DEV Community

Dakota Wu
Dakota Wu

Posted on

Pin a Solo Waitlist to a Local Byte and Time Ceiling

A solo waitlist can ship today and still keep the bill at zero. That result holds only when the handler, the store, and a local request-budget harness agree before any public host exists. A free model may draft the next check. It may not widen the response, add a client, or invent a second process.

The method is small on purpose. One POST, one append-only file, one command that fails closed. Everything else waits.

The constraint that makes the route shippable

MonkeyCode's free model access and a free server option are the two availability claims this workflow relies on. Disclosure: This article was prepared as part of MonkeyCode's product outreach.

Neither claim is a hardware spec, a duration, or a numeric token quota. This article does not treat quota, region, disk, or uptime figures as stable, because those numbers go stale faster than a tutorial can be corrected. The founder reads the current console before counting on either option.

The local ceiling stays stricter than any assumed platform limit. If the console no longer shows a free path, the harness still stops a quiet dependency from landing in the tree.

Where the second edit usually breaks the bill

The first generated handler is often short. The second prompt is the risky one. Asked to make a waitlist nicer, a model will echo the stored email, wrap the write in a retry, or pull in a helper that opens a socket.

The diff can look harmless. The response gets fatter, the call gets slower, or a new import appears below the fold. A ceiling on bytes and milliseconds catches the first two failures. It does not catch every import, which is why the founder still reads the diff after the command goes green.

Files that are allowed to exist

The layout is the policy. Extra services do not get a folder.

waitlist/
  handler.py
  budget.env
  fixtures/ok.json
  fixtures/fat.json
  harness.sh
Enter fullscreen mode Exit fullscreen mode

store.ndjson is created at runtime and is never committed. budget.env is committed. It records founder policy, not a measured host SLA.

# budget.env — local policy, not a vendor measurement
MAX_RESPONSE_BYTES=1024
MAX_HANDLER_MS=200
ALLOWED_METHOD=POST
ALLOWED_PATH=/waitlist
Enter fullscreen mode Exit fullscreen mode

Two hundred milliseconds is a laptop ceiling. It forces the handler to stay cheap before a cold remote process is involved. It is not a claim about any free server timeout, and this article publishes no host timing because none was measured here.

Step 1. Pin the handler to the standard library

The handler checks the method, the path, and one email field. It appends one JSON line and returns a tiny body. No framework, no mail client, and no socket of its own.

# handler.py — proposal, not executed for this article
import json
from pathlib import Path

STORE = Path("store.ndjson")

def handle(method, path, raw, budget):
    if method != budget["ALLOWED_METHOD"] or path != budget["ALLOWED_PATH"]:
        return 405, b'{"error":"method_or_path"}\n'
    try:
        body = json.loads(raw)
    except json.JSONDecodeError:
        return 400, b'{"error":"json"}\n'
    email = body.get("email")
    if not isinstance(email, str) or "@" not in email or len(email) > 120:
        return 400, b'{"error":"email"}\n'
    if len(raw) > 512:
        return 400, b'{"error":"size"}\n'
    line = json.dumps({"email": email}, separators=(",", ":")) + "\n"
    with STORE.open("a", encoding="utf-8") as fh:
        fh.write(line)
    return 201, b'{"ok":true}\n'
Enter fullscreen mode Exit fullscreen mode

The snippet is a proposal. It does not hash the address, rate-limit callers, or prove the mailbox exists. Those omissions are deliberate. A day-one route that adds them usually reaches for a paid API before the first real signup arrives.

Step 2. Add fixtures that stand in for a bad edit

Two fixtures are enough for the first gate. The good one is a short object. The fat one is a large object that must be rejected before the store grows.

mkdir -p fixtures
printf '%s\n' '{"email":"ada@example.com"}' > fixtures/ok.json
printf '%s' '{"email":"ada@example.com","pad":"' > fixtures/fat.json
python3 -c 'print("x" * 800, end="")' >> fixtures/fat.json
printf '%s\n' '"}' >> fixtures/fat.json
Enter fullscreen mode Exit fullscreen mode

The fat fixture is not a fuzz corpus. It stands in for the edit that echoes user input into a long error body, or that accepts a blob because a prompt said to store the raw request. If that edit lands, the gate should fail before any copy to a host.

Step 3. Run the budget command on the laptop

The harness imports the handler in-process. It does not bind a port, and it does not call a network. Startup noise stays out of the ceiling, which keeps the gate readable. Values in budget.env must not contain spaces around =, because the shell sources the file directly.

