The scenery sampler identifies as kamouniverse.com; the steward test follows the platform console
- FaunaClient's User-Agent to GBIF named https://kamocrm.com as the product's contact URL; it names https://kamouniverse.com, the platform's primary apex. - S...
Place the KamoAI voice cron keys clear of SP05's and SP10's
SP05's Tool Plane jobs add their cron fields after leadLedgerReconcileCron and their ConfigMap entries after kamoai-hire-steps, and SP10's tick adds its field a...
KamoAI voice SIP sync and retention jobs
kamoaiVoiceSipSyncJob POSTs kamoai-service's X7 **************** every minute, so LiveKit's SIP trunks and dispatch rules follow the AI lines and who is ACTIVE;...
KamoAI minute tick job (SP10)
KamoAiShiftTickJob POSTs kamoai-service's K2 tick (/api/kamoai/internal/tick) every minute with X-Internal-Auth = KAMOAI_INTERNAL_SECRET, mapped onto kamoai.int...
Pin DaemonService to k3m1, where the earthdata drive lives [skip ci]
k1m1 reaches /mnt/worldchunks only through a hard NFS mount of k3m1. That mount has hung, so the kubelet on k1m1 cannot stat the earthdata hostPath. A rollout t...
Delete the second calendar reminder path — EmailService's sweep is the only one
Kamoai-hire-steps job drives SecurityService's hire-step sweep every minute
Pin kamo-shared-library 1.6.1, the only version that exists
The library moved to 1.6.1 and this service still asked for 1.6.0. There is no window in which both resolve: the library is never published to a remote, so the ...
Fold and recount the public changelog's commit-log ledger
securityservice's create_commit_log_ledger.sql (applied by hand as the owner) adds commit_log_counts / commit_log_count_deltas: a total per (project, commit typ...
No live credentials in application.yml defaults
The local-development defaults carried the database OWNER's password (${DB_PASSWORD:<literal>}), and apiservice/securityservice also the live changelog webhook ...
No job overlaps itself, and no HTTP call can hang a worker forever
Quartz here runs 10 in-memory worker threads on one replica. 17 of the 24 jobs had no @DisallowConcurrentExecution, so a run that overran its interval started a...
The lead-intake counters join the ledgers the daemon folds and recounts
The intake endpoints' received / imported counters are now a ledger (securityservice create_lead_intake_ledger.sql, applied 2026-09-22): a trigger on lead_intak...
Fold the lead ledgers every 30 s and recount them nightly; the job trigger needs the cluster secret
The lead ledgers (securityservice create_lead_ledgers.sql, applied 2026-09-22) replace COUNT(*) over a 796k-lead pool and over lead_credits with maintained tota...
Release idle Hikari connections; liveness off the DB-aware health
Same changes the other services got on 2026-09-16, held back until the lead import this service was running finished. Keep the pool maximum but let idle connect...
Skip enabled connections that are not filled in yet
An enabled MERIDIAN_LINK connection with no instance URL, appCode or secret collapsed to a null|null poll-unit and failed token exchange every tick, logging ERR...
Read the public-chat secret by its own key
This pod also mounts mlos-internal-auth, whose INTERNAL_AUTH_SECRET env var relaxed-binds onto internal.auth.secret and outranks the ConfigMap. Every caller rea...
Create intake leads concurrently and claim larger batches
The job created one lead at a time from a 500-row claim, ~230 leads/min at best, which turns a large vendor list into days of backlog. It now claims 2000 payloa...
Accept OCI image indexes when resolving the built digest [skip ci]
The images are pushed as OCI image indexes, so asking the registry for a single image manifest only answered 404, the digest came back empty and the check faile...
Restart when a same-commit rebuild leaves pods on the old digest [skip ci]
The rollout step tried to detect a same-commit rebuild by comparing the Deployment's image reference before and after `set image`. "Apply manifests" has already...
Link the steward to the console the org can reach
StewardRecipientResolver built the steward link from the org's first domain row whatever its state, so an org still setting up its white-label domain was mailed...
Stop reporting a catalog bump as a missing SystemConfiguration row
Three scheduled jobs read a row and skip the whole tick if they cannot. All three were skipping ticks during schema changes, and two of them said so in a way th...
Prove the deploy by digest, not by tag
The preceding commit stops `set image` being a silent no-op. This asserts the outcome: after the rollout, the tag is resolved to a digest at the registry and th...
A rebuild of the same commit deployed nothing and reported success
The image is tagged with the commit SHA, so rebuilding the same commit produces an identical image reference. `kubectl set image` then changes nothing, the Depl...
Declare why this one stays on Recreate with no preStop
KlusterServices now audits every Deployment in kamo on each deploy and fails on Recreate, a missing preStop hook, a missing readiness probe or no minReadySecond...
