Skip to content

Recut DESIGN.md (gunbc.design_document) and the repository docs: census first, freshen and simplify in the authority, land after the closeout - #13669

Closed
briansrls wants to merge 2016 commits into
mainfrom
session/keen-owl-192
Closed

briansrls wants to merge 2016 commits into
mainfrom
session/keen-owl-192

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session keen-owl-192.
Pushing to session/keen-owl-192 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 30 commits October 9, 2026 16:33
…BMC steps

- gunbc.fleet_host_backing: OwnedMachine carries its OwnedProvisioning
  (BmcVirtualMediaInstall | ApplianceFirstBoot); a ProviderGuest's OS is the
  provider's image by construction, so a rented guest owing a BMC operation
  has no constructor.
- gunbc.host_standup gains the ProviderGuestAdopted prefix phase; the
  assimilation program selects prefix steps by backing
  (prefix_phase_applies) and assimilation steps by participation, so the CAX
  guests owe adoption + their CI roles and no BMC/virtual-media step.
- gunbc.provider_guest_adoption: bound provider resource, entitlement-bounded
  observation (uname -m/-n, _NPROCESSORS_ONLN, /proc/meminfo, /dev/kvm over
  host_command), and a MicroVmExecutionStanding carried beside adoption:
  Hetzner's cited no-nested-virtualization fact refuses the Firecracker path.
- extdeps: uname_machine_command / uname_nodename_command /
  uname_machine_architecture, getconf_online_processors_command (admitted on
  argv_command's caller list).
- os_install_actuator_selection_witness: the same pre-existing
  optional==required compares, so its witness runs again.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ollment root

- Population lists derive from gunbc.fleet_enrollment: runner_host_deploy's
  resolutions (one per enrolled CI host, Unmodeled where no spec exists),
  runner_slot_allocation standings, ci_fleet fleet_intent_offers (filtered
  from the owned offer catalog), and fleet_reach_endpoint's probe roster.
- runner_host_deploy: the two four-arm srvN switches become one keyed
  runner_host_spec_rows lookup; specs stay per-host facts.
- Name/identity seam goes through gunbc.hostname_allocation:
  host_reach_identity_probe compares against the allocated hostname
  (UnknownRefused when none), workspace_tool_observer joins the kernel
  hostname to the slot via the allocation, and fleet_converge_cli resolves
  `self` and named selectors to stable identities. srv5/srv6 gain legacy
  allocation rows recording what the probe already asserted.
- Provider guests are reached at explicitly bound public addresses
  (provider_guest_endpoints), never at an identity string, and converge
  through a ConvergeProviderGuestRoute that runs the adoption locally and
  reports adoption and microVM execution standing as separate causes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- gunbc.provider_guest_adoption provider_microvm_refusal: the provider's
  answer alone, for consumers that must refuse before observing.
- gunbc.workspace_allocation_supply: workspace_observe_host_supply refuses
  an enrolled provider guest's supply with that cause before probing any
  cell, and joins the local kernel hostname to the requested identity
  through the allocated hostname instead of string equality.
- test.claim.workspace_host_supply_refusal_witness: both CAX guests refused
  on extdeps.cloud.hetzner.cax41_catalog, srv1 not refused, and the local
  host join reads the allocation.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…VM path

The generated fleet-converge workflow offered the CAX guests as runner
hosts because fleet_hosts() had become the CI enrollment. Its consumers mean
"a host a pinned runner executes on", so fleet_hosts() now reads
gunbc.fleet_enrollment runner_executor_hosts: CI-enrolled hosts whose
backing passes gunbc.fleet_host_backing backing_microvm_forbidding_offer,
the one rule adoption, fabric supply and the executor roster all read.
The guests stay in the CI enrollment, where their refusal is visible.
Regenerated artifacts: no drift.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Operator direction 2026-10-07: replace the Census name corpus with a
fleet-owned Gen Z scheme. The CAX guests' recorded draws now yield vibe
(host-183527) and cringe (host-3dde7f); collisions lengthen to vibe-arc,
then vibe-salty-arc.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…inions)

The Minions are their own upstream module, cited to the franchise wiki's
Minions category (485 members read 2026-10-08, no continuation): 386
distinct first names folded to DNS labels. gunbc.host_names_gen_z draws
first parts from its own words followed by those names. The CAX guests'
recorded draws now yield damien (host-183527) and gus (host-3dde7f).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The operator recreated both servers 2026-10-08: host-183527 (damien) is
ubuntu-32gb-nbg1-1 at 178.104.134.135 on the Nuremberg route, and
host-3dde7f (gus) is ubuntu-32gb-hel1-1 at 62.238.115.145 on the Helsinki
route. Read-only observation from srv2 the same day: both aarch64, 16
online CPUs, MemTotal ~30.5 GiB, no /dev/kvm, Ubuntu 26.04.1 -- inside the
cax41 entitlement, and the provider's no-nesting fact confirmed on the guest.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
169308819 = ubuntu-32gb-nbg1-1 (host-183527, damien), 169308796 =
ubuntu-32gb-hel1-1 (host-3dde7f, gus), from the operator's Hetzner Cloud
console 2026-10-08. Both production rows now adopt against the observed
guest facts with microVM execution refused on the cited offer; the
unread-resource refusal stays covered by a fixture.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…te the spine

gunbc.host_standup had no imports at all: every external name (decl_ref,
the host_effect evidence rows, bmc_onboarding, os_install_mechanism,
host_converge, the assimilation deduction, millisecond, HostIdentity...)
reached it only through the whole-tree bare-name channel. claim_batch
resolves the whole tree, so its witnesses pass; the required floor
evaluates a claim in a scope built from the claim module's import closure,
where those names are not carried, so evaluating host_standup_spine raised
no-such-function the first time the spine witness was a changed witness.
The module now imports what it uses (no cycle), the Optional `Absent` that
the newly imported ObservationVerdict variant shadowed is spelled `none`,
and the stale host_assimilation_program#fold_list debt row is retired.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The mint read three plain fields (name, workflow, labels) and one existence
proof out of JitSlot = MicroVmJitSlot | HostUnitJitSlot, restating the
realization in one match per field, and carried the producers' refusals
(cell not owned, host-unit slot refused) in its own refusal vocabulary and
again in the dispatch's. Every new realization would have widened all three.

gunbc.runner.jit_registration_subject now owns a sole_constructor
JitRegistrationSubject { name, workflow, labels }, built only by the producer
arm that proved its slot exists (owned microVM cell, bound managed host), and
one carried JitRegistrationSubjectRefusal. The mint, dispatch, delivery,
deregistration subject and the launch's binding check consume the subject;
the launch compares it against the attempt's own subject. The forged-record
probe gains the subject, so its seal has an executing red.

Also fixes runner_microvm_shakedown_workflow_witness_test, which did not
compile on main (indexing a list yields an optional): it now compares the
whole label list, with a reversed-order discriminator observed red.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…inding

A host-unit slot was admitted only through gunbc.managed_host, which is a
host driven through a secured BMC whose row carries Altra facts (SMpro site,
firmware capability). A rented guest has no BMC: its provider's API is the
same out-of-band route. Widening ManagedHost would give that name a second
meaning, so gunbc.host_control_route owns the generic fact instead:

- ControlledHost (sole_constructor) = host + HostControlRoute, minted only
  on a proven route: BmcControlRoute { ManagedHostBinding } or
  ProviderApiControlRoute { route, acquisition }.
- enrolled_host_control decides it from enrollment backing, refusing with
  BmcRouteNotBound, BmcHostNotManaged, NoOutOfBandRoute (appliances) or
  ProviderResourceNotAcquired.
- runner_host_unit_slot admits through ControlledHost.

Acquisition is modeled as its own fact, separate from per-job reset
(operator 2026-10-08: CAX stock cannot be relied on, so a job must never
release a held server). gunbc.provider_acquisition records the account a
resource is held under, its API credential by Secret Manager reference,
and the three acquisition steps; today every step is OperatorPerformed.
gunbc.hetzner_cloud_acquisition records the Hetzner project "default"
(credential hetzner-cloud-default-api-key) and both CAX41 acquisitions.
ProviderResourceBound { resource_id } is replaced by ProviderResourceAcquired
{ acquisition }, so a server id and the account that drives it are one record.

Witnesses: both CAX guests controlled through the project account with
their own ids; srv1 (BMC-installed, no managed-host row) and srv5
(appliance) refuse by name; an unrecorded acquisition refuses; a forged
ControlledHost refuses at compile (probe + attributable control).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s excused by declared drop

A CAX guest cannot run the fleet's microVMs, so the guest itself is one
job's sandbox: the provider's hypervisor is beneath the job's kernel and a
rebuild from the provider's image before every job makes it fresh. The guest
is never released between jobs (release is an acquisition decision).

gunbc.runner.provider_guest_incarnation:
- ProviderRebuildReceipt: the provider's finished rebuild action for one
  acquired resource. Producer frontier: the Hetzner rebuild exchange lands
  with the controller-driven reset loop.
- ProviderGuestIncarnation (sole_constructor): controlled host + rebuild +
  adoption, joined on one resource id; rebuild or adoption of another server
  refuses by name.
- incarnation_offer: evidences DedicatedKernel, FreshWritableRoot and the
  three private namespaces (the whole guest belongs to one attempt);
  withholds AttemptScopedSecrets (earned at launch) and DefaultDenyEgress.
- admit_incarnation_work: requirement vs offer; a missing guarantee is
  excused only by an IsolationExcuse naming that guarantee, that host and
  its declared drop.

gunbc.rung_drop.provider_guest_ci_egress_unfiltered (operator ruling
2026-10-09): CI on the two CAX guests runs without default-deny egress,
Mitigatable -> OutsideTheLadder. Trigger: egress contained below the guest
(site SDN / VXLAN behind an owned router, or the provider's hypervisor) with
a filtered-egress receipt; an in-guest firewall does not satisfy it.

Witness: the enrolled nbg1 guest earns exactly five guarantees; general CI
is refused for AttemptScopedSecrets alone under the excuse and for egress
too without it; a rebuild of the hel1 server establishes nothing for nbg1;
the excuse covers only egress on the two guests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ecrets; CAX slot gets its own unit and lane label

The rebuild receipt names the attempt it was issued for; the slot and the
runner name derive from it. provider_guest_slot_for answers only to
self-hosted, gunbc-provider-guest-ci and its own unit name -- never the
fleet slot class labels (gunbc-heavy). admit_jit_credential_for is the one
credential checker for microVM and host-unit subjects; the microVM-only
subject_is_microvm_attempt is deleted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…uired-server entry, fleet-converge mode hetzner_cloud_server_read

The project token is pinned at version 1 and granted to the convergence
principal as one accessor cell (gcp_iam_converge grant set); the read is a
census row under RealizedFederatedGrant. Rebuild is declared on the surface
but has no caller until its ruling and interlock land with the reset loop.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…r a per-run ntfy approval

- gunbc.auth.branch_dispatch_federation: pool github-fleet-converge-dispatch pins repo, owner and
  workflow_dispatch only, maps run_id; hetzner-cloud-control is its first (RunScopedImpersonation)
  account, holding only the Hetzner project token.
- gunbc.auth.branch_run_grant: main job reads the branch run from GitHub, files an ntfy request, and
  on approval adds one time-conditioned workloadIdentityUser cell for exactly that run id, as
  iam-converge, reusing the gcp-iam-converge request/approval/apply machinery.
- DedicatedFederation.impersonation = StandingPoolImpersonation | RunScopedImpersonation; the estate
  plan skips an empty account-policy delta (RED: removing the skip fails
  the_converge_provisions_the_account_without_touching_its_policy).
- github.Workflows CreateDispatch carries real inputs; its unconsumed frontier rows are dissolved.
- fleet-converge.yml regenerated: hetzner_cloud_server_read awaits its grant, then authenticates
  as hetzner-cloud-control.

Pre-existing reds on the merge base, untouched: cloudflare_r2_token, fleet_converge_checkout_pin,
witness_floor_workflow_consolidation.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…d-only Hetzner token; exact-server adoption and control; no runnable guest capacity

Review 5471885603 on #13625:

1. actions: write leaves branch code. branch-run-grant-broker.yml (gunbc.branch_run_grant_broker_workflow)
   is a workflow_run workflow on requested fleet-converge runs, run by GitHub from the default branch
   on a hosted runner; it alone holds actions: write and dispatches branch_run_grant with the run id
   and attempt from the event. Fleet-converge's shared job is back to actions: read; the branch run
   only finds its grant run by title and waits (ListWorkflowRuns). No new dispatch inputs: the run key
   rides transaction_nonce, and the grant reads the mode from the run's title and maps it through
   main's run_scoped_modes table.
2. hetzner-cloud-control holds only a Read-only project token (HetznerTokenPermission, new secret
   hetzner-cloud-default-read-api-key). The Read & Write token is held by no account.
3. Attempt-exact: the provider maps attribute.run = run_id-run_attempt; facts, cell, title, preimage
   and purpose carry the attempt; judge_branch_run refuses a run GitHub has since re-run.
4. Adoption reads the guest's own server id from Hetzner metadata and refuses another resource
   (GuestIsAnotherResource), which also refuses a local observation run off the named host.
   ControlledHost for a guest requires a provider read that answered about exactly that server
   (gunbc.hetzner_cloud_server_reading, split pure from the transport).
5. ProviderRebuildReceipt is sole_constructor with no producer until the reset loop
   (test.probe.provider_rebuild_receipt_forged_probe); the launch withholds AttemptScopedSecrets.
6. Each grant removes lapsed gunbc-branch-run-* cells (as of the new run's start), keeps live ones
   and every foreign binding, written at the approved etag and read back.
7. The in-body comment the floor parse refused is moved above plan_dedicated_federation;
   microvm-shakedown.yml, fleet-converge.yml and the new broker yml regenerated.

Also: WorkflowRun.display_title; the workflow_run trigger carries its activity (WorkflowRunTriggered).
Discriminating reds, each run with its mechanism disabled: attempt check, pruning, metadata-id check
and the provider-read requirement each turned exactly their claim red.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…l-moth-86

# Conflicts:
#	docs/design-rung-drops.md
# Conflicts:
#	dag/gunbc/seed_growth_admission.dag
v1_compiler_emit_rust.rs carries main's side provisionally; regenerated in a following commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…type path-joined to std.primitives.PrimitiveContract), written once in symbol_index_fill, read by resolve and infer; 10 claims

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 24 commits October 10, 2026 03:06
import_variant_parent_for_name has no emit_info parameter; emit_specific_import_use_lines has no variant_to_enum binding.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ead exit_hook through the stream variant

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Hand-authored: 05_emit_rust keeps the partitioned EmittedRustCrate and the native-effect admission together; the planner stays in gunbc.crate_partition / gunbc.emitted_crate_workspace (src/v2/workflow/emitted_crate_workspace.dag stays deleted); integration's emit-only dry_run runtime-row mechanism is superseded by the emission-derived graph (dry_run reaches its crate by the ServiceRuntimeSurface edge), so its row and two witnesses are dropped; map_get_checked rename applied. Generated mirrors take the integration side; regen follows.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Generated files (fleet-converge.yml, design-rung-drops.md, stage0 cli dispatch) take the integration side for the single srv1 regen.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Fold the closeout tip into #13607 by name. Generated projections keep the integration side for a single srv1 regen; authored .dag conflicts keep both sides' surviving additions.

Co-authored-by: Cursor <cursoragent@cursor.com>
# Conflicts:
#	dag/gunbc/fleet/fleet_converge_workflow.dag
Generated files taken from integration (regen left to the srv1 pass); JitRegistrationSubject model kept over JitSlot, sealed BoundJitCredential carries the subject-bearing dispatch; srv5-srv12 not reintroduced.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…e; declare fixture residue as a rung drop

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Keeps #13544 deletions (srv5-srv6 rows/witnesses, Group A modes) and #13607 WorkspaceAllocationPlan/WorkspaceImageBuild/ci_fleet_wif_auth_step_when; PR's HetznerCloudServerRead/BranchRunGrant modes retained; ci_wif_auth_step_with_id_when folded onto integration's ci_wif_auth_step_with_condition.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Integration's removal of HealPublisher*/heal-publish kept (heal_publisher_workflow.dag stays deleted); BranchRunGrantBroker artifact and workflow added alongside.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…oduction rosters stay empty

Chain: the scoped cut emptied dgx_spark_reserved_identities and the router bindings, so witnesses that
discriminated on the Group B population (commitment standings, admissibility, rail rows, topology
membership, reach labels) read nothing. spark_host_commitment_witness now folds the production
placement, claim and reservation rows over a local four-host fixture, with one inhabitance claim that
the production roster is empty; the topology, reach and site-locale witnesses are re-derived to the
emptied rosters. Under rung drop serving_fixtures_name_sold_group_b_hosts.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
#13662 (headless Claude worker) stays outside the closeout. A child re-lands it into main after #13641, with its review findings resolved.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbc.roadmap.dashboard_instance_directories imported gunbc.roadmap.roadmap_event_carrier for one
directory function, and through it the dispatch actuator. With #13625's host_standup -> host_effect
import (c390a49), that closed a 13-module cycle (materialized_secret -> host_phase_status ->
host_standup -> host_effect -> live_deploy.spec -> dashboard_instance_directories ->
roadmap_event_carrier -> roadmap_dispatch_actuator -> cursor_harness_credential -> ...), and main_wet
refused to resolve. The demand moves unchanged to gunbc.roadmap.roadmap_event_carrier_directory;
the carrier, the directory list and the owned-directory witness import it from there.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls marked this pull request as ready for review October 10, 2026 03:56
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-10T04:01:30.982449Z eaf8b6d Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Closing: this was auto-opened for session keen-owl-192 (the DESIGN.md/docs recut lane), which closed with no edits — its branch is the integration/v1-closeout tip (eaf8b6d) with nothing on top, so the failing check is the closeout's own, not this PR's. The recut is being taken separately by the operator with the brief in smart-gull-336's hand-off; nothing to review here.

— sent from smart-gull-336

@gunbai-bot gunbai-bot Bot closed this Oct 10, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: eaf8b6d96b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@@ -483,7 +420,7 @@ fn fleet_converge_spark_target_description() -> String {
], "")
}

data fleet_converge_workflow_modes: List<FleetConvergeWorkflowMode> = [FullHostPlan, LaunchEnvironmentPlan, AllocationStorePlan, WorkspaceCommissioningPlan, FleetApply, OrgActionsObserve, AppControlPlaneObserve, MicrovmHostConverge, MicrovmNetworkObserve, MicrovmNetworkApply, GuestImageObserve, GuestImageConverge, MicrovmBootProbe, SparkGrants, SparkBootstrap, SparkServingApply, SparkNativeServingApply, SparkRuntimeImageProbe, SparkWirelessLinkConverge, SparkGrantsObserve, SparkV41CheckpointMaterialize, SparkV41RowStoreEncode, SparkV41RowStoreReadback, SparkV41EngramDifferential, SparkRuntimeImageProduce, SparkRuntimeImageDistribute, SparkArmGroupLoad, SparkArmCheckpointMaterialize, SparkArmGroupObserve, SparkArmGroupLaunchPlan, SparkArmGroupLaunch, SparkV41ServingLoad, DashboardDeploy, ApprovalBrokerDarkInstall, MicrovmControllerInstall, MicrovmSlotReserve, MicrovmSlotStart, RlmLaunchDeploymentReceipt, HostResetReturn, RunnerHostFileObserve, RunnerHostFileConverge, SitePxeEdgeObserve, SitePxeEdgeConverge, RunnerPasswordSessionToolConverge, RunnerBrowserToolchainConverge, R2MintPreflight, R2ObjectWriteMint, OrgRunnerRosterObserve, ApprovalKeyringConverge, ApprovalDeviceEnrolmentCodeIssue, MtCollins1Boot, MtCollins1FanObserve, MtCollins1UiBundleObserve, MtCollins1KvmObserverObserve, MtCollins1CensusImagePublish, MtCollins1CensusMemberReadback, MtCollins1CensusQemuHostObserve, MtCollins1CensusQemuToolchainConverge, HostCredentialCustodyConverge, AppKeyVersionVerify, R2BucketEnsure, R2BucketAdminMint, R2WorkspaceObjectReadMint, R2WorkspaceObjectWriteMint, R2CacheObjectReadMint, R2CacheObjectWriteMint, R2ConditionalPutRaceProbe, WorkspaceSourcePack, WorkspaceCheckpointMeasure, WorkspaceCheckpointRestore, FabricWriterIdentityObserve, PairServingD0, MicrovmRunnerGroupEnsure, GcpIamConverge, NamecheapObserve, PrinterWorkflow]
data fleet_converge_workflow_modes: List<FleetConvergeWorkflowMode> = [FullHostPlan, LaunchEnvironmentPlan, AllocationStorePlan, WorkspaceCommissioningPlan, WorkspaceAllocationPlan, WorkspaceImageBuild, FleetApply, OrgActionsObserve, AppControlPlaneObserve, MicrovmHostConverge, MicrovmNetworkObserve, MicrovmNetworkApply, GuestImageObserve, GuestImageConverge, MicrovmBootProbe, SparkGrants, SparkBootstrap, SparkServingApply, SparkNativeServingApply, SparkRuntimeImageProbe, SparkWirelessLinkConverge, SparkGrantsObserve, DashboardDeploy, ApprovalBrokerDarkInstall, MicrovmControllerInstall, MicrovmSlotReserve, MicrovmSlotStart, RlmLaunchDeploymentReceipt, HostResetReturn, RunnerHostFileObserve, RunnerHostFileConverge, SitePxeEdgeObserve, SitePxeEdgeConverge, RunnerPasswordSessionToolConverge, RunnerBrowserToolchainConverge, R2MintPreflight, R2ObjectWriteMint, OrgRunnerRosterObserve, ApprovalKeyringConverge, ApprovalDeviceEnrolmentCodeIssue, MtCollins1Boot, MtCollins1FanObserve, MtCollins1KvmObserverObserve, MtCollins1CensusImagePublish, MtCollins1CensusMemberReadback, MtCollins1CensusQemuHostObserve, MtCollins1CensusQemuToolchainConverge, HostCredentialCustodyConverge, AppKeyVersionVerify, R2BucketEnsure, R2BucketAdminMint, R2WorkspaceObjectReadMint, R2WorkspaceObjectWriteMint, R2CacheObjectReadMint, R2CacheObjectWriteMint, R2ConditionalPutRaceProbe, WorkspaceSourcePack, WorkspaceCheckpointMeasure, WorkspaceCheckpointRestore, WorkspaceTranscriptRateObserve, FabricWriterIdentityObserve, MicrovmRunnerGroupEnsure, GcpIamConverge, NamecheapObserve, PrinterWorkflow, ArrivalConverge, HetznerCloudServerRead, BranchRunGrant]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Regenerate the workflow with the new fleet modes

Adding HetznerCloudServerRead and BranchRunGrant here does not make either mode runnable because the committed .github/workflows/fleet-converge.yml contains neither mode in its mode choices and contains none of the new await/grant/Hetzner steps. Consequently the new broker's title condition cannot be reached through the published workflow, and even a caller that submits the raw mode string would run a job in which all relevant steps are absent. Regenerate and commit the fleet-converge projection from this updated authority.

Useful? React with 👍 / 👎.

workflow_run:
workflows: [fleet-converge]
branches: ["**"]
types: [requested]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Trigger grant brokerage for rerun attempts

When an operator reruns a hetzner_cloud_server_read fleet run, this trigger never starts the broker: GitHub documents that the requested activity does not occur for workflow reruns. The rerun nevertheless increments github.run_attempt, and branch_run_grant_await waits for a grant keyed by that new attempt, so it waits up to 40 minutes and fails because no matching grant run was dispatched. Use an activity or explicit rerun path that fires for every attempt.

Useful? React with 👍 / 👎.

@gunbai-bot gunbai-bot Bot mentioned this pull request Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants