AIRANKS — The Authoritative Rankings for AI Web Content

AIRANKS measures AI visibility: we ask AI models real product and service questions, capture the complete answers as immutable observations, and publish what they contain — which brands were mentioned, which domains were cited, and which exact pages were linked. Every domain gets an AIR score from 1–10 (a decile of visibility in the active dataset; 0 means insufficient data), with the methodology in the open.

AIR

BLOG

Skip to main content

the ledger notes

The council and the cutover

Build LogAugust 12, 2026 by Jeremy Schoemaker

Launch is Monday. The plan was to move airanks from the house to AWS over the weekend, and instead of trusting one model's architecture doc (mine), we convened the matrix council on it: six seats, five frontier models, a chair with tools, and a standing rule that a claim labelled VERIFIED is itself just a claim until someone runs the command.

The plan going in: split-plane hybrid. AWS gets what launch traffic touches — web, API, RDS, a $12 ElastiCache node. The house keeps what launch traffic never sees — the Pi collectors, the Macs, SearXNG, a 100GB archive — connected over Tailscale. $134/mo. The owner settled two questions mid-session from the peanut gallery ("if this is this cheap then ill buy it" bought ElastiCache; "I run everything in us-east-1" picked the region) which is exactly how a council should interact with an owner: they rule, it records.

Round one produced a fear with real teeth: three seats argued RDS would force a MariaDB downgrade — production runs 12.3.2, and everyone "knows" RDS lags on LTS versions. One seat labelled it VERIFIED. The chair ran aws rds describe-db-engine-versions and the list ended with 12.3.2. The exact version, sitting right there. The VERIFIED claim was falsified, the member retracted, and an hour of downgrade-compatibility planning evaporated. A claim's label is a claim.

Same round, same pattern, smaller stakes: "the WAN worker path is unmeasured" died against five TCP connects from the actual home network (median 62ms against Horizon's 3-second polling), and "DNS propagation is risky" died against dig NS showing Route53 already authoritative.

But the council earned its fee on the runbook. Seraph — the verifier seat, motto "I protect that which matters most" — declined to certify the Sunday cutover on argument and produced six concrete breaks, every one of them real: the TLS cert can't be issued via HTTP-01 while DNS still points at the old box (DNS-01 or an HTTPS gap at flip); the Mac's five-minute rsync loop would keep deploying new code onto the frozen-schema fallback server (a silent mismatch waiting 72 hours to matter); a single in-flight LiveSearch job can run 16 minutes against a 30-minute window, so you stop accepting new ones at T−20 rather than "draining"; the generation-key cache is cold at flip, converting launch-morning 304s into a full-body 200 storm unless pre-warmed; the hourly binlog-ship control — bought with real pain on 2026-08-08 — had no named successor and would have silently lapsed; and a dead tailscale daemon would let the site look healthy while search jobs queued into timeouts. Six for six, adopted verbatim into the runbook.

His best line settled the Multi-AZ debate in one sentence: "Multi-AZ replicates a DROP SCHEMA faithfully and instantly." The incident we actually had isn't insured by a standby replica — it's insured by point-in-time recovery, which costs nothing extra on Single-AZ. Multi-AZ stays a day-2 checkbox.

Final tally: every architecture question consensus or owner-settled, eight retractions on evidence, and the runbook certified conditionally — on Saturday's dress rehearsal returning a green checklist with named measurements, including the one number nobody has: how long a real PITR restore takes, which is the actual RTO, not the 10-second local dump restore everyone was quoting. If the rehearsal fails, Monday launches from the house, which works today, and the migration slips a week. The launch was never allowed to depend on the migration.

The meta-lesson, twice in one day (the JSON-LD product research pulled the same trick this afternoon): the cheap check beats the confident consensus. Six models agreed the version risk was real. The list of versions was one CLI call away the whole time.

← Back to blog