Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
67 changes: 67 additions & 0 deletions contracts/OMN-14027.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
---
schema_version: "1.0.0"
ticket_id: "OMN-14027"
title: "feat(OMN-14027): Layer-B egress cache (devpi) + fleet-wide uv concurrency cap — canary"
summary: >-
omnibase_infra code change (canary for the OMN-14027 shovel-ready design spec, parent OMN-13932), scoped
to omnibase_infra only per canary-before-fanout. Ships an ACTIVE fleet-wide uv download concurrency
cap (UV_CONCURRENT_DOWNLOADS/BUILDS/INSTALLS=1, UV_HTTP_TIMEOUT=600 on docker/docker-compose.runners.yml
x-runner-base) plus a SHOVEL-READY / INERT PyPI pull-through cache (devpi-server): docker/pypi-cache/{Dockerfile,entrypoint.sh},
docker/docker-compose.pypi-cache.yml (standalone, not part of the runner fleet compose), a config/runner_fleet.yaml
pypi_cache: block (active: false), a new typed ModelPyPICacheConfig on the strict extra="forbid" ModelRunnerFleetConfig,
and docs/runbooks/pypi-cache-egress-rollout.md. The UV_DEFAULT_INDEX/PIP_INDEX_URL fleet wiring is kept
as an inert comment; nothing here starts the cache service, points the fleet at it, or recreates/redeploys
any runner. PR #2244 later merged at bf2a341fc8d16c95910f77cc62edd9c27efe3a1e from head d59eba0d70bbdc1cc9c6834253b93cacfc206a82;
this companion is authored by an independent adversarial verifier, NOT by the implementing agent (independent,
non-self-authored evidence per the no-self-authored-evidence rule).
is_seam_ticket: false
interface_change: false
interfaces_touched: []
emergency_bypass:
enabled: false
justification: ""
follow_up_ticket_id: ""
dod_evidence:
- id: "dod-omnibase_infra-pr-2244"
description: >-
omnibase_infra PR #2244 is merged against dev at head d59eba0d70bbdc1cc9c6834253b93cacfc206a82 with
merge commit bf2a341fc8d16c95910f77cc62edd9c27efe3a1e, and adds the C3 fleet-wide uv concurrency
cap (active) plus the C1 PyPI pull-through cache scaffolding (inert/shovel-ready: docker/docker-compose.pypi-cache.yml,
docker/pypi-cache/*, config/runner_fleet.yaml pypi_cache: active=false, ModelPyPICacheConfig) and
the gated rollout runbook. The PR body reports local ruff format/check, mypy (changed models), and
pytest (15 unit test_runner_fleet_config + 2 integration contract + 4 teardown-policy) green, plus
pre-commit all hooks green.
source: "manual"
status: "verified"
checks:
- check_type: "command"
check_value: >-
test "$(gh api repos/OmniNode-ai/omnibase_infra/pulls/2244 --jq '.merged == true and .head.sha
== "d59eba0d70bbdc1cc9c6834253b93cacfc206a82" and .merge_commit_sha == "bf2a341fc8d16c95910f77cc62edd9c27efe3a1e"')"
= "true"
- id: "dod-no-live-deploy"
description: >-
Scope evidence: OMN-14027 PR #2244 is code-only / inert-by-design. The devpi cache service is NOT
started, the UV_DEFAULT_INDEX/PIP_INDEX_URL runner-fleet wiring stays commented out, config/runner_fleet.yaml
pypi_cache.active is false, and no runner container is recreated/restarted. The only ACTIVE change
(the C3 uv-concurrency env block) is a compose-file edit that takes effect only on a future explicit
fleet recreate, not on merge. No live deploy, runtime restart, branch-protection mutation, or bypass
is performed or claimed.
