Build1 distinct publisher3 min readUpdated
A two-person CODEOWNERS gate on every infrastructure path bought a brake on risk and paid for it in other people's queued work. The arithmetic is not close.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
Four approvals were not four approvals. CODEOWNERS does not count reviewers, it matches paths to named accounts, so a pull request can collect any number of passes and stay blocked until one specific person clicks [5]. With two names on most infrastructure paths, one lead in a meeting removes half the approval capacity and two leads in the same meeting removes all of it [20]. The billing-export change had the reviewers it needed by any reasonable reading and still needed a fifth, particular signature [21].
Now the ledger the rule actually produced. Thirty-one pull requests each waiting more than two business hours is a floor of 62 business hours of blocked work in a ten-weekday window [7][17]. The incident that motivated the rule was an S3 bucket policy left too open for 47 minutes [6]. That is a ratio of roughly 79 to 1 [18]. Wait time and exposure time are not the same unit, and nobody should pretend a blocked dependency bump is as bad as an open bucket. But the rule was sold internally as a brake [6], and the only quantity it demonstrably generated was hours of other people's stalled work.
The composition of that queue is thinner than it looks. Nine dependency bumps, six fixes to alerts that were already paging, and the timeout account for 16 of the 31 [8][19]. The other 15 are unlabelled, which means the documented sample is the harmless end and the real distribution is unknown even to the team that ran the gate.
One detail in the correction says more about review quality than the ownership map does. The team pinned terraform 1.8.5 in .tool-versions on 2026-08-18 because tool drift had been supplying fake disagreement in plan output [14]. Some fraction of the queue's dwell time was therefore spent arguing about diffs generated by different binaries, not about consequences. A one-line version pin plausibly bought more scrutiny than a named approver did, and it cost nobody a wait.
What replaced the broad rule is narrow: service operators own their own paths, and lead review survives for identity, network boundaries, account creation and production deletion paths [12], with a risk:high label carrying one lead approval instead of treating every YAML file as equivalent [13]. The team is explicit that this only held because service owners already had production access and knew their rollback paths, and that it is untested above 40 engineers or in a company with three separate compliance teams [15]. That is the honest boundary on the whole story: this is a fix for 26 services and four node pools [16], not a policy.
The failure underneath is measurement. A broad path rule feels like governance because it produces approvals, and an approval count tells you nothing about whether scrutiny was added [11]. The team ran that rule for six months and needed three hours of digging to find out what it had done [4].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
At 11:42 on Monday, the billing-export pull request had four approvals, one frustrated staff engineer, and no merge.
The diff changed a retry timeout from 30 seconds to 45 seconds; nothing in it was controversial.
Repository rules required a platform lead to approve anything touching infra/, and both platform leads were in a quarterly planning meeting.
The team wrote the rule six months earlier and then spent three hours discovering what it had actually done to the team.
@platform-leads was placed in CODEOWNERS for most infrastructure paths, so any Terraform module, Kubernetes manifest, Helm chart or GitHub Actions workflow waited for one of two people.
The rule was introduced after the team hired three engineers who had not worked with its AWS accounts and after a state-lock incident left an S3 bucket policy too open for 47 minutes; the team wanted a brake.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source, self-reported, unverifiable
Everything rests on one first-person dev.to retrospective. The configuration snippets and the terraform pin date are concrete and internally consistent, but the load-bearing quantities (31 delayed pull requests, the 47-minute S3 exposure, the 40-engineer ceiling) are self-reported with no artifact, dashboard or second publisher to corroborate them, and 15 of the 31 delayed changes are never described.
One team's internal change; no external uptake
Adoption evidence is limited to the reporting team itself: an ownership-map rewrite, a risk:high label and a pinned terraform version, all inside a single organisation of at most 40 engineers. No other team, product or vendor is shown adopting the pattern, and the author states the approach has not been tried at larger scale or under multiple compliance teams.
Mildly overstated generalisation, self-limited
The framing - that broad path ownership only manufactures approvals - is broader than an n=1 twelve-day sample can carry, and the headline arithmetic (62 blocked business hours versus a 47-minute exposure) compares a floor estimate against a single incident window while ignoring incidents the gate may have prevented. The gap stays small because the author volunteers the scope limits and reports the failure as his own.
Audience-building practitioner post, no product on sale
The piece is a DevOps-branded dev.to post whose incentive is practitioner credibility and reach: a confessional 'mistakes we shipped' format that rewards vivid, quotable failure narratives and tidy before/after code blocks. No vendor, funding round, pricing change or commercial offering is promoted, and the named tools (GitHub, Terraform, Kubernetes, PagerDuty) are incidental infrastructure rather than pitches.
Low-moderate
Confidence is limited by the single-publisher base and unverifiable internal metrics, but raised somewhat by the specificity and internal coherence of the account: dated configuration changes, quoted CODEOWNERS before and after, a named tool version, and explicit acknowledgement of what the team has not tested.
build
Partition, not consolidation: what a 43-minute Jenkins queue actually cost1 distinct publisher
build
A NetworkPolicy in another repo broke invoicing while every dashboard reported success1 distinct publisher
build
Send kills, not scores: the leaderboard fix that turns anti-cheat into a schema decision1 distinct publisher
build
A year without sprints: nine engineers, 36 services, and a WIP cap of eight graded B1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 21, 2026