Skip to content

Admin analytics readiness — September 11, 2026 PDT

Historical snapshot: September 12 credential rotation and the owner's replication restart are now complete. The restricted source and ClickPipe have been created; see current connection progress. Statements below about untouched credentials/replication describe the earlier preparation state.

This records preparation already performed. It does not schedule a Neon restart, enable logical replication, rotate credentials, or authorize switching the production admin.

Backend state

ComponentVerified state
Railway workeryumina-analytics, service 73b4ae19-ed15-40f0-a84f-7ece1ee871a3, existing production project, one US West replica. Separate Node 22 Docker image, non-root process, private health endpoint, no production DATABASE_URL.
ClickHouseyumina_analytics analytical tables created using the separate migration identity. Worker uses the limited importer identity. No PostgreSQL ClickPipe exists yet.
RedisWorker uses Redis.REDIS_URL over Railway private networking. Namespaced reports, renewable worker lease, durable ClickHouse snapshots and last-good API fallback.
PostHog storageDedicated private Railway bucket yumina-analytics-export-bf3zf6; existing product assets are separate. S3 virtual-host addressing verified.
PostHog liveIntegration 265208; hourly signup-only JSONLines/gzip export 01a09419-d233-0001-654c-53d8ec840b48. A completed one-hour object contained 38 signup events and imported successfully.
PostHog historyPaused daily export 01a0941d-4f15-0001-a3f7-9445922d6b5f; all 46 backfill runs completed. Requested April 1, but PostHog adjusted availability to July 28. Earlier attribution stays unknown.
Corporate StripeAccount identity verified; historical balance ledger imported. Ongoing payment/customer/product enrichment is bounded and independent of the legacy account.
Legacy StripeOwner enabled Accounts Read; GET /v1/account now returns 200. Identity verified and pinned as distinct from corporate. Complete historical ledger imported: 324 balance entries covering 150 distinct charges. Purchase enrichment continues separately.
OpenRouterActual account charges reconciled for April 1 through September 11 UTC: $70,945.836551. All 163 daily amounts match independent provider daily and monthly billing queries. September 12 is still partial. No extra cache discount; funding fees excluded.
Neon telemetryFour nullable usage columns and three new telemetry tables applied in a transaction with a 2-second lock timeout; migration plus verification took about 117 ms. No existing rows backfilled. Logical replication, publication and credentials untouched.
Production web/adminBranch not pushed or deployed. Capture and dashboard enablement are still pending. Existing UI continues to run.

Verification

  • Full monorepo build and typecheck passed.
  • Latest worker deployment 00bea228-e966-413a-9ea2-4675bd7df8fb is running successfully; its private health check reports alive, CDC disabled, and no production database credential. Report readiness is correctly false until the remaining sources are connected.
  • PostHog history, the hourly test, and the four-hour gap backfill all completed. The importer has 18,246 signup events at this check; these are deduplicated event IDs, not an account denominator. The live hourly export remains active.
  • Corporate Stripe currently has 3,286 balance rows covering 2,774 distinct charges. Legacy Stripe has 324 balance entries covering 150 distinct charges, with its initial ledger cursor complete through September 12, 06:04:23 UTC. Both account identities are verified. Purchase attribution is still being enriched in bounded batches; complete financial report readiness is not yet claimed.
  • Analytics tests cover cash conservation, cache deadlines/fallback, malformed data, authorization, leases, source migrations, Stripe account pinning and duplicate-account rejection.
  • Disposable real ClickHouse databases passed report and CDC-view tests, including replay/deletes, financial allocations, overlapping time, cohort maturity, acquisition denominators and age unknowns. These are synthetic correctness tests, not a completed production CDC import.
  • Desktop 1440px and phone 390px checks use the actual React app with synthetic API responses: finance controls, audience details, model tokens, world tags/zoom, retention, cached moderation navigation, embedded world rendering and searchable entries. The screenshots are fixtures, not live financial reports.
  • Railway private Redis benchmark: 100 reads, concurrency 10, 250,900-byte JSON payload, including JSON parse; p50 11.7 ms, p95 28.1 ms, maximum 42.4 ms. This is storage-path performance, not end-to-end authenticated page latency. QA keys expire automatically.
  • A source failure no longer forces healthy provider imports every minute. Stripe identities are checked independently against all pinned account IDs; an unavailable legacy source does not halt corporate import/enrichment. Combined finance remains unavailable until matching cutoffs are complete.
  • OpenRouter selects different underlying sources depending on requested metrics. Including detailed BYOK/request-history fields understated the checked closed period by $18.674338. Finance now requests the account billing metrics and requires date__day; a regression test rejects request-history dates. The worker refreshes a seven-day overlap and audits full billing history daily. Corrected warehouse charges match every day of the independently queried closed period.
  • Mobile funding flows show source rows with stacked destinations and expandable amounts. Finance labels stay above numbers; incomplete weeks/months are marked and the first displayed bucket starts April 1.

Remaining gates

  1. Finish and verify historical payment attribution, preserving unmapped receipts and missing request costs explicitly. The legacy Stripe permission gate is resolved; no further owner credential change is currently needed.
  2. After a separate later discussion: source replication and application capture deployment. Do not initiate that maintenance step from this document.
  3. Before switching the admin: reconcile complete financial/activity reports at matching UTC cutoffs and verify source load during initial replication. The worker being healthy does not mean those reports are ready; /health.ready remains false until a report is published.

Local setup credentials are Windows-DPAPI protected in an ignored directory; secrets are not committed or included in Docker uploads. The only credentials installed on Railway were for the new worker. No existing application DB key has been rotated.