Skip to content

Model the remote artifact broker as optional - #1103

Merged
teamleaderleo merged 1 commit into
mainfrom
artifact-optional-remote-broker
Sep 22, 2026
Merged

teamleaderleo merged 1 commit into
mainfrom
artifact-optional-remote-broker

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Refs #1068.

Summary

Make the immutable artifact distribution contract represent the topology decision in #1068 explicitly:

  • same-site persistent fleet: node local -> trusted peer -> GitHub Actions -> rebuild;
  • optional remote-broker fleet: node local -> trusted peer -> private R2 -> GitHub Actions -> rebuild.

R2 remains a source class for source-specific observations, but broker presence is no longer baked into the only lookup-order API.

Contract

The change keeps exact object identity, producer provenance, compatibility, and validation authority unchanged. It only separates source-policy configuration from product correctness.

ImmutableArtifactSourceClass now exposes:

  • same_site_first_lookup_order();
  • with_private_r2_lookup_order().

The regression test asserts both orders and keeps GitHub/rebuild fallback present in either policy.

Why

Persistent co-located CMUX nodes should use local disk and same-site peers as the ordinary acceleration path. A remote broker earns activation for off-site distribution, resilience, retention, or measured residual GitHub cost; it is not required for correctness.

Verification

Exact head 5a218d6a7d6e673e4c37e7b62aa4c5411485d05e is green in hosted Verify and Linux acceptance; Cultist advisory also completed successfully.

No physical fleet mutation or credential/configuration change is included.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant