Circuit Breaker: The Reporting Pipeline Can Be Shut Off Anytime
Imagine one day HQ discovers a data reporting channel at one of its branches has a problem. There's no need to send someone to that branch — they just shut down that channel from HQ's backend, effective within minutes. The front-counter display reporting and the membership system backend reporting can be switched off independently without affecting each other.
Claude Code has this same "HQ remote shutoff" capability. src/services/analytics/sinkKillswitch.ts reads a remote config to determine whether each backend is enabled:
// src/services/analytics/sinkKillswitch.ts
const SINK_KILLSWITCH_CONFIG_NAME = 'tengu_frond_boric' // Obfuscated config key name
export function isSinkKilled(sink: SinkName): boolean {
const config = getDynamicConfig_CACHED_MAY_BE_STALE<
Partial<Record<SinkName, boolean>>
>(SINK_KILLSWITCH_CONFIG_NAME, {})
return config?.[sink] === true
}
tengu_frond_boric is a deliberately obfuscated key name ("tengu" is Claude Code's internal codename). The full name looks like a meaningless word combination, preventing outsiders who discover the key name from trying to trigger it. The sink config structure is { datadog?: boolean, firstParty?: boolean } — the two backends can be shut down independently.
Fail-open: If this config doesn't exist or its format is wrong, the sink stays open — just like when HQ can't reach a branch, the branch defaults to staying open rather than shutting down. The worst case if a data pipeline has issues is that a bit too much data gets recorded; but if all events are silently discarded because of a config format error, the product team would be completely blind to user behavior — which is far more dangerous.