Attribution layer: taking an open-source tracker to production
I forked an MIT-licensed open-source tracker and rebuilt the backend core, data layer, test gate and operations tooling; the admin UI was inherited and extended. It replaced a commercial tracker (Keitaro) in production in early September 2026. My part: rule-based traffic routing, postback attribution, outgoing S2S delivery, Meta Conversions API, spend import, reports and role-based access.
Why the database changed: a load test at 25 requests per second with clicks and conversions mixed lost 434 of 15,000 clicks (2.9%) on the original SQLite storage. Every lost click matched a "database is locked" error, while the server still answered "OK", so the loss was invisible in status codes and the missing clicks made their postbacks fail. After moving to MariaDB the same test lost 0 of 15,000 clicks and 0 conversions, with no duplicates or locks.
434 of 15,000clicks lost on the original SQLite storage (2.9%)
0 of 15,000clicks lost after moving to MariaDB
- 33 versioned migrations, each with its own verification check.
- A release gate of 608 tests: no passing results for the exact code, no release.
- 20 tagged releases, each with a written evidence file.