Repository navigation
Conversation
…BMC steps - gunbc.fleet_host_backing: OwnedMachine carries its OwnedProvisioning (BmcVirtualMediaInstall | ApplianceFirstBoot); a ProviderGuest's OS is the provider's image by construction, so a rented guest owing a BMC operation has no constructor. - gunbc.host_standup gains the ProviderGuestAdopted prefix phase; the assimilation program selects prefix steps by backing (prefix_phase_applies) and assimilation steps by participation, so the CAX guests owe adoption + their CI roles and no BMC/virtual-media step. - gunbc.provider_guest_adoption: bound provider resource, entitlement-bounded observation (uname -m/-n, _NPROCESSORS_ONLN, /proc/meminfo, /dev/kvm over host_command), and a MicroVmExecutionStanding carried beside adoption: Hetzner's cited no-nested-virtualization fact refuses the Firecracker path. - extdeps: uname_machine_command / uname_nodename_command / uname_machine_architecture, getconf_online_processors_command (admitted on argv_command's caller list). - os_install_actuator_selection_witness: the same pre-existing optional==required compares, so its witness runs again. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ollment root - Population lists derive from gunbc.fleet_enrollment: runner_host_deploy's resolutions (one per enrolled CI host, Unmodeled where no spec exists), runner_slot_allocation standings, ci_fleet fleet_intent_offers (filtered from the owned offer catalog), and fleet_reach_endpoint's probe roster. - runner_host_deploy: the two four-arm srvN switches become one keyed runner_host_spec_rows lookup; specs stay per-host facts. - Name/identity seam goes through gunbc.hostname_allocation: host_reach_identity_probe compares against the allocated hostname (UnknownRefused when none), workspace_tool_observer joins the kernel hostname to the slot via the allocation, and fleet_converge_cli resolves `self` and named selectors to stable identities. srv5/srv6 gain legacy allocation rows recording what the probe already asserted. - Provider guests are reached at explicitly bound public addresses (provider_guest_endpoints), never at an identity string, and converge through a ConvergeProviderGuestRoute that runs the adoption locally and reports adoption and microVM execution standing as separate causes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- gunbc.provider_guest_adoption provider_microvm_refusal: the provider's answer alone, for consumers that must refuse before observing. - gunbc.workspace_allocation_supply: workspace_observe_host_supply refuses an enrolled provider guest's supply with that cause before probing any cell, and joins the local kernel hostname to the requested identity through the allocated hostname instead of string equality. - test.claim.workspace_host_supply_refusal_witness: both CAX guests refused on extdeps.cloud.hetzner.cax41_catalog, srv1 not refused, and the local host join reads the allocation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…VM path The generated fleet-converge workflow offered the CAX guests as runner hosts because fleet_hosts() had become the CI enrollment. Its consumers mean "a host a pinned runner executes on", so fleet_hosts() now reads gunbc.fleet_enrollment runner_executor_hosts: CI-enrolled hosts whose backing passes gunbc.fleet_host_backing backing_microvm_forbidding_offer, the one rule adoption, fabric supply and the executor roster all read. The guests stay in the CI enrollment, where their refusal is visible. Regenerated artifacts: no drift. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Operator direction 2026-10-07: replace the Census name corpus with a fleet-owned Gen Z scheme. The CAX guests' recorded draws now yield vibe (host-183527) and cringe (host-3dde7f); collisions lengthen to vibe-arc, then vibe-salty-arc. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…inions) The Minions are their own upstream module, cited to the franchise wiki's Minions category (485 members read 2026-10-08, no continuation): 386 distinct first names folded to DNS labels. gunbc.host_names_gen_z draws first parts from its own words followed by those names. The CAX guests' recorded draws now yield damien (host-183527) and gus (host-3dde7f). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The operator recreated both servers 2026-10-08: host-183527 (damien) is ubuntu-32gb-nbg1-1 at 178.104.134.135 on the Nuremberg route, and host-3dde7f (gus) is ubuntu-32gb-hel1-1 at 62.238.115.145 on the Helsinki route. Read-only observation from srv2 the same day: both aarch64, 16 online CPUs, MemTotal ~30.5 GiB, no /dev/kvm, Ubuntu 26.04.1 -- inside the cax41 entitlement, and the provider's no-nesting fact confirmed on the guest. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
169308819 = ubuntu-32gb-nbg1-1 (host-183527, damien), 169308796 = ubuntu-32gb-hel1-1 (host-3dde7f, gus), from the operator's Hetzner Cloud console 2026-10-08. Both production rows now adopt against the observed guest facts with microVM execution refused on the cited offer; the unread-resource refusal stays covered by a fixture. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…te the spine gunbc.host_standup had no imports at all: every external name (decl_ref, the host_effect evidence rows, bmc_onboarding, os_install_mechanism, host_converge, the assimilation deduction, millisecond, HostIdentity...) reached it only through the whole-tree bare-name channel. claim_batch resolves the whole tree, so its witnesses pass; the required floor evaluates a claim in a scope built from the claim module's import closure, where those names are not carried, so evaluating host_standup_spine raised no-such-function the first time the spine witness was a changed witness. The module now imports what it uses (no cycle), the Optional `Absent` that the newly imported ObservationVerdict variant shadowed is spelled `none`, and the stale host_assimilation_program#fold_list debt row is retired. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The mint read three plain fields (name, workflow, labels) and one existence
proof out of JitSlot = MicroVmJitSlot | HostUnitJitSlot, restating the
realization in one match per field, and carried the producers' refusals
(cell not owned, host-unit slot refused) in its own refusal vocabulary and
again in the dispatch's. Every new realization would have widened all three.
gunbc.runner.jit_registration_subject now owns a sole_constructor
JitRegistrationSubject { name, workflow, labels }, built only by the producer
arm that proved its slot exists (owned microVM cell, bound managed host), and
one carried JitRegistrationSubjectRefusal. The mint, dispatch, delivery,
deregistration subject and the launch's binding check consume the subject;
the launch compares it against the attempt's own subject. The forged-record
probe gains the subject, so its seal has an executing red.
Also fixes runner_microvm_shakedown_workflow_witness_test, which did not
compile on main (indexing a list yields an optional): it now compares the
whole label list, with a reversed-order discriminator observed red.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…inding
A host-unit slot was admitted only through gunbc.managed_host, which is a
host driven through a secured BMC whose row carries Altra facts (SMpro site,
firmware capability). A rented guest has no BMC: its provider's API is the
same out-of-band route. Widening ManagedHost would give that name a second
meaning, so gunbc.host_control_route owns the generic fact instead:
- ControlledHost (sole_constructor) = host + HostControlRoute, minted only
on a proven route: BmcControlRoute { ManagedHostBinding } or
ProviderApiControlRoute { route, acquisition }.
- enrolled_host_control decides it from enrollment backing, refusing with
BmcRouteNotBound, BmcHostNotManaged, NoOutOfBandRoute (appliances) or
ProviderResourceNotAcquired.
- runner_host_unit_slot admits through ControlledHost.
Acquisition is modeled as its own fact, separate from per-job reset
(operator 2026-10-08: CAX stock cannot be relied on, so a job must never
release a held server). gunbc.provider_acquisition records the account a
resource is held under, its API credential by Secret Manager reference,
and the three acquisition steps; today every step is OperatorPerformed.
gunbc.hetzner_cloud_acquisition records the Hetzner project "default"
(credential hetzner-cloud-default-api-key) and both CAX41 acquisitions.
ProviderResourceBound { resource_id } is replaced by ProviderResourceAcquired
{ acquisition }, so a server id and the account that drives it are one record.
