The payroll journal writer had never once run to completion, so no payroll had ever reached the ledger. And a production deploy that does not actually move the code is now a failed build.
A Deploy That Does Not Move the Code Is Now a Red Build
Three production deploys reported success over a checkout that never moved: a stale local edit made the code update abort, the pipeline carried on regardless, ran the database upgrade against the old code, restarted every service and printed “updated” — a line that was never conditional on the update having worked. Four releases, including a security fix, sat undeployed with no signal anywhere.
The step now refuses instead of silently skipping: a failing command fails the stage, a modified tracked file is a named failure with the file list and the remedy, the checkout must be on the release branch, a diverged checkout is refused rather than quietly merged, and the deployed commit is asserted against the release afterwards. The closing summary now reads the deployed commit and version back off the server instead of asserting what the pipeline intended.
A Payroll Run Now Produces a Journal
Three separate errors in the journal writer, each of them fatal, meant the posting had never once completed: the currency was assigned as a plain code where the ledger expects a currency record, the reference was written to a field that does not exist, and the journal lines were created against the wrong field name and without their line numbers.
All three are fixed, the entry’s total is set from the debit side rather than left at zero, and the lines are numbered debits first so the entry reads the way it would be written by hand. Verified end to end on a real run: a balanced journal in the right period, with its posting log recorded.