Repository navigation
Conversation
Require explicit immutable update references; reconciliation must not undo restores or follow moved tags. Read the installed descriptor from the runtime volume. Preserve rollback recovery files, all backup data, and old/new protected paths during updates. Serialize command admission with maintenance without holding locks during command waits. Preserve symlinks without following protected parent paths. BREAKING CHANGE: runtime update callers must supply repository@sha256. Old tag/empty update requests fail before stopping the workload. Verified full Go suite, focused race tests, and rebuilt-image isolated Kubernetes lifecycle. See docs/runtime-lifecycle-verification.md for scope and remaining product work.
Check the installed descriptor under the maintenance lock before stopping. Keep the accepted baseline unchanged on conflict and return HTTP 409. Verified with the full Go suite and rebuilt-image Kubernetes lifecycle.
Use the authenticated public listener for cross-cluster accepted updates. Reject missing and cross-owner tokens before reading or changing runtime state; keep operator-only management authorization unchanged.
Contributor
|
MarcStdt
added this pull request to stack #126
October 4, 2026 16:21
This was referenced Oct 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope of this layer
Stage exact-digest updates; read installed release descriptors; reject stale approval under the maintenance lock; expose owner-authenticated installed-release/update routes. Align workers, API schema and integration coverage.
Review order
Review worker replacement/protection logic, runtime update/maintenance locking and owner checks, then generated API code. This PR points to existing commit 1e6f057, with no new implementation commit. Final scoped safeguards follow in #124.
Native GitHub stack #126, bottom to top:
GitHub's Files changed tab is incremental against the preceding branch. Review the complete stack before landing: later layers contain final fixes and cleanup for earlier layers. The old consolidated/superseded descriptions and draft acceptance notes are historical and replaced by this reconstruction.
Unchanged implementation
Reconstructed from existing commits only: no source edits, rebases, squashes or force-pushes. The complete stack tip is
e4aadf2816bfec4f4642cf2ae130ca82401b5fd9, tree7d6c9fb61e07900ec756fef2437b495c230a4585, exactly the previously verified local tree. Existing commits, discussion and PR identities are retained; only the runtime update boundary needed a new PR.Verification and rollout
Local verification recorded on October 3 for the complete final implementation: 112 lifecycle/UI tests (11 opt-in skips in the default run); separate real Harbor/Postgres integration (2 passed); authenticated publisher import/retry/publication; SPA type-check; full CLI and engine commands; uncached publisher/workflow checks; focused race runs; rebuilt Docker/Kubernetes acceptance. Browser/workload evidence is complementary and qualified, not one uninterrupted end-to-end run. Four legacy Core compilation failures and the documented baseline active-workload backup/queue issues remain outside scope. These results do not assert every historical intermediate layer independently passed the final suite or that fresh remote CI is green.
See the final local requirement audit for exact commands, qualifications and rollout order. Ready for review does not mean merged or deployed. Matching Core/engine/runtime contracts must ship together; configure the public runtime API URL when GAME_HOST is not that API. Protected Team publishing environments/identity/secrets must exist before activating the workflow cutover; its fail-closed gate remains intact.
Companion changes: monorepo stack, runtime stack, standalone publisher. No production mutation or merge is part of this reconstruction.