Publish the architecture that exists, rather than provisioning a host to make a false sentence true
Decided
sandbox.api.novelsystems.ca was published by the hosted developer docs as a base endpoint and does not resolve. It was removed from the docs. It was not provisioned, and the DNS record was deliberately not created.
The alternative, and why it was rejected. Provisioning the host is a DNS record and twenty minutes, and four separate documents in this repository — the audit, the status file, the claims register and the task list — all recorded that as the fix. All four were wrong.
There is no separate sandbox deployment behind the backend, no weekly reset job and no nsk_test_ key issuance. A host named "sandbox" could therefore only have pointed at production. The published page describes an environment that mirrors production and resets weekly; making the host resolve would not have made that sentence true, it would have made it *unfalsifiable at the DNS layer*. The developer who currently fails at step three with a DNS error would instead succeed, write test data into the live database, and expect it to disappear on Sunday. Removing the error message would have removed the only signal that anything was wrong.
The general form. A false published claim can be corrected in two directions: change the world to match the claim, or change the claim to match the world. The first is usually the more impressive-looking and is occasionally right, but it is only right when the thing being built is independently worth having. Here it was not — nothing wanted a second deployment; the seeded-tenant design is arguably the better one, because the row-level isolation exercised in the sandbox is the same isolation running in production. Building infrastructure whose sole purpose is to retroactively justify a sentence is how a documentation defect becomes an architecture defect.
What was actually wrong was narrower and duller: docs-site/*.md had been correct for some time, and the hosted GitBook copy had never been republished from it. Three pages replaced from source, nine drifted claims gone.
What would have to change for this to be wrong. If a real isolated sandbox environment is ever wanted on its own merits — separate database, real weekly reset, its own key issuance — then build it and publish it, and the host name becomes true rather than merely resolvable. The test is whether it would be built if the docs had never mentioned it.