Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 10 additions & 9 deletions docs/contributing/architecture/runtime-worker-migration-runbook.md
Original file line number Diff line number Diff line change
Expand Up @@ -171,15 +171,16 @@ npm run deploy -- --config packages/worker/wrangler-production.generated.json
A class that arrived on `kody-runtime` through `transferred_classes` keeps a
remote binding until a deploy publishes config without that binding. Cloudflare
rejects a same-deploy `deleted_classes` migration while that binding still
exists (error 10061). Drop the binding first, then add the `deleted_classes`
migration and its `tools/ci/do-deletion-allowlist.json` entry on a later deploy.

`PackageServiceInstance` is in that window on production: the transferred
binding is still present, so top-level runtime-worker tag `v2` is deferred until
after the binding-only deploy. Preview keeps `v2` and the matching
`tools/ci/do-deletion-allowlist.json` entry because a fresh worker applies `v1`
`new_sqlite_classes` and cannot create an unexported class (error 10070). The
follow-up reuses that allowlist entry when it restores top-level `v2`.
exists (error 10061). Existing objects also require the script to keep exporting
the class until `deleted_classes` runs (error 10064). Export a stub, drop the
binding, then add the `deleted_classes` migration and its
`tools/ci/do-deletion-allowlist.json` entry on a later deploy.

`PackageServiceInstance` is in that window: the runtime worker exports a stub
and omits tag `v2` so production can drop the remote binding. Preview also omits
`v2` while the stub is exported; `deleted_classes` fails with error 10074 when
the previous script version did not export the class. The allowlist entry stays
for the follow-up that restores `v2` and removes the stub.

## Rollback

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,10 +37,11 @@ discovering those storage ids until that purge succeeds.

Deleting `PackageServiceInstance` on production `kody-runtime` is two deploys.
The class arrived through a `transferred_classes` migration, so Cloudflare still
has a remote binding after the source binding is gone. A same-deploy
`deleted_classes` migration fails with error 10061. Drop the remote binding
first, then apply top-level runtime-worker tag `v2` `deleted_classes`. The
`tools/ci/do-deletion-allowlist.json` entry for that tag stays for preview `v2`
and is the same contract the follow-up reuses. Preview keeps `v2` because a
fresh worker applies `v1` `new_sqlite_classes` and cannot create an unexported
class (error 10070).
has a remote binding and existing objects after the source binding is gone. A
same-deploy `deleted_classes` migration fails with error 10061. Dropping the
binding without exporting the class fails with error 10064. Export a stub, drop
the remote binding, then apply runtime-worker tag `v2` `deleted_classes` and
remove the stub. The `tools/ci/do-deletion-allowlist.json` entry for that tag
stays for the follow-up. Preview also omits `v2` while the stub is exported:
`deleted_classes` fails with error 10074 when the previous script version did
not export the class.
16 changes: 7 additions & 9 deletions packages/runtime-worker/wrangler.jsonc
Original file line number Diff line number Diff line change
Expand Up @@ -74,11 +74,13 @@
},
],
},
// Production still has the transferred PackageServiceInstance
// binding (error 10061). Do not add deleted_classes here until
// after this binding-only deploy lands. Preview keeps tag v2
// because a fresh worker applies v1 new_sqlite_classes and
// cannot create an unexported class (error 10070).
// Production still has transferred PackageServiceInstance
// objects. deleted_classes while the remote binding exists is
// error 10061; dropping the binding without exporting the class
// is error 10064. Export the stub and omit the binding here.
// Add tag v2 after this deploy. Preview also omits v2: a
// delete-class on a script whose previous version did not
// export the class is error 10074.
],
"observability": {
"enabled": true,
Expand Down Expand Up @@ -268,10 +270,6 @@
"PackageServiceInstance",
],
},
{
"tag": "v2",
"deleted_classes": ["PackageServiceInstance"],
},
],
"worker_loaders": [
{
Expand Down
9 changes: 9 additions & 0 deletions packages/worker/src/package-service-instance-stub.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
import { DurableObject } from 'cloudflare:workers'

/**
* Temporary export so production `kody-runtime` can drop the transferred
* `PackageServiceInstance` binding. Existing Durable Objects still require
* the class to be exported (Cloudflare error 10064). Remove this module when
* top-level runtime-worker tag `v2` `deleted_classes` lands.
*/
export class PackageServiceInstance extends DurableObject<Env> {}
2 changes: 2 additions & 0 deletions packages/worker/src/runtime-worker.ts
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ import {
} from '@kody-internal/shared/runtime-worker.ts'
import { StorageRunner } from './storage-runner.ts'
import { RunLog } from './run-records/run-log-do.ts'
import { PackageServiceInstance } from './package-service-instance-stub.ts'
import { PackageRealtimeSession } from '#worker/package-runtime/realtime-session.ts'
import { DynamicCallableWorkflow } from '#worker/package-runtime/package-workflows.ts'
import { PackageAppRuntimeBridge } from '#worker/package-runtime/package-app.ts'
Expand Down Expand Up @@ -41,6 +42,7 @@ export {
StorageRunner,
RunLog,
PackageRealtimeSession,
PackageServiceInstance,
DynamicCallableWorkflow,
PackageAppRuntimeBridge,
KodyFetchGateway,
Expand Down
Loading