docs(prd): bound heavy gateway operations
prd-number-check / require-numbered-prds (pull_request) Successful in 10s
test / unit (pull_request) Successful in 54s
test / coverage (pull_request) Has been skipped
test / integration-docker (pull_request) Has been cancelled
test / image-input-builds (pull_request) Successful in 53s
tracker-policy-pr / check-pr (pull_request) Failing after 14m19s
prd-number-check / require-numbered-prds (pull_request) Successful in 10s
test / unit (pull_request) Successful in 54s
test / coverage (pull_request) Has been skipped
test / integration-docker (pull_request) Has been cancelled
test / image-input-builds (pull_request) Successful in 53s
tracker-policy-pr / check-pr (pull_request) Failing after 14m19s
This commit is contained in:
@@ -51,6 +51,9 @@ misleading behavior:
|
|||||||
10. Cleanup executes the entire post-confirmation snapshot rather than the
|
10. Cleanup executes the entire post-confirmation snapshot rather than the
|
||||||
intersection with what the operator saw, and mutation failures are not
|
intersection with what the operator saw, and mutation failures are not
|
||||||
reflected in the command result.
|
reflected in the command result.
|
||||||
|
11. Git smart-HTTP can retain sixteen 100 MiB request bodies concurrently,
|
||||||
|
cleanup mutations have no subprocess deadline, and Firecracker signalling
|
||||||
|
failures bypass shared mutation accounting.
|
||||||
|
|
||||||
These are one design problem: state used to authorize deletion, replacement,
|
These are one design problem: state used to authorize deletion, replacement,
|
||||||
or resource allocation must be authoritative at the point of use.
|
or resource allocation must be authoritative at the point of use.
|
||||||
@@ -85,6 +88,9 @@ or resource allocation must be authoritative at the point of use.
|
|||||||
- Cleanup executes only resources present in both the displayed and current
|
- Cleanup executes only resources present in both the displayed and current
|
||||||
authoritative plans, attempts every approved mutation, and returns failure
|
authoritative plans, attempts every approved mutation, and returns failure
|
||||||
when any mutation does not complete.
|
when any mutation does not complete.
|
||||||
|
- Git request bodies spool to disk behind a separate heavy-work semaphore;
|
||||||
|
cleanup commands have configurable deadlines; Firecracker signalling
|
||||||
|
failures aggregate while identity-verification uncertainty still aborts.
|
||||||
- Unit tests cover PID/path reuse, partial backend enumeration, transient
|
- Unit tests cover PID/path reuse, partial backend enumeration, transient
|
||||||
policy resolution failure, slow bodies, concurrency saturation, and stream
|
policy resolution failure, slow bodies, concurrency saturation, and stream
|
||||||
closure races.
|
closure races.
|
||||||
@@ -160,6 +166,8 @@ reported through the supervisor's normal diagnostic channel.
|
|||||||
queries, and bounded Firecracker artifact transfers.
|
queries, and bounded Firecracker artifact transfers.
|
||||||
9. Mandatory authenticated secret storage, shared cleanup-plan intersection
|
9. Mandatory authenticated secret storage, shared cleanup-plan intersection
|
||||||
and mutation accounting, and contained Git backend process failures.
|
and mutation accounting, and contained Git backend process failures.
|
||||||
|
10. Disk-spooled and separately bounded Git bodies, cleanup command deadlines,
|
||||||
|
and classified Firecracker signalling failures.
|
||||||
|
|
||||||
## Open questions
|
## Open questions
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user