Skip to content

[3/4] feat(runtime): apply accepted release digests - #125

Open
MarcStdt wants to merge 4 commits into
codex/scroll-runtime-backup-orchestrationfrom
codex/runtime-accepted-release-updates
Open

MarcStdt wants to merge 4 commits into
codex/scroll-runtime-backup-orchestrationfrom
codex/runtime-accepted-release-updates

Conversation

@MarcStdt

@MarcStdt MarcStdt commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Scope of this layer

Stage exact-digest updates; read installed release descriptors; reject stale approval under the maintenance lock; expose owner-authenticated installed-release/update routes. Align workers, API schema and integration coverage.

Review order

Review worker replacement/protection logic, runtime update/maintenance locking and owner checks, then generated API code. This PR points to existing commit 1e6f057, with no new implementation commit. Final scoped safeguards follow in #124.

Native GitHub stack #126, bottom to top:

  1. [1/4] feat(registry): preserve release manifest #122 — feat(registry): preserve release manifest
  2. [2/4] fix(runtime): make backups restore-safe #123 — fix(runtime): make backups restore-safe
  3. [3/4] feat(runtime): apply accepted release digests #125 — feat(runtime): apply accepted release digests
  4. [4/4] feat(runtime): validate releases and finalize lifecycle safeguards #124 — feat(runtime): validate releases and finalize lifecycle safeguards

GitHub's Files changed tab is incremental against the preceding branch. Review the complete stack before landing: later layers contain final fixes and cleanup for earlier layers. The old consolidated/superseded descriptions and draft acceptance notes are historical and replaced by this reconstruction.

Unchanged implementation

Reconstructed from existing commits only: no source edits, rebases, squashes or force-pushes. The complete stack tip is e4aadf2816bfec4f4642cf2ae130ca82401b5fd9, tree 7d6c9fb61e07900ec756fef2437b495c230a4585, exactly the previously verified local tree. Existing commits, discussion and PR identities are retained; only the runtime update boundary needed a new PR.

Verification and rollout

Local verification recorded on October 3 for the complete final implementation: 112 lifecycle/UI tests (11 opt-in skips in the default run); separate real Harbor/Postgres integration (2 passed); authenticated publisher import/retry/publication; SPA type-check; full CLI and engine commands; uncached publisher/workflow checks; focused race runs; rebuilt Docker/Kubernetes acceptance. Browser/workload evidence is complementary and qualified, not one uninterrupted end-to-end run. Four legacy Core compilation failures and the documented baseline active-workload backup/queue issues remain outside scope. These results do not assert every historical intermediate layer independently passed the final suite or that fresh remote CI is green.

See the final local requirement audit for exact commands, qualifications and rollout order. Ready for review does not mean merged or deployed. Matching Core/engine/runtime contracts must ship together; configure the public runtime API URL when GAME_HOST is not that API. Protected Team publishing environments/identity/secrets must exist before activating the workflow cutover; its fail-closed gate remains intact.

Companion changes: monorepo stack, runtime stack, standalone publisher. No production mutation or merge is part of this reconstruction.

Require explicit immutable update references; reconciliation must not undo restores or follow moved tags. Read the installed descriptor from the runtime volume.

Preserve rollback recovery files, all backup data, and old/new protected paths during updates. Serialize command admission with maintenance without holding locks during command waits. Preserve symlinks without following protected parent paths.

BREAKING CHANGE: runtime update callers must supply repository@sha256. Old tag/empty update requests fail before stopping the workload.

Verified full Go suite, focused race tests, and rebuilt-image isolated Kubernetes lifecycle. See docs/runtime-lifecycle-verification.md for scope and remaining product work.
Check the installed descriptor under the maintenance lock before stopping.
Keep the accepted baseline unchanged on conflict and return HTTP 409.
Verified with the full Go suite and rebuilt-image Kubernetes lifecycle.
Use the authenticated public listener for cross-cluster accepted updates.
Reject missing and cross-owner tokens before reading or changing runtime
state; keep operator-only management authorization unchanged.
@druid-infra

Copy link
Copy Markdown
Contributor
Error: This repo is not allowlisted for Atlantis.

@MarcStdt
MarcStdt added this pull request to stack #126 October 4, 2026 16:21
@MarcStdt MarcStdt changed the title feat(runtime): apply accepted release digests [3/4] feat(runtime): apply accepted release digests Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants