Restart-safe jobs
Jobs persist in PostgreSQL across restarts. Retries are bounded, and failed work has a visible Retry action.
Reliability
Crash-conscious writes, durable jobs, transactional source generations, and recoverable projections protect specific transitions—not every failure mode.
Implemented mechanisms
Small, inspectable state machines replace request-level optimism.
Jobs persist in PostgreSQL across restarts. Retries are bounded, and failed work has a visible Retry action.
Each page shows whether it is queued, generating, ready, failed, or interrupted. Incomplete work stays visible.
Losing access to Gmail or Notion stops sync. It never deletes content already imported.
Blue-green regeneration builds replacement views before switching readers to them. Pages can be rebuilt from the underlying facts.
Crash-safe contributions
Replaceable generations keep incomplete re-ingestion from displacing the last good source.
Extraction and derivation stay staged. Staged or failed work is not active memory and can be cleaned before retry.
Activation and supersession commit together. A pre-commit crash leaves the prior successful generation active.
Search pages and cards are derived projections. The queue tracks writes, rebuilds, and deletions.
Projection work is acknowledged only after its write or deletion succeeds, leaving unfinished work recoverable.
Operational state
Jobs expose lifecycle state and bounded diagnostics. Transient failures can retry; permanent policy or content failures stop. Unexpected failures stay generic at the customer boundary.
Pending, running, succeeded, and failed states persist with recovery timestamps.
Retries are selective and bounded; durable does not mean eventual success.
Post-write checks can leave repair work queued when completion is uncertain.
Current limitations
The first deployments are small, managed, and not a basis for wider service objectives.
The service does not currently publish an availability percentage, support-response target, RPO, RTO, or maintenance-window commitment.
The beta runs in one region with no high-availability replica. There is no automatic regional failover.
Durable-state, recovery, projection, and deletion paths have focused validation. That does not establish correctness for every input, integration, or compound infrastructure failure.
Operate for recovery
Define retries, human intervention, and the authoritative source before failures occur.