I wanted one gate before a free model edited code. The budget was zero extra paid services this week. The missing piece was evidence, not another clever prompt.
Solo builders still ship a tiny tool the same day. A same-day patch can feel like real progress. Then the diff lands with no rollback note attached.
Would you merge a patch that cannot be undone? I would not, yet the shortcut still looks tempting. Speed without an exit is how small tools rot.
What a free run is not
A free model can draft a small patch today. A free server can host one scratch run tonight. Neither availability claim counts as a production permit.
Did you write the exit path before the run started? If not, the job is still only a draft. A draft does not get to touch main.
Disclosure: This article was prepared as part of MonkeyCode's product outreach. Two operator-stated options are the only product claims here. Those options are free model access and a free server.
I state no token quota, hardware size, uptime, or permanence. The operator also describes MonkeyCode as open source. I will not link a repository I have not verified here.
Use the install docs you already trust for setup steps. Re-check those docs on the day you actually run. Terms for a free option can move without a warning.
The promise and the clean exit
You get one command that fails closed on purpose. Missing evidence returns exit code two every time. A bad marker also returns exit code two.
Only a complete pass is allowed to return zero. The time box for this exercise is sixty minutes. The cost box is local files and no paid calls.
Abandon the job if scope evidence cannot be shown. Abandon it if rollback or a human ack is missing. Do not delete a red gate just to look green.
Step 1: Write the evidence contract
Start inside a scratch directory, never on main. Ask what would prove this job is still small. If you cannot answer, stop before any model runs.
Save this contract in the same folder as the checker. It is a template, not a live audit record. Change the scope line to match your real task.
# readiness.yml — template, not a live audit record
job: side-project-patch
scratch_dir: ./scratch
fail_closed: true
evidence:
scope_file: evidence/scope.txt
secret_scan: evidence/secret-scan.log
rollback: evidence/rollback.md
cost_cap: evidence/cost-cap.txt
server_note: evidence/server-ephemeral.txt
human_ack: evidence/human-ack.txt
gates:
- id: scope
evidence: scope_file
must_contain: "OUT OF SCOPE"
- id: secrets
evidence: secret_scan
must_contain: "NO_HITS"
- id: rollback
evidence: rollback
must_contain: "git restore"
- id: cost
evidence: cost_cap
must_contain: "ABORT_OVER"
- id: server
evidence: server_note
must_contain: "EPHEMERAL"
- id: human
evidence: human_ack
must_contain: "ACK"
Each gate needs a real file and a visible marker. A blank file is not evidence of a review. Why trust a file that never names a boundary?
Step 2: Plant the failure fixture
I want the red path before any green path. Create the evidence folder, then omit one required file. The missing human ack is the failure fixture.
The gate must fail while that ack file is absent. If the checker passes, stop and fix the script. A green result on a broken fixture is useless.
mkdir -p evidence scratch
printf 'IN SCOPE: README typos only\nOUT OF SCOPE: auth, billing, migrations\n' > evidence/scope.txt
printf 'scanner=local-grep\nNO_HITS\n' > evidence/secret-scan.log
printf 'rollback: git restore --source=HEAD --worktree -- path\n' > evidence/rollback.md
printf 'cap: local scratch only\nABORT_OVER: any paid call or secret file\n' > evidence/cost-cap.txt
printf 'EPHEMERAL: free server is scratch, not a system of record\n' > evidence/server-ephemeral.txt
# human-ack.txt is intentionally missing
Step 3: Run the fail-closed checker
The checker below is a proposal you can run locally. It uses only the Python standard library on purpose. I am not claiming a benchmark or a model score.
#!/usr/bin/env python3
"""ready_gate.py — fail closed unless every evidence marker exists.
Proposal script. Not a measured production control.