Fail a bad rollout instead of reporting it green
Deploys replaced the only pod of each service with nothing to catch the requests in flight. Three settings, applied across the fleet: - preStop sleeps 10s befo...
Tick SecurityService's scheduled-report sweep
Every five minutes. A schedule is set to the minute, so a finer tick buys nothing a member would notice and a coarser one makes an 8:00 report arrive at 8:15. ...
Pin kamo-shared-library 1.6.0
The library moved to 1.6.0 while every consumer stayed on 1.5.0. Consumer CI builds the library from a fresh clone into a cold ~/.m2 and ci-settings.xml mirrors...
Record that the unprocessed claim is now batched
getUnprocessedPayloads() returned every unprocessed payload, and this job holds each one's raw and flattened text for its whole run — so its memory was a functi...
Mark payload outcomes by column, not through the entity
payloadRepo.save() on a detached payload makes Hibernate walk its graph — organization pulls in org_domains — and that read lands in a transaction that has alre...
Stop overlapping runs importing the same payloads twice
The trigger fires every minute and each run claims work by selecting payloads still in RECEIVED. A backlog that takes longer than a minute therefore still had R...
Bump the processed counter instead of rewriting the endpoint
The job finished a batch by mutating totalProcessed on the endpoint entity it loaded before the batch began and saving the whole row. Two consequences: - it ...
Persist each payload's outcome as it happens, not in one batch
processEndpointPayloads looped over the batch mutating statuses in memory and saved them all at the end. createLead commits per lead, so any failure of that fin...
Let a mapped payload carry companyName and source
The intake job's direct-field switch stopped at vendorLeadID, so a mapping onto companyName or source was accepted by the UI, stored on the endpoint and then si...
Rebuild against the shared-library lead id fix
This service creates leads through LeadService, so it hit the same failure as /leads/new: on a mortgage market Hibernate 6.2 emitted "insert into leads (...) re...
Size the pod above its own JVM heap ceiling [skip ci]
The image starts the JVM with -XX:MaxRAMPercentage=70 -XX:+AlwaysPreTouch, so the heap alone may take 70% of the container limit and pre-touch keeps every commi...
Nightly payroll-provider sync job
Drives TimecardService's **************** which syncs every organization whose next sync is due. Cron lives here rather than in TimecardService because that de...
Schedule the nightly timecard sweeps
Cron lives here rather than in TimecardService because that deployment is RollingUpdate with maxSurge: 1 — two pods overlap on every rollout and every @Schedule...
The hourly training reminder tick
HOURLY at :10, unlike the legal sweep's daily 13:00. Training reminds each org at its OWN local send hour, and Organization.timezone spans 21 hours (Pacific/Hon...
Refresh planner statistics after the weekly GeoLite rebuild
YugabyteDB does not auto-analyze, and the staging+rename swap replaces geolite_blocks wholesale -- so after every Sunday sync the planner had no statistics for ...
Geolite range index must be ASC, not YugabyteDB's default HASH
The IP lookup is a range scan: WHERE network_start <= ? ORDER BY network_start DESC LIMIT 1 YugabyteDB partitions the LEADING index column by HASH unless tol...
Rebuild against shared-library @Lob LONGVARCHAR fix
Hibernate's PostgreSQL dialect read @Lob String columns as OIDs via getLong(). Affects notes, contacts, calendar, OAuth tokens, IMAP passwords, email campaign b...
Point at YugabyteDB and use PostgreSQLDialect
CockroachDB has been replaced by YugabyteDB. Connection strings move from cockroachdb-public:26257 to yb-tserver-service:5433, and the Hibernate dialect from **...
Retry the shared-library build, which the LAN uplink keeps corrupting
Three builds died today on "Tag mismatch" pulling a jar — and the mirror added an hour ago did not help, because kbservice, mcpgatewayservice and ragservice hit...
Mirror Maven Central through the Google GCS copy
Every Docker stage starts from a cold ~/.m2 and refetches the whole dependency tree, so Central sees the full weight of every concurrent service build. It answe...
Daily legal-package reminder tick
DaemonService owns the tick because DocsService cannot. DaemonService is strategy:Recreate — the old pod is gone before the new one starts, so a deploy window c...
Rebuild against kamo-shared-library 8f3c1ec
Picks up the intake-pool fix: LeadService.createLead now flags unowned leads with requiresAssignment so imported leads are counted by countAssignablePool and ca...
Drive the mail-to-lead association sweep
Five-minute tick against EmailService's internal sweep endpoint, mirroring VoipGlobalSyncJob. The schedule lives here because EmailService runs several pods and...
Like what you see shipping?
All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.
