Fail closed.
Unknown destinations are denied inside the twin, and an unverified golden cannot be branched.
Give your coding agent a production twin through MCP. Test migrations, user flows, and load on masked data, then use the findings to fix the change before you ship.
Isolated TwinYour stack, isolatedfor each change.
Safe StateMasked Postgres.Relationships intact.
Side-Effect FirewallTest payments and mail.Contain external calls.
LoadYour traffic mix.Against the new build.
Migration SafetyLocks, rewrites, plans.Before you deploy.
Follow a schema change from pull request to rehearsal. See the lock it holds, the finding it produces, and the environment being removed.
While this lock is held
Antifailure finding
Table rewriteThe type change rewrites the orders table under an ACCESS EXCLUSIVE lock. Reads and writes to orders wait until PostgreSQL releases it.
Sampled lower bounds on the demo database.
What the agent receives
The MCP result carries the finding, measured lock, and evidence. Your agent has something concrete to fix before merge.
The type change rewrites orders under an ACCESS EXCLUSIVE lock. Reads and writes wait while it is held. The recorded demo measured a lock on orders for at least 10.5 seconds.
Add a new bigint column, backfill in batches, cut over reads and writes, and remove the old column later. This is a proposal, not a passing result. Rehearse the revision before merge.
An isolated copy of your app for each change.
antifailure/demo-orders
| Environment | Branch | State |
|---|---|---|
| demo-orders-default-side-eff-e3aa26 | Branch: default (side-effect baseline)#1 | Torn down |
| demo-orders-default-27b977 | Branch: default#1 | Torn down |
| demo-orders-drop-the-per-mer-faeda1 | Branch: drop-the-per-merchant-scope-on-order-reads | Failed |
Each twin has its own network. Gateway policies control which external services it can reach.
Use test credentials and route payments, messages, and other external calls through your test policies.
Review the teardown record to see which tracked resources were removed.
Unknown destinations are denied inside the twin, and an unverified golden cannot be branched.
The route mix out of your own access log, with the worst regression first.
A gate on the pull request carrying the rows and the trace behind it.
// The application. Antifailure needs no import in it. export default async function handler(req, res) { const subs = await db.query( "select * from subscriptions where account_id = $1", [req.accountId], ); res.status(200).json(subs); }
Three commands. af init reads the repository and writes the manifest, af up builds the twin around a branch of the golden, af test runs the workflows and returns verdicts with evidence. With a production database, af golden refresh once before af up.
terminal$ af init $ af up $ af test # verdicts, with evidence
Try for yourself, start proving a change before it ships.
ExampleExample project using the Antifailure CLI.
Your application tries to reach
api.stripe.com
POST/v1/charges
amount 49.00 USD
The request reaches the twin's egress policy before it can leave.
Policy decision
MockThe app receives a simulated payment response from the local pack. The real processor never receives this test charge.
Your agent sees the policy decision and observed counts through inspect_egress_firewall.
A POST to api.stripe.com receives a local simulated response. The test checkout continues without a real processor charge.
A POST to api.sendgrid.com is retained in the test inbox. The message can be inspected without sending it to a customer.
A POST to the unlisted api.prod.internal host matches no rule. The default block policy refuses it before it can touch the live service.
Keep production data in your cloud while your team reviews results in the control plane.
Explore the data boundary →Replace customer details and credentials before a test environment uses the database. A signed attestation records the masking checks.
Choose sandboxes, mocks, or captured messages for each integration. The gateway blocks destinations you have not configured.
Every created resource is recorded in a journal. Cleanup uses that record to remove the environment and report the outcome.
Antifailure + your coding agent
See Antifailure rehearse a change from your stack. Review the findings, then decide what to ship.