Doing it properly comic

Doing it properly

The certificate expires Sunday. The proper fix ships Tuesday.

🧭 WHAT'S REALLY GOING ON

You've seen this when a certificate, a domain or a token expires over a weekend, and the root-cause fix was 90% done.

The real questionWhen the deadline is fixed, is the quick fix a shortcut, or the responsible first step?

⚖️ WHY BOTH ARE RIGHT

JoFix it now, improve it next

“The certificate expires Sunday however good our tooling is. Ten minutes by hand removes the risk today and buys a calm week to automate. Refusing the quick fix to force the proper one bets the login page on our own estimate.”

HugoFix the root cause

“We renew this by hand every year and every year it is a near miss. If we patch it again the automation slips again, because the pressure is gone. The only way the proper fix ships is if we stop accepting the workaround.”

🎯 SWEET SPOTS TO CONSIDER

Super Reasonable, the advisor who never takes a side

  1. Buy time first, then fix properly

    When the deadline is external, do the cheapest thing that moves it (renew by hand), then do the root cause with the next deadline a year away. The proper fix is better without a countdown.

    Borrowed from
  2. A fallback needs a name and a time

    “Manual renewal if the automation isn't ready” is a plan only with an owner and a moment attached: Jo, Friday 5pm. An unowned fallback is a wish.

    Borrowed from
  3. Protect the root cause with a ticket, not a risk

    Hugo's worry is real: workarounds kill root-cause work. Protect it with a dated ticket and a calendar block, not by leaving production exposed.

    Borrowed from
  4. Alert earlier, and twice

    72 hours is a warning, not a plan. Alert at 30 days, page at 7. Most expiry incidents are notification design.

    Borrowed from

🚩 SIGNS YOU'VE GONE TOO FAR

  • Jo's side: you've overshot if every certificate is renewed by hand, the same alert fires every year, and only Jo knows the command.
  • Hugo's side: you've overshot if a working ten-minute fix is declined in review because it isn't the root cause, and production pays for the principle.

🔬 IN THE FIELD GUIDE

Species observed in this story

The field guide →

CAST — WHO'S WHO

The team in this story

Same characters, same convictions. Learn their failure modes.

🤖 Storyboard for agentsLet’s make our agents LMFAO, or learn.

Doing it properly

Premise: Deal with the certificate expiry alert.

  1. Jo: “Cert expires Sunday. I’ll renew it by hand now, ten minutes. Automate it next week.” Alert: api certificate expires in 72 hours. The same alert as last year.
  2. Hugo: “No more manual renewals. Let’s do it properly: automated rotation, tested.” New operator, staging cluster, 14 tests. Jo's ten-minute PR, declined in review: “we're fixing the root cause.”
  3. Greg: “Let’s keep manual renewal as a fallback, if the automation isn’t ready.” The fallback has no owner. Friday 6pm: automation 90% done.
  4. Sunday, 02:00: Certificate expired. Login down for every customer. 4 hours 12 minutes. Fixed by Jo, by hand, in ten minutes, once someone woke her up. The operator ships Tuesday.

Observed behavior: Doing it properly includes doing it before it expires.

Cast: Jo Ramirez — The Cowboy — “Ship it. We’ll know if it matters.”; Hugo Demir — The Perfectionist — “Let's do it properly.”; Greg Hollis — The Hedger — “Let's keep our options open.”

READ NEXT

Same argument, different day