Review a fictional Aster Reports production infrastructure change. The requested queue-retention value moves from 47 hours to 71 hours. The queue is owned by the reports platform team. A database in the same workspace is outside scope. Deliver a prompt packet with the change envelope, redacted plan review, drift decision, apply checklist, and post-apply evidence. This project does not connect to a cloud account or execute an infrastructure change.
Project: review an Aster queue retention change
Block the first plan
Operator verification establishes the intended production workspace and account. Sanitized plan P1 shows the expected queue update plus an unexpected database replacement. The prompt classifies both actions and blocks P1. Investigation finds a manual database setting changed during an earlier incident. Its owner must choose whether configuration should adopt or reverse that setting through a separate change. The model sees only resource address, action, and redacted attribute path, not raw state, a token, or a binary plan. After resolution, a fresh P2 contains only the queue update and receives a new review.
Apply and inspect the actual outcome
The reports platform owner approves P2. An authorized operator checks state locking and executes the reviewed plan through the controlled pipeline. Run R-47 reports completion. A provider read confirms 71 hours, and a new plan has no unexpected actions. A test message is accepted and read, while operations watches queue age and dead-letter counts during the observation window. The packet states a rollback limit: setting retention back cannot recreate already expired messages. Keep the blocked P1 and its resolution in the review history.
Request: queue retention 47h -> 71h; database out of scope.
P1: queue update + database replacement -> BLOCK.
Investigate drift without exposing raw state or saved plan.
P2: queue update only; owner approves; operator applies.
R-47: execution receipt; provider read 71h; postchecks pass.
Rollback limit: configuration reversal cannot restore expired data.Performance and operating cost
Classifying A plan actions takes O(A) review, and checking V postconditions adds O(V) work plus an observation period. This is small compared with the cost of an unexpected database replacement. A redacted packet reduces disclosure and token cost but must still preserve enough action detail to expose risk. Neither a plan nor a pipeline success line proves the resource and application behave as intended; verify the live setting and a representative message path before closing the change.
Common Mistakes
- Do not apply P1 because its queue change looks right.
- Do not send raw state or a saved plan to an unrestricted model.
- Do not call P2 complete until the actual resource and message path are checked.
Connected lessons
- Infrastructure prompts: bind scope, owner, and environment
- Infrastructure plans: classify every action before apply
- Infrastructure prompts: quarantine state secrets and drift
- Infrastructure apply: separate review from execution
- Infrastructure release: verify live state and rollback limits
- Terraform state: shared ownership and safe plans
- Terraform replacement: prove old and new can coexist
- Tool effects: reconcile receipts before retrying
- Infrastructure-change prompt decisions