#!/bin/sh
# harness.sh — local gate, not a load test
set -eu
set -a
. ./budget.env
set +a
rm -f store.ndjson

python3 - <<'PY'
import os, time, pathlib, importlib.util
spec = importlib.util.spec_from_file_location("handler", "handler.py")
mod = importlib.util.module_from_spec(spec)
spec.loader.exec_module(mod)
budget = {
    "ALLOWED_METHOD": os.environ["ALLOWED_METHOD"],
    "ALLOWED_PATH": os.environ["ALLOWED_PATH"],
}
max_bytes = int(os.environ["MAX_RESPONSE_BYTES"])
max_ms = int(os.environ["MAX_HANDLER_MS"])
cases = [
    ("POST", "/waitlist", pathlib.Path("fixtures/ok.json").read_bytes(), 201),
    ("POST", "/waitlist", pathlib.Path("fixtures/fat.json").read_bytes(), 400),
    ("GET", "/waitlist", b"{}", 405),
]
for method, path, raw, expect in cases:
    t0 = time.perf_counter()
    status, body = mod.handle(method, path, raw, budget)
    elapsed = (time.perf_counter() - t0) * 1000
    if status != expect or len(body) > max_bytes or elapsed > max_ms:
        raise SystemExit(
            "fail method=%s status=%s bytes=%s ms=%.1f"
            % (method, status, len(body), elapsed)
        )
print("budget-ok")
PY
Enter fullscreen mode Exit fullscreen mode

The release command is short.

chmod +x harness.sh
./harness.sh
Enter fullscreen mode Exit fullscreen mode

The script prints budget-ok only when every case matches. In this proposal that string is the release token, not a measurement from a live host. Any other output means the files stay on the laptop.

The founder does not repair a red run by raising MAX_RESPONSE_BYTES inside the same edit that grew the body. The ceiling moves in a separate commit, with a one-line reason, or it does not move.

Step 4. Let the model draft, then restore on red

The free model earns its place as a drafter inside this fence, not as the reviewer of record. The prompt includes budget.env, handler.py, and one requested change, such as rejecting a missing source label without new imports. The reply is pasted over a copy of the handler by hand. Nothing is applied by a tool.

cp handler.py handler.py.bak
# paste the drafted handler over handler.py, then:
./harness.sh || mv handler.py.bak handler.py
Enter fullscreen mode Exit fullscreen mode

There is no second model call in the loop. A green harness is necessary and not sufficient. The founder still scans the import block. A new network client can be fast and small, so the byte ceiling will not save a route that starts calling out.

Step 5. Copy the green tree, and stop there

Upload is a copy of handler.py and budget.env. It is not a database create, a queue bind, or a domain purchase. If the free server option wants a start command, that command should import the same module the harness imported. A framework entrypoint suggested in a model comment is a new service, and it stays off the host.

# DEST comes from the current panel, not from this article
test -n "${DEST}"
cp handler.py budget.env "${DEST}/"
Enter fullscreen mode Exit fullscreen mode

This article names no region, disk size, or process limit. A copied number would be worse than a blank. Consoles change, and a stale limit gets treated as permission.

How to judge the second edit

Suggested edit What the gate sees Action
Tighter email check, no new import budget-ok Keep
Error body echoes the stored line Byte ceiling fails Revert
Retry wrapped around the file write Time ceiling fails, or the gate hangs Revert
New HTTP client import Often still green Reject in the diff read
Paid mail API for confirmation Out of policy even if fast Reject before the harness

The last two rows are the honest limit of a local timer. Speed is not the same thing as a zero bill. A fast call to a paid API is still a bill.

Limits that stay even after a green run

The timer measures the laptop. A free server can be slower when the process is cold, and no cold-start figure is claimed here. A local pass does not prove a remote pass.

The store is one append-only file. Two overlapping writes can tear a line. That is tolerable for a solo list with tiny traffic. It is the wrong store for a paid signup, or for two people sharing a host.

The email check is a length cap plus an @ sign. Junk will get in. Mail will not go out. Confirmation mail, abuse controls, and a privacy review are a different system, and that system should be expected to cost money.

The harness does not watch DNS, TLS, or an idle policy on the host. A route can pass locally and still sleep after upload. The founder opens the public URL once. If the panel asks for a card, the upload stops.

Who should leave this pattern alone

More than one writer should not share store.ndjson. A product that takes payment should not keep emails this way. A founder who will not read a diff should not aim a free model at the handler, because quiet imports slip past the timer.

Anyone who needs a stated uptime target should not treat a free server option as capacity. The option is a way to put one route on the public internet today, with the limits written in budget.env. It is not a promise that the option remains.

After the command prints budget-ok

A founder who already keeps this fence can draft the next tiny check with MonkeyCode's free model access, and can use the free server option as the only copy target, if the console still shows both. The release rule does not change with the editor. ./harness.sh prints budget-ok, or the files stay on the laptop.

Top comments (0)