# Letting Jinja hot-reload templates in the deployment root _2026-09-21 ยท booth_ **Letting Jinja hot-reload templates while the repo is the deployment root** โ€” the cause of a live outage the same day U2 landed, and the sharpest foot-gun in the repo. `booth.service` sets `WorkingDirectory` to this repo, so the running service imports these files with no build step and no staging copy. Python is read once at process start; Jinja's `FileSystemLoader` re-reads a template **on every render**. Editing `booth.html` therefore deployed it instantly against Python from 22:03 that knew nothing about `item_marks`, and **19 of 25 live booths returned 500** with `UndefinedError: 'item_marks' is undefined`. Neither the old code nor the new code was broken โ€” the service was running both at once. **The lesson that generalises:** a skew between a process and the disk under it is invisible to the test suite by construction, so no amount of green tests would have caught it; the operator found it. Fixed at the source rather than with a reminder โ€” the `Environment` is hand-built with `auto_reload=False`, so there is now ONE staleness rule (nothing takes effect until you restart) and the running process is always a coherent snapshot of one commit. Asserted by `test_templates_do_not_hot_reload_from_disk`. Watch the second-order risk the fix introduces: a hand-built `Environment` does not inherit `autoescape` from the `Jinja2Templates` constructor, and booth names, item names and mark text are all agent-authored strings landing in HTML.