Skip to main content

Legacy Bucket Cleanup — Jul–Aug 2026

Status: Complete as of 19 Aug 2026. The hourly Legacy Bucket 404 Watch is retired. Do not restore objects that the July cleanup deleted, and do not re-add .github/workflows/legacy-404-watch.yml.

This page is the history of the July 2026 prune of gs://finmatch-finance-marketing-assets and the short-lived monitor that watched for leftover storefront fetches. It exists so future agents can see why the watch existed and why it was turned off.

The June repository cleanup (ghost mirrors, SDK copies) is a separate record: Cleanup Runbook (Jun 2026).

1. What we cleaned​

On 23 Jul 2026 the live legacy bucket was pruned (~350 objects retired). Storefront runtime (scripts/, css/, env configs) already lives on gs://finmatch-{p,s,t}/. The legacy bucket is only still needed for merchant snippets that have not been rewritten:

  • s/scripts/finmatch-sdk.js — canonical snippet entry, published from finmatch-shared by sync-to-gcs.yml
  • {s,p,t}/scripts/finmatch-header-loader.js — router-aware shim

Git tracks only those two files under finmatch-finance-marketing-assets/. Object versioning stayed on so a mistaken delete could be restored.

Same-day follow-up in PR #343 (timestamp fix PR #344):

  • Stopped sync-to-gcs.yml writing stale duplicates (legacy s/p/t branch triggers, build-info.json on the legacy bucket, env-branch scripts/finmatch-sdk.js)
  • Enabled GCS access logging on the legacy bucket (gs://finmatch-usage-logs/, prefix access_log_finmatch-finance-marketing-assets__usage_)
  • Added hourly legacy-404-watch.yml so a merchant still requesting a retired URL would show up as a red Actions run plus an email, and the object could be restored from versioning if it was a real dependency

2. What the watch found (24 Jul – 19 Aug 2026)​

375 published scans at gs://finmatch-admin/monitoring/legacy-404-watch/. 316 had zero 404s. The 59 non-zero scans were almost all noise:

KindWhat it was
JS crawler (jscrawler/0.1)Literal template paths such as s/scripts/${baseUrl}aldermore-logic.js
Secret scannerProbes for .aws/credentials, wp-config.php.save, dump.sql, etc.
No-referer browsersMobile Chrome/Safari with no page referer

Three real merchant leftovers hit old env-prefixed paths on the legacy bucket (not gs://finmatch-{p,s,t}/):

DomainRetired pathLast seen
revmonkeyuk.comp/configs/finmatch-ecom-config.json25 Jul 2026
approvedengines.comp/scripts/finmatch-utils.js, p/scripts/finmatch-modal.js26 Jul 2026
escooterclinic.co.ukt/scripts/*, t/css/finmatch.css16 Aug 2026

Those 404s are snippet / cached-loader leftovers. Restoring the deleted objects on the legacy bucket would undo the cleanup. The correct fix for a live merchant is the current SDK or header-loader shim, which then loads runtime from the env bucket.

Latest snapshot before retirement (2026-08-19T05:47:45Z): 0 404s out of 609 rows. Every scheduled run after 17 Aug 05:00 UTC was green except crawler-overlap leftovers that had already stopped.

The hourly job also crowded the Actions tab: no concurrency group, last-3-hour overlapping windows, and exit 1 on any 404 including bots. One crawler sweep painted ~3 consecutive red runs.

3. E-Scooter Clinic (turned off)​

E-Scooter Clinic (escooterclinic.co.uk / www.escooterclinic.co.uk) was the only merchant still hitting retired t/ paths on the legacy bucket as of mid-August.

The account was turned off in Aug 2026 because invoices were unpaid. Do not treat further 404s from that domain as a restore signal, and do not chase a snippet update while the merchant is off.

If they return as a paying merchant, onboard them on the current snippet (finmatch-sdk.js or the header-loader shim) so runtime loads from gs://finmatch-{p,s,t}/, not from retired finmatch-finance-marketing-assets/{p,t}/scripts|css paths.

4. Why the watch was decommissioned​

The precaution window did its job. After four weeks:

  • No live paying merchant was still depending on a retired object
  • Remaining red runs were scanners
  • The one lingering merchant referer (E-Scooter Clinic) is an off-account leftover, not a missing file

The workflow file .github/workflows/legacy-404-watch.yml was deleted (not left as a disabled cron). Scheduled workflows only run from the GitHub default branch (finmatch-shared), so merge stops the hourly job immediately.

After merge, run ./scripts/deploy-workflow.sh --yes from a clean finmatch-shared worktree so env branches drop the leftover YAML (rsync --delete). Until that runs, finmatch-{p,s,t} may still carry a stale copy; workflow-drift-check.yml does not compare this file, so the leftover is cosmetic.

5. Optional operator follow-ups (not required to retire the watch)​

These are GCS / billing hygiene, not Git:

  1. Access logging — logging on gs://finmatch-finance-marketing-assets was enabled only for this watch. Disable it (or shorten retention) if you no longer want hourly objects in gs://finmatch-usage-logs/.
  2. Public monitoring JSON — delete or archive gs://finmatch-admin/monitoring/legacy-404-watch/ when convenient. Those snapshots are public (admin bucket stays public; see SECURITY.md §9.7 Phase 1.5). Do not mix that delete with a Phase 1 file-move PR unless you intend to.
  3. Do not restore the ~350 retired objects from versioning unless a paying merchant is proven to load that exact legacy URL.

Do not reintroduce hourly fail-on-any-404 monitors for this bucket. If a future prune needs a safety net, use workflow_dispatch or a weekly scan that ignores known crawler user-agents and no-referer hits.