Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
114 commits
Select commit Hold shift + click to select a range
0fa9134
fix(auxiliary-files): serve bundles from the public, non-requester-pa…
rdahis Aug 28, 2026
f246858
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Aug 28, 2026
a123779
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Aug 28, 2026
24dd3e2
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Aug 28, 2026
ce1cd6b
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Aug 29, 2026
1e8e1e6
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Aug 31, 2026
aded36a
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Aug 31, 2026
5d043be
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Aug 31, 2026
ca1f7ed
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Aug 31, 2026
66834da
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Aug 31, 2026
134a9ae
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 1, 2026
06959d8
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 1, 2026
030743b
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 2, 2026
481c689
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 2, 2026
0ea3d3e
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 2, 2026
8830ae5
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 2, 2026
f778203
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 2, 2026
33dbcef
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 2, 2026
49644c8
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 2, 2026
3479b39
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 2, 2026
5e680a8
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 2, 2026
ca11b0f
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 2, 2026
bb9cf87
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 2, 2026
cd1f186
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 2, 2026
3d3edcf
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 3, 2026
e244458
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 3, 2026
0203167
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 3, 2026
dcd8ba0
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 3, 2026
a482e43
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 3, 2026
31e59e4
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 3, 2026
01793b7
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 3, 2026
9bcf603
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 3, 2026
fc9bc90
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 3, 2026
1e15a32
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 4, 2026
1660647
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 4, 2026
d37dc27
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 4, 2026
5dcdd8e
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 4, 2026
a2da749
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 4, 2026
8df5019
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 4, 2026
7669a7f
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 7, 2026
793bda8
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 7, 2026
2c2d65c
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 7, 2026
78286f8
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 7, 2026
e8418c4
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 7, 2026
ee65f12
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 7, 2026
e69c7b2
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 7, 2026
2680f5a
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 7, 2026
e9c7708
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 8, 2026
8a9a656
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 8, 2026
78b5faf
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 8, 2026
f6b77aa
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 8, 2026
c698f69
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 8, 2026
8db2151
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 8, 2026
adc953f
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 8, 2026
48fd1bc
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 9, 2026
816f6af
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 9, 2026
484731e
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 9, 2026
1af7292
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 9, 2026
420a72a
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 9, 2026
d9c22d7
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 9, 2026
a36fdde
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 9, 2026
955cc1b
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 9, 2026
20dc9cc
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 9, 2026
3af4b5c
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
1001327
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
e62111d
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
ece486b
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
f1a5c3a
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
371f933
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
1417ba0
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
fc64324
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
dd7362e
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
bc45b41
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
a31d7c9
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
6de4d9c
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
dba5faa
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 10, 2026
6aa18a4
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 11, 2026
786c718
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 11, 2026
79d1fc4
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 11, 2026
1e2a7ec
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 11, 2026
a610b99
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 11, 2026
f61fbd5
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 11, 2026
9b30a0f
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 11, 2026
3972fb5
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 12, 2026
254e545
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 12, 2026
1e8b17a
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 14, 2026
d3cfa39
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 15, 2026
220df9e
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 15, 2026
6c32433
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 15, 2026
8900b6c
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 15, 2026
4f8305e
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 15, 2026
43e96e0
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 15, 2026
0c0d0be
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 15, 2026
8a50f8f
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 15, 2026
05ecbae
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 16, 2026
dbcb1fc
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 16, 2026
2070697
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 16, 2026
b45ab81
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 16, 2026
c309e1b
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 16, 2026
e6cb1e3
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 16, 2026
0779b7d
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 16, 2026
e345ca8
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 16, 2026
a196b7a
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 16, 2026
3e6353f
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 16, 2026
25df8de
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 17, 2026
6d2e8d2
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 17, 2026
12dd3f8
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 17, 2026
e678058
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 18, 2026
c745ab5
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 18, 2026
4b68cdb
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 18, 2026
c087ff0
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 18, 2026
20f61f4
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 18, 2026
a1867fd
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 18, 2026
9036b5b
Merge branch 'main' into fix/auxiliary-files-public-bucket
mergify[bot] Sep 18, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 24 additions & 16 deletions .claude/rules/auxiliary-files.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,41 +53,49 @@ Rule of thumb: if it is over ~5 MB and a user would read it once, link it.
## Where auxiliary files are stored

```text
gs://basedosdados/auxiliary_files/<gcp_dataset_id>/<table_slug>/auxiliary_files.zip
gs://basedosdados-public/auxiliary_files/<gcp_dataset_id>/<table_slug>/auxiliary_files.zip
```

recorded as the matching public URL:

```text
https://storage.googleapis.com/basedosdados/auxiliary_files/<gcp_dataset_id>/<table_slug>/auxiliary_files.zip
https://storage.googleapis.com/basedosdados-public/auxiliary_files/<gcp_dataset_id>/<table_slug>/auxiliary_files.zip
```

Use the **prod** bucket (`basedosdados`) for anything that will be published. Most
existing rows point at `basedosdados-dev`, which is a historical accident, not the
convention.

