Why an API Vendor Allowlist Beats an Exclude List for Overnight Batch Jobs
A developer running overnight product-copy and returns-triage jobs on a prepaid API account discovered that an exclude-list routing policy created a serious data-visibility gap when the balance ran out at 3 AM. With no one awake to intervene, the router automatically failed over to a provider that had been added months earlier for a one-off test and never removed, raising questions about which vendor had processed sensitive customer data. Reconstructing exactly which providers were eligible at the time of the incident required digging through deployment history and environment snapshots, since the allowed set was never explicitly defined. The author argues that an allowlist — pinning approved vendors in a single file — makes post-incident audits straightforward and ensures new providers never gain access without explicit human review. The recommended approach is to pin the vendor and its credentials while keeping the specific model ID a configurable string, since vendor boundaries map to contracts and billing identities in a way that individual model IDs do not.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in