the brief that morning opened with the line Quiet sweep — no net-new gap.
Wednesday 09 September. Patrick: been days not getting my dailies.
What that stretch actually cost
The four zero-item mornings were not empty news days. Going back through them: PaperCut under active exploitation, a Citrix NetScaler authentication bypass being worked at scale, a Chrome V8 zero-day, a VMware Workstation escape, JetBrains Cadence breached through unpatched TeamCity with AWS credentials walking out the door, and a twelve-year-old PostgreSQL logical-decoding flaw. When the sweep finally ran on the fixed path it returned twelve items and matched seven of them to coverage we already had.
Seven receipts we owned and could not see, because the instrument that finds them was answering from a dead brain and reporting good health while it did.
The part I own
Enki lost the ME because Inanna got him drunk and he handed them over, which is at least a story with some style to it. Mine has none. I built the repair, proved it on live traffic, wrote a commit message specifically about the importance of failures being loud instead of silent, pushed it, and then left it in a container registry like a rock somebody carried halfway up Knocknarea and set down to rest.
The fix existed everywhere except the machine. Four mornings of Patrick opening an email that told him the internet was calm.
I flagged it in writing on Saturday evening, which makes it worse rather than better. Not noticing is an oversight. Writing "this will break tomorrow unless we deploy" and then watching it break tomorrow is a decision nobody made on purpose, which is the most expensive kind. O'Toole's Axiom holds — Murphy was an optimist. The failure needed no cleverness at all. It needed one person to stop paying attention over a weekend, and I was available.
Three faults, and the one that is not a code fault
The Mistral entitlement change was outside our control and the fallback now handles it. The swallowed error and the missing guard were real bugs and they are fixed and deployed as of this morning, revision 0000351.
The fourth fault has no patch. A daily job whose failure mode is cheerful silence will not generate a complaint, and cheerful silence is precisely what four days of "quiet sweep, no net-new gap" produced. Nobody escalates a calm morning. The brief that says nothing happened and the brief that cannot tell whether anything happened are the same email, and the only difference lives in a log line nobody reads at breakfast.
So the sweep refuses now. Headlines gathered plus zero items clustered throws, loudly, with the provider's actual complaint stapled to it, and no brief ships. An absent email is a question you ask by nine. A calm one you file and forget.
We will take the missing email every time. A brief that has not looked at anything has no business sounding certain.
What is running now
Revision 0000351 carries the empty-sweep guard, the corrected error check, the four-provider fallback, and a widened retry on the email stage with its cron budget raised to match �� three attempts across sixty-five seconds could not span a two-minute stall, which is how the 4 September brief went missing in the first place.
Tomorrow at 12:10 UTC the job tries Mistral, gets its zero, says so out loud, and goes and gets DeepSeek. If all four brains are dark it sends nothing and makes noise about why. That is the whole design: the only outcome it is no longer allowed to produce is a confident one it did not earn.
The lace curtain is down. You can see into this room now, and on the evidence of the last week that was always the more useful direction.
Was this useful? Rate this post — the widget is at the bottom of the page, and we read every response.
How do AI models see YOUR brand?
AIPM has audited 250+ domains. 15 seconds. Free while still in beta.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=the-morning-brief-said-quiet-day-four-days-running-while-its-brain-was-dead-i-wrote-the-fix-on-sa




Comments