Witnesses: both CAX guests controlled through the project account with
their own ids; srv1 (BMC-installed, no managed-host row) and srv5
(appliance) refuse by name; an unrecorded acquisition refuses; a forged
ControlledHost refuses at compile (probe + attributable control).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s excused by declared drop A CAX guest cannot run the fleet's microVMs, so the guest itself is one job's sandbox: the provider's hypervisor is beneath the job's kernel and a rebuild from the provider's image before every job makes it fresh. The guest is never released between jobs (release is an acquisition decision). gunbc.runner.provider_guest_incarnation: - ProviderRebuildReceipt: the provider's finished rebuild action for one acquired resource. Producer frontier: the Hetzner rebuild exchange lands with the controller-driven reset loop. - ProviderGuestIncarnation (sole_constructor): controlled host + rebuild + adoption, joined on one resource id; rebuild or adoption of another server refuses by name. - incarnation_offer: evidences DedicatedKernel, FreshWritableRoot and the three private namespaces (the whole guest belongs to one attempt); withholds AttemptScopedSecrets (earned at launch) and DefaultDenyEgress. - admit_incarnation_work: requirement vs offer; a missing guarantee is excused only by an IsolationExcuse naming that guarantee, that host and its declared drop. gunbc.rung_drop.provider_guest_ci_egress_unfiltered (operator ruling 2026-10-09): CI on the two CAX guests runs without default-deny egress, Mitigatable -> OutsideTheLadder. Trigger: egress contained below the guest (site SDN / VXLAN behind an owned router, or the provider's hypervisor) with a filtered-egress receipt; an in-guest firewall does not satisfy it. Witness: the enrolled nbg1 guest earns exactly five guarantees; general CI is refused for AttemptScopedSecrets alone under the excuse and for egress too without it; a rebuild of the hel1 server establishes nothing for nbg1; the excuse covers only egress on the two guests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ecrets; CAX slot gets its own unit and lane label The rebuild receipt names the attempt it was issued for; the slot and the runner name derive from it. provider_guest_slot_for answers only to self-hosted, gunbc-provider-guest-ci and its own unit name -- never the fleet slot class labels (gunbc-heavy). admit_jit_credential_for is the one credential checker for microVM and host-unit subjects; the microVM-only subject_is_microvm_attempt is deleted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…uired-server entry, fleet-converge mode hetzner_cloud_server_read The project token is pinned at version 1 and granted to the convergence principal as one accessor cell (gcp_iam_converge grant set); the read is a census row under RealizedFederatedGrant. Rebuild is declared on the surface but has no caller until its ruling and interlock land with the reset loop. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…r a per-run ntfy approval - gunbc.auth.branch_dispatch_federation: pool github-fleet-converge-dispatch pins repo, owner and workflow_dispatch only, maps run_id; hetzner-cloud-control is its first (RunScopedImpersonation) account, holding only the Hetzner project token. - gunbc.auth.branch_run_grant: main job reads the branch run from GitHub, files an ntfy request, and on approval adds one time-conditioned workloadIdentityUser cell for exactly that run id, as iam-converge, reusing the gcp-iam-converge request/approval/apply machinery. - DedicatedFederation.impersonation = StandingPoolImpersonation | RunScopedImpersonation; the estate plan skips an empty account-policy delta (RED: removing the skip fails the_converge_provisions_the_account_without_touching_its_policy). - github.Workflows CreateDispatch carries real inputs; its unconsumed frontier rows are dissolved. - fleet-converge.yml regenerated: hetzner_cloud_server_read awaits its grant, then authenticates as hetzner-cloud-control. Pre-existing reds on the merge base, untouched: cloudflare_r2_token, fleet_converge_checkout_pin, witness_floor_workflow_consolidation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…d-only Hetzner token; exact-server adoption and control; no runnable guest capacity Review 5471885603 on #13625: 1. actions: write leaves branch code. branch-run-grant-broker.yml (gunbc.branch_run_grant_broker_workflow) is a workflow_run workflow on requested fleet-converge runs, run by GitHub from the default branch on a hosted runner; it alone holds actions: write and dispatches branch_run_grant with the run id and attempt from the event. Fleet-converge's shared job is back to actions: read; the branch run only finds its grant run by title and waits (ListWorkflowRuns). No new dispatch inputs: the run key rides transaction_nonce, and the grant reads the mode from the run's title and maps it through main's run_scoped_modes table. 2. hetzner-cloud-control holds only a Read-only project token (HetznerTokenPermission, new secret hetzner-cloud-default-read-api-key). The Read & Write token is held by no account. 3. Attempt-exact: the provider maps attribute.run = run_id-run_attempt; facts, cell, title, preimage and purpose carry the attempt; judge_branch_run refuses a run GitHub has since re-run. 4. Adoption reads the guest's own server id from Hetzner metadata and refuses another resource (GuestIsAnotherResource), which also refuses a local observation run off the named host. ControlledHost for a guest requires a provider read that answered about exactly that server (gunbc.hetzner_cloud_server_reading, split pure from the transport). 5. ProviderRebuildReceipt is sole_constructor with no producer until the reset loop (test.probe.provider_rebuild_receipt_forged_probe); the launch withholds AttemptScopedSecrets. 6. Each grant removes lapsed gunbc-branch-run-* cells (as of the new run's start), keeps live ones and every foreign binding, written at the approved etag and read back. 7. The in-body comment the floor parse refused is moved above plan_dedicated_federation; microvm-shakedown.yml, fleet-converge.yml and the new broker yml regenerated. Also: WorkflowRun.display_title; the workflow_run trigger carries its activity (WorkflowRunTriggered). Discriminating reds, each run with its mechanism disabled: attempt check, pruning, metadata-id check and the provider-read requirement each turned exactly their claim red. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…l-moth-86 # Conflicts: # docs/design-rung-drops.md
# Conflicts: # dag/gunbc/seed_growth_admission.dag
v1_compiler_emit_rust.rs carries main's side provisionally; regenerated in a following commit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… into integration/silent-lark-156
…type path-joined to std.primitives.PrimitiveContract), written once in symbol_index_fill, read by resolve and infer; 10 claims Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…egration/swift-ibex-601
import_variant_parent_for_name has no emit_info parameter; emit_specific_import_use_lines has no variant_to_enum binding. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ead exit_hook through the stream variant Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Hand-authored: 05_emit_rust keeps the partitioned EmittedRustCrate and the native-effect admission together; the planner stays in gunbc.crate_partition / gunbc.emitted_crate_workspace (src/v2/workflow/emitted_crate_workspace.dag stays deleted); integration's emit-only dry_run runtime-row mechanism is superseded by the emission-derived graph (dry_run reaches its crate by the ServiceRuntimeSurface edge), so its row and two witnesses are dropped; map_get_checked rename applied. Generated mirrors take the integration side; regen follows. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Generated files (fleet-converge.yml, design-rung-drops.md, stage0 cli dispatch) take the integration side for the single srv1 regen. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Fold the closeout tip into #13607 by name. Generated projections keep the integration side for a single srv1 regen; authored .dag conflicts keep both sides' surviving additions. Co-authored-by: Cursor <cursoragent@cursor.com>
# Conflicts: # dag/gunbc/fleet/fleet_converge_workflow.dag
Generated files taken from integration (regen left to the srv1 pass); JitRegistrationSubject model kept over JitSlot, sealed BoundJitCredential carries the subject-bearing dispatch; srv5-srv12 not reintroduced. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…16653087 green)
…e; declare fixture residue as a rung drop Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Keeps #13544 deletions (srv5-srv6 rows/witnesses, Group A modes) and #13607 WorkspaceAllocationPlan/WorkspaceImageBuild/ci_fleet_wif_auth_step_when; PR's HetznerCloudServerRead/BranchRunGrant modes retained; ci_wif_auth_step_with_id_when folded onto integration's ci_wif_auth_step_with_condition. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Integration's removal of HealPublisher*/heal-publish kept (heal_publisher_workflow.dag stays deleted); BranchRunGrantBroker artifact and workflow added alongside. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…oduction rosters stay empty Chain: the scoped cut emptied dgx_spark_reserved_identities and the router bindings, so witnesses that discriminated on the Group B population (commitment standings, admissibility, rail rows, topology membership, reach labels) read nothing. spark_host_commitment_witness now folds the production placement, claim and reservation rows over a local four-host fixture, with one inhabitance claim that the production roster is empty; the topology, reach and site-locale witnesses are re-derived to the emptied rosters. Under rung drop serving_fixtures_name_sold_group_b_hosts. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
gunbc.roadmap.dashboard_instance_directories imported gunbc.roadmap.roadmap_event_carrier for one directory function, and through it the dispatch actuator. With #13625's host_standup -> host_effect import (c390a49), that closed a 13-module cycle (materialized_secret -> host_phase_status -> host_standup -> host_effect -> live_deploy.spec -> dashboard_instance_directories -> roadmap_event_carrier -> roadmap_dispatch_actuator -> cursor_harness_credential -> ...), and main_wet refused to resolve. The demand moves unchanged to gunbc.roadmap.roadmap_event_carrier_directory; the carrier, the directory list and the owned-directory witness import it from there. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Closing: this was auto-opened for session keen-owl-192 (the DESIGN.md/docs recut lane), which closed with no edits — its branch is the integration/v1-closeout tip (eaf8b6d) with nothing on top, so the failing check is the closeout's own, not this PR's. The recut is being taken separately by the operator with the brief in smart-gull-336's hand-off; nothing to review here. — sent from smart-gull-336 |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: eaf8b6d96b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| @@ -483,7 +420,7 @@ fn fleet_converge_spark_target_description() -> String { | |||
| ], "") | |||
| } | |||
|
|
|||
| data fleet_converge_workflow_modes: List<FleetConvergeWorkflowMode> = [FullHostPlan, LaunchEnvironmentPlan, AllocationStorePlan, WorkspaceCommissioningPlan, FleetApply, OrgActionsObserve, AppControlPlaneObserve, MicrovmHostConverge, MicrovmNetworkObserve, MicrovmNetworkApply, GuestImageObserve, GuestImageConverge, MicrovmBootProbe, SparkGrants, SparkBootstrap, SparkServingApply, SparkNativeServingApply, SparkRuntimeImageProbe, SparkWirelessLinkConverge, SparkGrantsObserve, SparkV41CheckpointMaterialize, SparkV41RowStoreEncode, SparkV41RowStoreReadback, SparkV41EngramDifferential, SparkRuntimeImageProduce, SparkRuntimeImageDistribute, SparkArmGroupLoad, SparkArmCheckpointMaterialize, SparkArmGroupObserve, SparkArmGroupLaunchPlan, SparkArmGroupLaunch, SparkV41ServingLoad, DashboardDeploy, ApprovalBrokerDarkInstall, MicrovmControllerInstall, MicrovmSlotReserve, MicrovmSlotStart, RlmLaunchDeploymentReceipt, HostResetReturn, RunnerHostFileObserve, RunnerHostFileConverge, SitePxeEdgeObserve, SitePxeEdgeConverge, RunnerPasswordSessionToolConverge, RunnerBrowserToolchainConverge, R2MintPreflight, R2ObjectWriteMint, OrgRunnerRosterObserve, ApprovalKeyringConverge, ApprovalDeviceEnrolmentCodeIssue, MtCollins1Boot, MtCollins1FanObserve, MtCollins1UiBundleObserve, MtCollins1KvmObserverObserve, MtCollins1CensusImagePublish, MtCollins1CensusMemberReadback, MtCollins1CensusQemuHostObserve, MtCollins1CensusQemuToolchainConverge, HostCredentialCustodyConverge, AppKeyVersionVerify, R2BucketEnsure, R2BucketAdminMint, R2WorkspaceObjectReadMint, R2WorkspaceObjectWriteMint, R2CacheObjectReadMint, R2CacheObjectWriteMint, R2ConditionalPutRaceProbe, WorkspaceSourcePack, WorkspaceCheckpointMeasure, WorkspaceCheckpointRestore, FabricWriterIdentityObserve, PairServingD0, MicrovmRunnerGroupEnsure, GcpIamConverge, NamecheapObserve, PrinterWorkflow] | |||
| data fleet_converge_workflow_modes: List<FleetConvergeWorkflowMode> = [FullHostPlan, LaunchEnvironmentPlan, AllocationStorePlan, WorkspaceCommissioningPlan, WorkspaceAllocationPlan, WorkspaceImageBuild, FleetApply, OrgActionsObserve, AppControlPlaneObserve, MicrovmHostConverge, MicrovmNetworkObserve, MicrovmNetworkApply, GuestImageObserve, GuestImageConverge, MicrovmBootProbe, SparkGrants, SparkBootstrap, SparkServingApply, SparkNativeServingApply, SparkRuntimeImageProbe, SparkWirelessLinkConverge, SparkGrantsObserve, DashboardDeploy, ApprovalBrokerDarkInstall, MicrovmControllerInstall, MicrovmSlotReserve, MicrovmSlotStart, RlmLaunchDeploymentReceipt, HostResetReturn, RunnerHostFileObserve, RunnerHostFileConverge, SitePxeEdgeObserve, SitePxeEdgeConverge, RunnerPasswordSessionToolConverge, RunnerBrowserToolchainConverge, R2MintPreflight, R2ObjectWriteMint, OrgRunnerRosterObserve, ApprovalKeyringConverge, ApprovalDeviceEnrolmentCodeIssue, MtCollins1Boot, MtCollins1FanObserve, MtCollins1KvmObserverObserve, MtCollins1CensusImagePublish, MtCollins1CensusMemberReadback, MtCollins1CensusQemuHostObserve, MtCollins1CensusQemuToolchainConverge, HostCredentialCustodyConverge, AppKeyVersionVerify, R2BucketEnsure, R2BucketAdminMint, R2WorkspaceObjectReadMint, R2WorkspaceObjectWriteMint, R2CacheObjectReadMint, R2CacheObjectWriteMint, R2ConditionalPutRaceProbe, WorkspaceSourcePack, WorkspaceCheckpointMeasure, WorkspaceCheckpointRestore, WorkspaceTranscriptRateObserve, FabricWriterIdentityObserve, MicrovmRunnerGroupEnsure, GcpIamConverge, NamecheapObserve, PrinterWorkflow, ArrivalConverge, HetznerCloudServerRead, BranchRunGrant] | |||
There was a problem hiding this comment.
Regenerate the workflow with the new fleet modes
Adding HetznerCloudServerRead and BranchRunGrant here does not make either mode runnable because the committed .github/workflows/fleet-converge.yml contains neither mode in its mode choices and contains none of the new await/grant/Hetzner steps. Consequently the new broker's title condition cannot be reached through the published workflow, and even a caller that submits the raw mode string would run a job in which all relevant steps are absent. Regenerate and commit the fleet-converge projection from this updated authority.
Useful? React with 👍 / 👎.
| workflow_run: | ||
| workflows: [fleet-converge] | ||
| branches: ["**"] | ||
| types: [requested] |
There was a problem hiding this comment.
Trigger grant brokerage for rerun attempts
When an operator reruns a hetzner_cloud_server_read fleet run, this trigger never starts the broker: GitHub documents that the requested activity does not occur for workflow reruns. The rerun nevertheless increments github.run_attempt, and branch_run_grant_await waits for a grant keyed by that new attempt, so it waits up to 40 minutes and fails because no matching grant run was dispatched. Use an activity or explicit rerun path that fires for every attempt.
Useful? React with 👍 / 👎.
Auto-opened by session-dashboard for session
keen-owl-192.Pushing to
session/keen-owl-192advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan