Legacy Bucket Cleanup — Jul–Aug 2026
Status: Complete as of 19 Aug 2026. The hourly Legacy Bucket 404 Watch is retired. Do not restore objects that the July cleanup deleted, and do not re-add
.github/workflows/legacy-404-watch.yml.
This page is the history of the July 2026 prune of
gs://finmatch-finance-marketing-assets and the short-lived monitor
that watched for leftover storefront fetches. It exists so future
agents can see why the watch existed and why it was turned off.
The June repository cleanup (ghost mirrors, SDK copies) is a separate record: Cleanup Runbook (Jun 2026).
1. What we cleaned
On 23 Jul 2026 the live legacy bucket was pruned (~350 objects
retired). Storefront runtime (scripts/, css/, env configs) already
lives on gs://finmatch-{p,s,t}/. The legacy bucket is only still
needed for merchant snippets that have not been rewritten:
s/scripts/finmatch-sdk.js— canonical snippet entry, published fromfinmatch-sharedbysync-to-gcs.yml{s,p,t}/scripts/finmatch-header-loader.js— router-aware shim
Git tracks only those two files under
finmatch-finance-marketing-assets/. Object versioning stayed on so a
mistaken delete could be restored.
Same-day follow-up in PR #343 (timestamp fix PR #344):
- Stopped
sync-to-gcs.ymlwriting stale duplicates (legacys/p/tbranch triggers,build-info.jsonon the legacy bucket, env-branchscripts/finmatch-sdk.js) - Enabled GCS access logging on the legacy bucket
(
gs://finmatch-usage-logs/, prefixaccess_log_finmatch-finance-marketing-assets__usage_) - Added hourly
legacy-404-watch.ymlso a merchant still requesting a retired URL would show up as a red Actions run plus an email, and the object could be restored from versioning if it was a real dependency
2. What the watch found (24 Jul – 19 Aug 2026)
375 published scans at
gs://finmatch-admin/monitoring/legacy-404-watch/. 316 had zero
404s. The 59 non-zero scans were almost all noise:
| Kind | What it was |
|---|---|
JS crawler (jscrawler/0.1) | Literal template paths such as s/scripts/${baseUrl}aldermore-logic.js |
| Secret scanner | Probes for .aws/credentials, wp-config.php.save, dump.sql, etc. |
| No-referer browsers | Mobile Chrome/Safari with no page referer |
Three real merchant leftovers hit old env-prefixed paths on the
legacy bucket (not gs://finmatch-{p,s,t}/):
| Domain | Retired path | Last seen |
|---|---|---|
revmonkeyuk.com | p/configs/finmatch-ecom-config.json | 25 Jul 2026 |
approvedengines.com | p/scripts/finmatch-utils.js, p/scripts/finmatch-modal.js | 26 Jul 2026 |
escooterclinic.co.uk | t/scripts/*, t/css/finmatch.css | 16 Aug 2026 |
Those 404s are snippet / cached-loader leftovers. Restoring the deleted objects on the legacy bucket would undo the cleanup. The correct fix for a live merchant is the current SDK or header-loader shim, which then loads runtime from the env bucket.
Latest snapshot before retirement (2026-08-19T05:47:45Z): 0 404s
out of 609 rows. Every scheduled run after 17 Aug 05:00 UTC was
green except crawler-overlap leftovers that had already stopped.
The hourly job also crowded the Actions tab: no concurrency group,
last-3-hour overlapping windows, and exit 1 on any 404 including
bots. One crawler sweep painted ~3 consecutive red runs.
3. E-Scooter Clinic (turned off)
E-Scooter Clinic (escooterclinic.co.uk /
www.escooterclinic.co.uk) was the only merchant still hitting
retired t/ paths on the legacy bucket as of mid-August.
The account was turned off in Aug 2026 because invoices were unpaid. Do not treat further 404s from that domain as a restore signal, and do not chase a snippet update while the merchant is off.
If they return as a paying merchant, onboard them on the current
snippet (finmatch-sdk.js or the header-loader shim) so runtime loads
from gs://finmatch-{p,s,t}/, not from retired
finmatch-finance-marketing-assets/{p,t}/scripts|css paths.
4. Why the watch was decommissioned
The precaution window did its job. After four weeks:
- No live paying merchant was still depending on a retired object
- Remaining red runs were scanners
- The one lingering merchant referer (E-Scooter Clinic) is an off-account leftover, not a missing file
The workflow file .github/workflows/legacy-404-watch.yml was
deleted (not left as a disabled cron). Scheduled workflows only
run from the GitHub default branch (finmatch-shared), so merge
stops the hourly job immediately.
After merge, run ./scripts/deploy-workflow.sh --yes from a clean
finmatch-shared worktree so env branches drop the leftover YAML
(rsync --delete). Until that runs, finmatch-{p,s,t} may still
carry a stale copy; workflow-drift-check.yml does not compare this
file, so the leftover is cosmetic.
5. Optional operator follow-ups (not required to retire the watch)
These are GCS / billing hygiene, not Git:
- Access logging — logging on
gs://finmatch-finance-marketing-assetswas enabled only for this watch. Disable it (or shorten retention) if you no longer want hourly objects ings://finmatch-usage-logs/. - Public monitoring JSON — delete or archive
gs://finmatch-admin/monitoring/legacy-404-watch/when convenient. Those snapshots are public (admin bucket stays public; seeSECURITY.md§9.7 Phase 1.5). Do not mix that delete with a Phase 1 file-move PR unless you intend to. - Do not restore the ~350 retired objects from versioning unless a paying merchant is proven to load that exact legacy URL.
Do not reintroduce hourly fail-on-any-404 monitors for this bucket.
If a future prune needs a safety net, use workflow_dispatch or a
weekly scan that ignores known crawler user-agents and no-referer
hits.