### Known bug: these links do not resolve for the public

Both buckets are **requester-pays**, so an anonymous request returns HTTP 400:
**Use `basedosdados-public`, not `basedosdados` or `basedosdados-dev`.** The two
data-lake buckets are requester-pays, which makes every link served from them
return HTTP 400 to an anonymous visitor:

```xml
<Error><Code>UserProjectMissing</Code>
<Message>Bucket is a requester pays bucket but no user project provided.</Message></Error>
```

As of 2026-08-21 **all 84** production tables whose `auxiliaryFilesUrl` points at
GCS are affected — every one of those links is dead for a site visitor.
Requester-pays is a bucket-level billing setting; it cannot be scoped to a
prefix, and the objects being world-readable does not help — `allUsers` already
holds `roles/storage.objectViewer` on `basedosdados-dev` and the links are dead
regardless. Turning it off on a data-lake bucket is not an option either: it
would make hundreds of terabytes of egress anonymously billable.

`basedosdados-public` is not requester-pays and is already how the public reaches
Data Basis data — it serves the one-click table downloads under
`one-click-download/<gcp_dataset_id>/<table_slug>/` that `pipelines/utils/tasks.py`
exports to and the website streams. Auxiliary bundles sit beside them under
`auxiliary_files/`.

Follow the convention anyway: a per-table bundle in the documented location is
correct, and the fix is one bucket setting, not 84 bespoke hosting decisions. But
**verify and report the real status** rather than assuming the link works:
### Always verify the link anonymously

The bucket choice is the whole fix, so confirm it rather than assuming:

```bash
curl -sI "<auxiliaryFilesUrl>" | head -1
```

Never state that auxiliary files are "available at" a URL you have not fetched
anonymously. If it returns 400, say so in the onboarding summary.
without credentials. A 400 means you used a requester-pays bucket.

`.github/scripts/migrate_auxiliary_files.py verify --env prod` runs this check
across every registered `auxiliaryFilesUrl` at once.

## Every bundle carries a README

Expand Down Expand Up @@ -133,6 +141,6 @@ why.
- [ ] At most one raw data source linked per table
- [ ] Bundles are per table and contain only that table's documents
- [ ] Every bundle has a README with citation, per-file provenance and download dates
- [ ] Uploaded to the prod bucket under `auxiliary_files/<gcp_dataset_id>/<table_slug>/`
- [ ] Uploaded to `gs://basedosdados-public` under `auxiliary_files/<gcp_dataset_id>/<table_slug>/`
- [ ] `auxiliary_files_url` set on every table that has a bundle
- [ ] Each published URL fetched anonymously and its real status reported
2 changes: 1 addition & 1 deletion .claude/rules/metadata-schema.md
Original file line number Diff line number Diff line change
Expand Up @@ -113,7 +113,7 @@ Resolve tags **per backend**: ids differ across dev/staging/prod, so re-scan (an
| `status_id` | string | `status.published` — tables are gated by the dataset's `under_review` status, so they may stay published (see "Dataset status lifecycle") |
| `published_by_ids` | list | Authenticated account ID |
| `data_cleaned_by_ids` | list | Authenticated account ID |
| `auxiliary_files_url` | string | Public URL of the table's auxiliary-file bundle. See `auxiliary-files` for what belongs in one, the GCS path convention, and the requester-pays caveat that makes these links resolve to HTTP 400 for anonymous users today |
| `auxiliary_files_url` | string | Public URL of the table's auxiliary-file bundle. See `auxiliary-files` for what belongs in one and the GCS path convention. Must be served from `gs://basedosdados-public`; the data-lake buckets are requester-pays and return HTTP 400 to anonymous visitors |
| `id` | string | Pass when updating |

Do **not** pass `raw_data_source_ids` in the initial creation — link them in the deferred update (step 15).
Expand Down
10 changes: 5 additions & 5 deletions .claude/rules/onboarding-workflow.md
Original file line number Diff line number Diff line change
Expand Up @@ -117,11 +117,11 @@ long-form PDFs).

Two things to know before reporting success:

- **The published links are currently dead for the public.** Both GCS buckets are
requester-pays, so an anonymous fetch returns `UserProjectMissing`; all 84
production tables using the field are affected. Ship the bundle in the documented
location anyway, but `curl -sI` each URL with no credentials and report what it
actually returns.
- **Upload to `gs://basedosdados-public`, not to a data-lake bucket.** The two
data-lake buckets (`basedosdados`, `basedosdados-dev`) are requester-pays, so
anything served from them returns `UserProjectMissing` to an anonymous fetch.
`curl -sI` each URL with no credentials and report what it actually returns —
a 400 means the wrong bucket.
- **Some publishers block scripted downloads.** `www.oecd.org` serves `.zip` only to
a real browser. Fetch through the browser tools rather than dropping the document.

Expand Down
Loading
Loading