# Deployment checks: 4 October 2026

The public API was checked directly using curl and Python's HTTP client. Console/source pages returned HTTP 403 with a Cloudflare access challenge. No challenge bypass was attempted. The upstream returned HTTP 200 Atom XML. Public feed and individual alert responses were inspected, including conflicting suffix/Accept requests. Recorded response metadata is in `live-results.json`; transient warning bodies and challenge pages are not bundled.

## Findings that differ from the original talk brief

1. The reflector collection's XML is **RSS**, served as `application/rss+xml` for the unsuffixed negotiated URL. It is not one CAP document. `Accept: application/cap+xml` on that feed returned **406**. Individual reflected alerts did return `application/cap+xml`.
2. Suffixes are **fixed formats** in the deployed routes. `.xml` returned XML with a conflicting HTML preference, and `.html` returned HTML with a conflicting CAP/XML preference. `Accept` selects the **unsuffixed** resource. Do not describe this deployment as `Accept > suffix > default`.
3. Responses demonstrate negotiation, not which rendering implementation ran. Approved/cached publisher XSLT and default renderer capabilities were confirmed by source inspection, not inferred from the Mexico HTML.
4. No assertion of automatic runtime-error fallback: local code uses a default when no approved stylesheet is selected, while transformation failures need a separate handling policy.

## Reproduce

```sh
REFLECTOR='https://ah-node-v2.api.alerting-apps.net/public/reflector/mx-smn-es'
curl --max-time 20 -i -H 'Accept: text/html' "$REFLECTOR"
curl --max-time 20 -i -H 'Accept: application/rss+xml' "$REFLECTOR"
curl --max-time 20 -i -H 'Accept: application/xml' "$REFLECTOR"
curl --max-time 20 -i -H 'Accept: application/cap+xml' "$REFLECTOR"
curl --max-time 20 -i -H 'Accept: */*' "$REFLECTOR"
curl --max-time 20 -i -H 'Accept: text/html' "$REFLECTOR.xml"
curl --max-time 20 -i -H 'Accept: application/xml' "$REFLECTOR.html"
```

Pick an **individual reflected alert URL** from the current RSS/HTML feed and set `ALERT_URL` to that URL. Historical identifiers may expire.

```sh
curl --max-time 20 -i -H 'Accept: application/cap+xml' "$ALERT_URL"
curl --max-time 20 -i -H 'Accept: text/html' "$ALERT_URL"
curl --max-time 20 -i -H 'Accept: text/html' "$ALERT_URL.xml"
curl --max-time 20 -i -H 'Accept: application/cap+xml' "$ALERT_URL.html"
```

The historical sample UUID is recorded in `live-results.json`. Set variables in your own shell; the snippets intentionally do not contain an automatically chosen alert that could later disappear.

Recheck before speaking. If behaviour changes, update the article, slide 10, corresponding presenter notes and this record together. Never change deployment code merely to make a case study match its planned narrative.
