Repository navigation
Conversation
… purpose gunbc.cloudflare.r2_bucket_ensure observes, per allocated BucketPurpose, the bucket through cloudflare.R2Buckets.Get (extdeps.cloudflare.r2), classifies with std.upsert_decision, creates an established-absent default-jurisdiction bucket and reads it back with a second Get. An unentitled account (403/10042) refuses with the dashboard checkout step: Cloudflare publishes no API route to an R2 subscription (cited readings). Wired as fleet-converge mode r2_bucket_ensure; witness test.claim.cloudflare_r2_bucket_ensure. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… on std.upsert_decision Operator ruling (option B): the bootstrap token is not widened. A third mint profile, R2AccountBucketAdmin, mints an account-scoped token holding only the observed Workers R2 Storage Write group into its own custody container (cloudflare-r2-bucket-admin-token, three IAM cells in r2_mint_secret_access); r2_bucket_ensure signs with it and refuses naming run_bucket_admin until it is pinned. The R2 buckets service moves to extdeps.cloudflare.r2_buckets so its cloudflare.* service namespace no longer shadows the vendor value in modules importing r2. Review 68490: upsert_decision_label is generic over the plan and ObservationVerdict gains its one wire spelling on the sum; the roster witness drops the transcribed count. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…n mint observe_r2_mint_custody_container now creates an absent container (automatic replication) as the running identity before any Cloudflare effect; an identity without the project-level secretmanager.secrets.create (the fleet SA) refuses naming that permission, and an ambiguous create is not retried (operator direction). Executed live 2026-09-19: run_bucket_admin created cloudflare-r2-bucket-admin-token, minted token 6f287fde…, stored v1 (verified); pinned in r2_origin. ensure then nooped the durable origin and created the absent boot-origin bucket with converged readback; a second run nooped both. Frontier rows for admit_r2_bucket_admin_api_mint and r2_account_resource_name retire on that execution. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… 68550) observe_r2_mint_custody_container -> ensure_r2_mint_custody_container, ObserveCustodyContainer -> EnsureCustodyContainer, R2MintCustodyContainerUnobserved -> R2MintCustodyContainerNotEnsured, and the refusal texts with them: the step now creates an absent container, so the observation names were a meaning fork (DESIGN 3). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…iew 68589) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # .github/workflows/fleet-converge.yml # dag/gunbc/fleet/fleet_converge_workflow.dag
# Conflicts: # .github/workflows/fleet-converge.yml # dag/gunbc/fleet/fleet_converge_workflow.dag
…pile) main #11736 made fleet_converge_mode_fleet_ssh_key_demand exhaustive over the mode sum; the merge that added R2BucketEnsure and R2BucketAdminMint left them without an arm, so the corpus did not resolve and no regeneration of fleet-converge.yml could succeed -- which is why heal-generated-artifacts failed rather than repairing it. Both reach api.cloudflare.com and secretmanager.googleapis.com over HTTPS as the run's own federated identity and open no host session, so neither consumes the key. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The merge kept our side of the hunk carrying fleet_converge_mode_fleet_ssh_key_demand, which lost main's ApprovalKeyringConverge and MtCollins1Boot arms, so the match stayed non-exhaustive after 854e773 fixed the other half. Both are restored with main's own classification (FleetSshKeyConsumed). Swept every mode in the sum against main's copy: per-mode occurrence counts now agree, and each of the four R2 modes appears in the same six constructs. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The main merge took the ours side of this generated file, dropping the r2_bucket_ensure and r2_bucket_admin_mint modes the model at this head declares. Regenerated through gunbc.instruments.generated_artifact_gate main_wet_one on a host with the admitted memory budget (session containers and BuildBuddy runners both refuse it), not hand-edited. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # dag/gunbc/fleet/fleet_converge_workflow.dag
…on/sharp-ant-20 # Conflicts: # .github/workflows/fleet-converge.yml
parse_r2_jurisdiction re-spelled the five wire tokens r2_jurisdiction_wire already owns, so a corrected spelling in one would have left the other silently unrecognising. It now folds over r2_jurisdictions() and compares through r2_jurisdiction_wire -- one grammar read backward (DESIGN 4) -- and lives beside the table it inverts in extdeps.cloudflare.r2 rather than in the operation module. No declared-fork row is needed because the fork is gone. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # .github/workflows/fleet-converge.yml # dag/gunbc/fleet/fleet_converge_workflow.dag
# Conflicts: # .github/workflows/fleet-converge.yml # dag/gunbc/fleet/fleet_converge_workflow.dag
# Conflicts: # .github/workflows/fleet-converge.yml # dag/gunbc/fleet/fleet_converge_workflow.dag
Contributor
|
Duplicate: this branch is my local working copy of session/sharp-ant-20 (auto-pushed by the session). Its commits -- the main merge keeping all three new converge modes, and the regenerated fleet-converge.yml -- are on #11721. Closing to keep one PR for that work. — sent from still-owl-744 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Auto-opened by session-dashboard for session
still-owl-744.Pushing to
sharp-ant-mergeadvances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan