Repository navigation
feat(OMN-13011): LANE CENSUS RECONCILIATION ratchet — declared desired-state per lane, drift = auto-ticket - #1953
jonahgabriel wants to merge 1 commit into
Conversation
…d-state per lane, drift = auto-ticket The class fix for the recurring lane-drift regression. Nothing reconciled the declared desired state of a runtime lane against what is actually running, so the same failure kept recurring with zero signal: volume config drift (OMN-12945), WORKER_REPLICAS silent zero (OMN-12988/12990), and on 2026-06-11 prod runtime containers plus the broker network were silently absent for hours during demo prep. Ships a per-lane DESIRED-STATE census: - (a) DECLARED in a versioned lane manifest (deploy/lane-census/lane-manifest.yaml): container set, network, replicas, image-tag pattern per lane (stability-test/prod/judge/dev), derived from the canonical compose lane files. A parity ratchet keeps the manifest locked in step with the compose files. - (b) RECONCILED on a schedule on .201 by SHARING the OMN-13008 systemd timer (a drop-in 4th ExecStart on onex-disk-gc.service — never a second timer) and on-demand via scripts/lane-census-check.sh / runtime_sweep. - (c) Drift = typed bus event (onex.evt.infra.lane-census-drift.v1) + Linear auto-ticket naming exactly what is missing/extra (container_absent, network_detached, replicas_zero, unexpected_container, oneshot_failed/stuck, image_tag_mismatch). Fail-fast, no warn-only mode (gates-block policy); exit 30 on drift; bus publish fail-fast on KAFKA_BOOTSTRAP_SERVERS (no localhost default). Red fixture reproduces 2026-06-11: prod runtime containers absent + broker network detached must produce the exact drift findings + a non-zero exit hours before a human noticed. Pure planner is fully unit-tested; shell driver dry-run-tested. Builds on the OMN-12988 deploy-agent RUNTIME census (deploy-time) as the complementary steady-state reconciler; closes the runtime-worker.yaml container_name: null census gap by sourcing names from the compose lane files. Evidence-Ticket: OMN-13011 Config-drift family: OMN-12945 Relates-to: OMN-13009, OMN-12988, OMN-13008 Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
|
Warning Review limit reached
More reviews will be available in 1 hour, 14 minutes, and 24 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more credits in the billing tab to continue. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (12)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
OMN-13011 — LANE CENSUS RECONCILIATION ratchet
The class fix for the recurring lane-drift regression. Nothing reconciled the declared desired state of a runtime lane against what is actually running, so the same failure kept recurring with zero signal:
WORKER_REPLICASsilent zero — worker scaled to 0, no alert (OMN-12988 / OMN-12990)Operator demand: "how do we keep having this regression over and over." Answer: there was no reconciler. This ships one.
What this does
(a) DECLARED —
deploy/lane-census/lane-manifest.yamlis the versioned desired state per lane (stability-test,prod,judge,dev): container set, network, replicas, image-tag pattern. Names/networks are derived from the canonical compose lane files; nothing is hardcoded in the scripts. A parity ratchet (test_lane_census_manifest_parity.py) keeps the manifest locked in step with the compose files and forbids any service declaringreplicas: 0(the silent-drop surface). This also closes the OMN-12988runtime-worker.yaml container_name: nullcensus gap by sourcing concrete names from the compose lane files.(b) RECONCILED —
scripts/lane_census_plan.py(pure planner, no I/O) diffs desired vs the livedocker ps/docker network lsinventory and emits typed drift findings.scripts/lane-census-check.shdrives it on .201. Coordinated with the OMN-13008 AutoGC timer (PR #1952): instead of a second timer, a systemd drop-in (deploy/lane-census/onex-disk-gc.service.d/20-lane-census.conf) appends a 4thExecStartto the sharedonex-disk-gc.service. On-demand path:bash scripts/lane-census-check.sh --json(the runtime_sweep invocation surface).(c) DRIFT = AUTO-TICKET — on drift,
scripts/lane_census_event.pybuilds a typed bus event (onex.evt.infra.lane-census-drift.v1) with a dedupealert_keyand a ticket title/body naming exactly what is missing/extra:container_absent,network_detached,replicas_zero,unexpected_container,oneshot_failed,oneshot_stuck,image_tag_mismatch. The sweep auto-ticket path consumes it (single ticket-creation authority, same pattern as the OMN-13008 disk-watermark event).Fail-fast, no warn-only mode (gates-block policy): drift exits 30; the bus publish is fail-fast on
KAFKA_BOOTSTRAP_SERVERS(no localhost/default broker).Red fixture (tonight's case)
test_tonight_prod_red_fixture_runtime_absent_and_network_detachedreproduces 2026-06-11: prod runtime containers absent + broker network detached. The planner must emitnetwork_detached+container_absentfor every missing runtime service, allcritical— the ticket that should have fired hours before a human noticed.Builds on (no duplication)
verify_containers_up— the deploy-time census. This is the complementary steady-state reconciler.Evidence (dod_evidence — contracts/OMN-13011.yaml)
Evidence-Ticket: OMN-13011
Evidence-Source: OCC#2536
Config-drift family: OMN-12945
Relates-to: OMN-13009, OMN-12988, OMN-13008