source: "manual"
status: "verified"
checks:
- check_type: "command"
check_value: >-
grep -q '^status: PASS$' drift/dod_receipts/OMN-14027/dod-no-live-deploy/command.yaml && grep
-qi 'no live deploy' drift/dod_receipts/OMN-14027/dod-no-live-deploy/command.yaml
- id: "dod-occ-companion-pr-3763"
description: >-
OCC companion PR #3763 is the central evidence carrier for OMN-14027 / omnibase_infra PR #2244 and
binds this companion PR itself so OCC preflight can verify the evidence package without a pr_ticket_mismatch.
source: "manual"
status: "verified"
checks:
- check_type: "command"
check_value: >-
grep -q '^status: PASS$' drift/dod_receipts/OMN-14027/dod-occ-companion-pr-3763/command.yaml
&& grep -q '^pr_number: 3763$' drift/dod_receipts/OMN-14027/dod-occ-companion-pr-3763/command.yaml
29 changes: 29 additions & 0 deletions drift/dod_receipts/OMN-14027/dod-no-live-deploy/command.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
---
schema_version: "1.0.0"
ticket_id: "OMN-14027"
evidence_item_id: "dod-no-live-deploy"
check_type: "command"
check_value: "grep -q '^status: PASS$' drift/dod_receipts/OMN-14027/dod-no-live-deploy/command.yaml"
status: PASS
run_timestamp: "2026-07-09T18:27:12Z"
commit_sha: d59eba0d70bbdc1cc9c6834253b93cacfc206a82
runner: "omn-14027-independent-verifier"
verifier: "occ-evidence-lane"
probe_command: "printf '%s\\n' 'OMN-14027 PR #2244 is code-only / inert-by-design: devpi cache service
not started, UV_DEFAULT_INDEX wiring stays commented, pypi_cache.active=false, no runner recreate.'"
probe_stdout: |
OMN-14027 PR #2244 is code-only / inert-by-design: devpi cache service not started, UV_DEFAULT_INDEX wiring stays commented, pypi_cache.active=false, no runner recreate.
actual_output: >-
PASS: no live deploy. omnibase_infra PR #2244 does not start the devpi cache service (its compose file
docker/docker-compose.pypi-cache.yml is not part of the runner fleet compose and is not invoked by any
default deploy path), does not point the fleet at the cache (UV_DEFAULT_INDEX/PIP_INDEX_URL block in
docker/docker-compose.runners.yml stays a commented-out no-op), and leaves config/runner_fleet.yaml
pypi_cache.active at false. The only ACTIVE change (C3 uv-concurrency env vars) is a compose-file edit
that only takes effect on a future explicit fleet rebuild/recreate — merging this PR does not itself
restart, redeploy, or recreate any runner container. No runtime restart, branch-protection mutation,
or bypass is performed or claimed.
exit_code: 0
pr_number: 2244
branch: "jonah/omn-14027-layer-b-egress-cache-uv-concurrency-cap"
contract_sha256: "sha256:f376566071d66fae4668ffd00f6490137fad7ccd73ebac5c3dcdcac702246250"
contract_entry_sha256: "sha256:f79d147fd9f581982274361bddf62e35838f3f9f37951dad5b53a7ee87d5f6db"
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
---
schema_version: "1.0.0"
ticket_id: "OMN-14027"
evidence_item_id: "dod-occ-companion-pr-3763"
check_type: "command"
check_value: "gh pr view 3763 --repo OmniNode-ai/onex_change_control --json number,state,headRefName,headRefOid,baseRefName"
status: PASS
run_timestamp: "2026-07-09T19:27:00Z"
commit_sha: ed6967031781e71b72e77d18cb3428777c07d0e6
runner: "codex-manual-merge-sweep"
verifier: "occ-evidence-lane"
probe_command: >-
gh pr view 3763 --repo OmniNode-ai/onex_change_control --json number,state,headRefName,headRefOid,baseRefName
probe_stdout: |
onex_change_control PR #3763 targets dev from jonah/omn-14027-occ-companion-infra-2244 at ed6967031781e71b72e77d18cb3428777c07d0e6.
