Skip to the content
Georgi DimitrovdaTuzzo

Tuzzo Music

A hi-res music player for one household, hardened by a verifying agent fleet

Role
Product owner, directing agent fleets
Status
Live
Source
Private repository
Stack
Next.jsTypeScriptPrismaPostgresCapacitorNetlifyVitestTailwind
The Tuzzo Music app icon: a stylised sound waveform with a small play triangle in the middle, inside a round dark metal disc with a teal glow.
The app's own icon.

In numbers

24-bit / 96 kHz

FLAC delivered straight to the browser from a signed CDN URL on the first probe; the quality badge reads back the delivered format

0

bytes of audio relayed through my server

4

independent causes of queue desync closed, with one reducer case as the shared mechanism

The problem

The backend had been through three providers: a community API, community-run workers and then a paid subscription. Both community backends were fragile in the same way, and the player's queue desynchronised for four independent reasons.

The approach

I put the provider behind a seam, moved to the paid subscription and ran a hardening campaign: two sweeps of finder and adversarial-verifier agents, then parallel blueprint-then-build lanes in isolated git worktrees, with a test lane pinning what the sweeps found.

How it works

  1. A provider seam, and audio that skips the server

    IDs are namespaced by provider, so older rows keep resolving after a migration. The server holds one shared token, signs the file-URL request and hands the browser a signed CDN URL for native FLAC. The quality badge reads back the delivered format code, so it reports what arrived. A cold-start bug found along the way, an initialisation step that downloaded about 9 MB and blew the serverless time limit, was fixed on the spot.

  2. A closed API switch and a CI auth check

    The provider API sits behind a closed, enumerated switch, with no slug relay. A CI script fails the build when any route under app/api neither calls an auth helper nor sits on an allowlist.

  3. Find, then verify

    Two sweeps of 12 and about 13 agents paired finders with adversarial verifiers. 58 findings survived the first and 133 the second, 191 in total. The output was copied somewhere durable because it lived in a session temp directory.

  4. Lanes that refuse to guess

    Lanes worked in isolated worktrees (player core, shell UX, data provider, discovery, player UI). The discovery lane declined to build on endpoints it could not confirm and filed a probe request instead. Four independent causes of queue desync closed in the player-core lane, with one reducer case as the shared mechanism.

  5. A merge rule that was only a rule

    Auto-merge relied on do-not-merge-on-red as an honour rule. A lane merged with a red check because the repository had no required status checks, and CI did not build the app until a later change added a build step. The test lane then pinned the invariant violations as executable assertions, 65 tests on main by the end of the campaign.

  6. QA in a real browser

    Four QA lanes ran against production with separate minted accounts. At my insistence the lead cross-checked in my real Chrome through the browser extension, with a disposable account deleted afterwards, instead of trusting a headless harness.

What I chose, and what lost

Chose

Signed CDN URLs fetched by the browser

Over

Streaming audio through the server

It keeps the app serverless-friendly and made hi-res work on the deployed site; the first probe delivered 24-bit audio at 96 kHz.

Chose

A paid subscription behind a seam

Over

Community HIFI workers and the earlier community API

Both community backends were the same class of fragile.

Outcome

The player is live for one household behind a login. The provider API is unofficial, which the README states, so I keep the player private and unlinked. A blueprint for a bit-perfect desktop client exists only as a document.