首页 / Skills / 开发提效 / 追问到底 Grilling
开发提效

追问到底 Grilling

Matt PocockMITSkill 语言: 英文
协议已核对不含脚本
演示真实运行记录 · claude-opus-5-5 · 2026年10月
Grill me on this plan before I start building it. We want to move our nightly cron jobs (invoice generation, the email digest, and the CSV data exports) off the single cron server and onto a Redis-backed BullMQ queue, with 3 worker containers on our existing Kubernetes cluster. I'd like to ship it within two weeks.
Skill: grilling

I don't see a codebase in this directory, so this round is based only on your description. If the repo lives somewhere else, point me to it and I'll look up the facts myself.

Round 1. These questions don't depend on each other, so you can answer them in any order.


❓ Q1 - What's actually broken today?: Which of these is driving the move?

  • (a) The cron server is a single point of failure, so if it dies, nothing runs.
  • (b) Jobs take too long or overrun their window and need parallelism.
  • (c) The box is a pet server you want to get rid of.
  • (d) You want retries and visibility into failures.

This decides most of what follows. If it's (a) or (c), a Kubernetes CronJob running the existing scripts unchanged could get you there in 2–3 days, with no Redis and no queue. BullMQ only pays off if you need (b) or (d).

➡️ I suspect it's mostly (a) plus (d). If that's right, a queue is defensible, but you should be able to say why plain k8s CronJobs aren't enough.


❓ Q2 - What triggers the nightly runs?: A queue doesn't schedule anything by itself. Something has to enqueue the jobs at 2am. Options:

  • (a) BullMQ repeatable jobs / job schedulers, defined in code
  • (b) A k8s CronJob that enqueues the jobs and exits
  • (c) The workers enqueue on startup

With (a), the schedule lives in Redis. If you redeploy with a changed cron pattern, the old schedule can linger and fire twice unless you upsert by a stable key.

➡️ (a), using upsertJobScheduler with fixed scheduler IDs, so the schedule is versioned in code and stays idempotent across deploys of all 3 workers.


❓ Q3 - Is invoice generation safe to run twice?: BullMQ guarantees at-least-once delivery, not exactly-once. A worker that gets OOM-killed or evicted mid-job, or misses its lock renewal during a long CPU-bound loop, will have its job marked stalled and picked up by another worker. If invoices get created and emailed twice, customers get billed twice. The same applies to the digest: a duplicate digest is embarrassing but not costly.

What happens today if the invoice script runs twice for the same night?

➡️ Before migrating, make each unit idempotent with a DB uniqueness key such as (customer_id, billing_period) and an "already sent" marker for emails. This is the main thing that has to be in place before launch.


❓ Q4 - Which Redis, and how is it configured?: Is there an existing Redis you plan to share (cache or sessions), or a new one? BullMQ needs maxmemory-policy noeviction. A cache Redis with allkeys-lru will quietly evict job data. Also: is persistence (AOF) turned on, and what happens to the queue if Redis restarts at 2:05am?

➡️ Use a dedicated Redis instance (managed, or a small StatefulSet with AOF), configured with noeviction, and keep it separate from any cache.


❓ Q5 - Where do the CSV exports go?: Containers have ephemeral filesystems. If today's export writes to /var/exports on the cron box, or something reads files from there over SFTP or rsync, that path disappears. Who consumes these files, and how do they get them?

➡️ Write to object storage (S3/GCS) and give consumers a bucket path or signed URL. If an external party pulls the files from the cron box, that's a separate migration to coordinate with them.


❓ Q6 - What does the cron server do that nobody listed?: Old cron boxes usually pick up extra crontab entries, things like log rotation, someone's backup script, or a cleanup find -delete. They also tend to have implicit setup like the timezone (TZ), local credentials, and mounted drives. Have you diffed crontab -l for every user, plus /etc/cron.d, against these three jobs?

➡️ Do a full audit before scoping. Anything left over gets either an owner or an explicit decision to drop it, so it isn't lost when the box is decommissioned.


❓ Q7 - How do you cut over without running jobs twice or zero times?: Options:

  • (a) A hard switch on a given night
  • (b) Shadow mode: the new system runs with side effects disabled and you compare outputs
  • (c) Migrate one job at a time, CSV first, then digest, then invoices last

➡️ (c), starting with the CSV exports because they're lowest-risk, and leaving invoices for last, after a shadow comparison. That also makes two weeks realistic. Moving all three at once, invoices included, in two weeks is the part of the plan I'd push back on hardest.


Answer whichever of these you have opinions on. Your answers, especially to Q1 and Q3, will set up the next round, which covers job granularity, concurrency and rate limits, failure alerting, and worker resource limits.

Real run recorded with claude-code / claude-opus-5-5. Output is shown verbatim, unmodified.

它做什么

让代理对你的计划、决定或想法进行不留死角的追问。它把计划画成一棵决策树,每个决定后面挂着依赖它的下一批决定,一直问到没有任何事被默默当成前提。

工作方式

  1. 把当下就能回答的问题编号,一轮全部提出,每个问题都带一个推荐答案。
  2. 等你回答后,重新计算哪些问题被解锁,再问下一轮。
  3. 事实类的信息(文件、工具里能查到的)由代理通过子代理自己去查,不拿来问你;只有决定才交给你。
  4. 没有遗留问题时才算结束,而且在你确认双方理解一致之前不会动手执行。

适合场景

在开工前检验迁移、架构或功能方案是否经得起推敲。

需要了解

这里收录的是可复用的追问核心。作者那两条只有一行的 grill-me、grill-with-docs 命令,就是调用它。

说明与风险

纯指令文件:没有脚本、不联网。 它可能让代理启动子代理去读取你的项目文件来查证事实。 压缩包里另有原仓库的 MIT 协议文件 LICENSE 和 agents/openai.yaml(供 Codex 使用的显示名)。