Partner pack

Engineering Partner Onboarding

Artifacts for bringing an engineering partner up to speed on Timed Trading. Prefer accuracy over polish; unknowns are marked.

Front door for newcomers: Newcomer Repo & Workers Guide (repo layout, which worker runs what, local run, first-week checklist).

Repo sources of truth (do not duplicate wholesale):

DocWhy
AGENTS.mdOnboarding contract, house rules, local Cloud tips
CONTEXT.mdStack, journey pages, condensed lessons
skills/README.mdHow-to index
skills/worker-topology.mdCron / role ownership
skills/deploy.mdDeploy decision tree; merge ≠ deploy
skills/security-auth-patterns.mdRoute / WS / tier gating
skills/partner-onboarding.mdBroker partner isolation (product partners)
skills/user-state-matrix.mdPro / VIP / Member / Admin states
.cursor/rules/price-data-pipeline.mdcPrice KV + freshness invariants

1. System architecture

Rendered diagram

Timed Trading system architecture

Local asset: assets/system-architecture.svg

Flow (text)

Clients (Browser → CF Access → Stripe)
        │
        ▼
Cloudflare Pages (react-app-dist/ + _worker.js)
        │  proxy /timed/*
        ▼
timed-trading-ingest (worker/) — ALL /timed/* · DOs · fallback crons
        │
   ┌────┼────────────────────┐
   ▼    ▼                    ▼
tt-feed  tt-engine       tt-research   (same bundle, role-gated)
   │         │                │
   └────┬────┴────────────────┘
        ▼
   D1 + KV (+ PriceStream WS → TwelveData; PriceHub → Browser)

tt-broker-bridge (worker-bridge/) ← /timed/broker/* session owner
        │
   Alpaca / IBKR / Webull / Robinhood / E*TRADE scaffold

External: TwelveData · Discord · SendGrid / OpenAI · Stripe

Component cheat sheet

PieceScript / pathNotes
Main APItimed-trading-ingest ← worker/Only place that owns DO classes/migrations
Feedtt-feed ← worker-feed/After cutover: price feed + keep-alive
Enginett-engine ← worker-engine/*/5 scoring + trade lanes
Researchtt-research ← worker-research/Hourly arms + 22:00 UTC batch
Bridgett-broker-bridge ← worker-bridge/Sidecar; no end-user CF Access auth
FrontendPages ← react-app-dist/Independent deploy from workers
QuotesTwelveData (+ Alpaca fallback/exec)Native change fields preferred
AlertsDiscordSee skills/discord-alerts.md
Billing / SSOStripe + CF AccessSee user-state-matrix + billing skill

Unknown until checked in dashboard/prod: which *_EXTERNAL / *_ENABLED flag pairs are currently live. Do not assume cutover state from docs alone — probe health / Cloudflare vars.

2. Newcomer material (summary)

The full day-1 / first-week guide lives in the newcomer guide. It covers:

Reading path for a new senior engineer:

AGENTS.md → CONTEXT.md (Stack/Deploy) → skills/README.md → skills/worker-topology.md → skills/deploy.md → this pack’s architecture section.

3. Deploy topology (partner-facing)

ChangeDeploy
worker/** (shared logic)Monolith both envs and tt-engine + tt-research
worker/feed/**tt-feed as well
worker-bridge/**Bridge worker only
react-app/**npm run build:frontend, commit dist, push main (Pages)

CI workflows (path-filtered): deploy-worker.yml, deploy-feed.yml, deploy-engine.yml, deploy-research.yml.

A merge is not a deploy. Verify Cloudflare version dates or /timed/health deployedSha. Stamp ENGINE_GIT_SHA on hand deploys. Details: skills/deploy.md.

4. Auth, tiers, security boundaries

Entitlements

WhoLive prices + scores
Pro / VIP / AdminYes
Member (free) / anonNo — redacted

Server gate: canAccessLivePrices() / redactTickerMapForTier(). UI: window._ttIsPro. Canonical states: skills/user-state-matrix.md.

Route / trust boundaries

BoundaryRule
Mutating admin routesrequireKeyOrAdmin (+ destructive confirm when irreversible)
Licensed market dataServer-side tier redact; cache keys include tier bucket
CF Access JWTFail closed (verifyAccessJWT); no “degrade gracefully” on assertion headers
API keyPrefer X-API-Key; ?key= deprecated
WebSocketsTicket flow: /timed/ws-ticket then ?ticket= (browsers can’t set upgrade headers)
Broker bridgeBrowser never hits bridge directly; /timed/broker/* stamps owner from session email
LLM HTMLSanitize (DOMPurify); treat model output as untrusted

Full patterns: skills/security-auth-patterns.md. Broker tenant isolation: skills/partner-onboarding.md.

Discord / Stripe / Access (placement)

5. Price pipeline invariants (pointer sheet)

Do not re-implement. Read .cursor/rules/price-data-pipeline.mdc and CONTEXT lessons tagged PriceStream / q_ts.

Non-negotiables for a partner touching feed or UI prices:

  1. TwelveData primary; parse native quote change fields (parseTdQuote).
  2. Client daily change only via getDailyChange(t) in shared-price-utils.js.
  3. Every timed:prices writer stamps q_ts + p_ts and never regresses them.
  4. Freshness / health use value stamps, not blob t.
  5. PriceStream DO ownership of symbols in timed:prices (orphan clobber risk under KV lag).
  6. Session-aware EXT fields: no AH writes during RTH; preserve closed-session day/EXT appropriately.
  7. Licensing footer: “Market data powered by Twelve Data”.

6. Skills index (common tasks)

SituationSkill
Deploy / verify liveskills/deploy.md
Which worker / cronskills/worker-topology.md
Rescore one tickerskills/rescore-ticker.md
Snapshot / universeskills/all-snapshot.md
D1 / KVskills/d1-debugging.md, skills/kv-inspection.md
HTTP codesskills/debug-http-codes.md
New route / WSskills/security-auth-patterns.md
Broker automationskills/broker-bridge.md
Onboard a trading partner (Webull mirror)skills/partner-onboarding.md
Frontend buildskills/frontend-build.md
Holistic smokeskills/mc-holistic-smoke-test.md

Complete list: skills/README.md.

7. Partner onboarding checklist

Use this when an engineering partner joins (code access). For a broker-mirror product partner, use skills/partner-onboarding.md instead (different isolation model).

Access & tooling

Engineering ramp

First production-adjacent change

Security review before self-serve prod writes

8. Files in this pack

FileRole
newcomer.html (from docs/newcomer-repo-workers-guide.md)Primary day-1 / first-week guide
This page (from docs/engineering-partner-onboarding.md)Architecture + partner checklist
assets/system-architecture.svgArchitecture visual

Changelog