"""
import sys
from pathlib import Path
GATES = [
("scope", "evidence/scope.txt", "OUT OF SCOPE"),
("secrets", "evidence/secret-scan.log", "NO_HITS"),
("rollback", "evidence/rollback.md", "git restore"),
("cost", "evidence/cost-cap.txt", "ABORT_OVER"),
("server", "evidence/server-ephemeral.txt", "EPHEMERAL"),
("human", "evidence/human-ack.txt", "ACK"),
]
def check(root: Path) -> int:
failed = False
for name, rel, marker in GATES:
path = root / rel
if not path.is_file():
print(f"FAIL {name}: missing {rel}")
failed = True
continue
text = path.read_text(encoding="utf-8", errors="replace")
if not text.strip() or marker not in text:
print(f"FAIL {name}: missing marker {marker!r}")
failed = True
continue
print(f"PASS {name}")
if failed:
print("RESULT fail-closed")
return 2
print("RESULT pass")
return 0
if __name__ == "__main__":
root = Path(sys.argv[1]) if len(sys.argv) > 1 else Path(".")
raise SystemExit(check(root))
Run the checker from the folder that holds evidence/. You should see a human-gate failure and exit two. Did a missing file somehow slip through as a pass?
python3 ready_gate.py .
echo "exit=$?"
Then the script is wrong and this exercise stops. Do not continue to a model call after a bad fail. Fix the checker before you trust any later green.
Step 4: Add the human ack
A human ack is a sentence you can defend later. It is not a vibe, a hunch, or a shrug. Write it only after you read the planned diff.
printf 'ACK: I read scope, rollback, and the secret scan\n' > evidence/human-ack.txt
python3 ready_gate.py .
echo "exit=$?"
Exit zero means the files exist and the markers match. It does not mean the patch itself is correct. Can you see the gap between those two claims?
Step 5: Bind the run to scratch
Keep every model write inside the scratch directory only. Copy only files already named in the scope note. Refuse the run whenever the readiness gate is red.
python3 ready_gate.py . || exit 2
test -d scratch || mkdir scratch
cp README.md scratch/README.md
If you use a free server, treat that box as disposable. The server note must contain the marker EPHEMERAL. Do not store the only copy of your work there.
What happens if that free box vanishes tonight? Free model access can draft a small README tweak. It should not invent new gates or edit the checker.
Why give the writer the keys to its own lock? Split drafting work from the gate that permits a run. A model may propose text, not approve its own text.
Copy this fail-closed table
Read these rows as hard stops, not gentle suggestions. A secret hit is a stop, not a soft warning. Quarantine the file and write a fresh scan log.
| Gate | Evidence you must show | Fail closed when |
|---|---|---|
| Scope |
scope.txt contains OUT OF SCOPE
|
File missing, or no boundary line |
| Secrets | scan log contains NO_HITS
|
Log missing, or any hit remains |
| Rollback | note contains git restore
|
No restore command is written |
| Cost | note contains ABORT_OVER
|
No abort line for paid calls |
| Server | note contains EPHEMERAL
|
Box treated as durable storage |
| Human | ack contains ACK
|
Nobody records a real read |
Do not weaken NO_HITS into a hopeful maybe. Do not mark the server durable just to skip a backup. Would you bet your only copy on a free box?
Limits, and who should skip this
This checklist is not a process sandbox at all. It does not isolate a model or prove privacy. It does not scan generated output for hostile edits.
A tired human can type ACK and still be wrong. You still need a second look outside scratch. The gate catches missing files, not bad judgment.
I am not publishing latency, spend, or a model name. Those figures were not supplied as current primary facts. Quotas and free-server terms can change without notice.
Re-read the vendor docs on the day you run. Do not freeze an old quota into this script. A checklist that hard-codes a number will rot.
Do not use this flow on production customer data. Do not use it for auth, billing, or migrations. Do not pretend it is an enterprise control framework.
A solo README typo job is the intended fit. A regulated system needs a different and heavier process. If policy already names a change tool, use that tool.
A second checklist will only become a rubber stamp. Skip this gate when another system is mandatory. Two paper trails are worse than one enforced trail.
How to abandon without a mess
Stop when any gate stays red after one fix. Delete the scratch tree when it holds unreviewed files. Leave the evidence folder in place as the postmortem.
rm -rf scratch
git status --short
If git status shows edits outside scratch, restore them. Restore those files before you close the laptop tonight. Did you actually run the rollback line you wrote?
One rehearsal, then stop
MonkeyCode's free model access and a free server can host this rehearsal. Try the red path, then the green path, then stop. Do not promote that rehearsal into a real deploy.
Which missing field keeps biting your small team now? Is it the secret scan, the rollback line, or the ack? Send the failure step, not a generic take on models.
Top comments (0)