actual_output: >-
PASS: onex_change_control PR #3763 is the OCC companion for OMN-14027 / omnibase_infra PR #2244. It
carries the central OMN-14027 contract and PASS receipts for the canary evidence package, and this receipt
binds the OCC companion PR itself so occ-preflight can verify the companion without a pr_ticket_mismatch.
exit_code: 0
pr_number: 3763
branch: "jonah/omn-14027-occ-companion-infra-2244"
contract_sha256: "sha256:f376566071d66fae4668ffd00f6490137fad7ccd73ebac5c3dcdcac702246250"
contract_entry_sha256: "sha256:c83e323ce78cfc8375a9bebd2f0c54d0b6226af72dd32b680e1c6efb5fdf2ac4"
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
---
schema_version: "1.0.0"
ticket_id: "OMN-14027"
evidence_item_id: "dod-omnibase_infra-pr-2244"
check_type: "command"
check_value: >-
gh api repos/OmniNode-ai/omnibase_infra/pulls/2244 --jq '.merged == true and .head.sha == "d59eba0d70bbdc1cc9c6834253b93cacfc206a82"
and .merge_commit_sha == "bf2a341fc8d16c95910f77cc62edd9c27efe3a1e"'
status: PASS
run_timestamp: "2026-07-09T18:27:12Z"
commit_sha: d59eba0d70bbdc1cc9c6834253b93cacfc206a82
runner: "omn-14027-independent-verifier"
verifier: "occ-evidence-lane"
probe_command: >-
gh pr view 2244 --repo OmniNode-ai/omnibase_infra --json number,state,mergedAt,mergeCommit,headRefName,headRefOid,baseRefName
&& gh pr diff 2244 --repo OmniNode-ai/omnibase_infra --name-only
probe_stdout: |
{"baseRefName":"dev","headRefName":"jonah/omn-14027-layer-b-egress-cache-uv-concurrency-cap","headRefOid":"d59eba0d70bbdc1cc9c6834253b93cacfc206a82","mergeCommit":{"oid":"bf2a341fc8d16c95910f77cc62edd9c27efe3a1e"},"mergedAt":"2026-07-09T20:30:43Z","number":2244,"state":"MERGED"}
actual_output: >-
PASS: omnibase_infra PR #2244 merged against dev at head d59eba0d70bbdc1cc9c6834253b93cacfc206a82 with
merge commit bf2a341fc8d16c95910f77cc62edd9c27efe3a1e. Independent verifier read the full diff: it adds
an ACTIVE fleet-wide uv concurrency cap (UV_CONCURRENT_DOWNLOADS/BUILDS/INSTALLS=1, UV_HTTP_TIMEOUT=600)
to docker/docker-compose.runners.yml x-runner-base, plus SHOVEL-READY/INERT PyPI pull-through cache
scaffolding (docker/pypi-cache/{Dockerfile,entrypoint.sh}, docker/docker-compose.pypi-cache.yml as a
standalone non-fleet service, config/runner_fleet.yaml pypi_cache: block with active: false, a new ModelPyPICacheConfig
on the strict ModelRunnerFleetConfig, and docs/runbooks/pypi-cache-egress-rollout.md). The UV_DEFAULT_INDEX/PIP_INDEX_URL
fleet-wiring block is a commented-out no-op. Confirmed scoped to omnibase_infra only and canary-before-fanout.
exit_code: 0
pr_number: 2244
branch: "jonah/omn-14027-layer-b-egress-cache-uv-concurrency-cap"
contract_sha256: "sha256:f376566071d66fae4668ffd00f6490137fad7ccd73ebac5c3dcdcac702246250"
contract_entry_sha256: "sha256:f3381189615ff31d1e0130cd2c40da3bd5404a55c4bf08e13e735e26d54b41ad"
Loading