Skip to content

Propose opt-in feature recovery and reconciliation protocol - #64

Draft
anoopath wants to merge 1 commit into
aws:mainfrom
anoopath:proposal/feature-recovery-reconciliation
Draft

anoopath wants to merge 1 commit into
aws:mainfrom
anoopath:proposal/feature-recovery-reconciliation

Conversation

@anoopath

Copy link
Copy Markdown

Summary

Draft specification proposal for an explicitly opted-in Feature Recovery and
Reconciliation Protocol. No production code or recovery endpoint is added.

  • Add a linked protocol with a decision table, handoff sequence diagram, retry
    and replay rules, immutable repair/replacement semantics, cleanup safeguards,
    rollout gates, and conformance scenarios.
  • Propose an optional read-only featureRecoveryManagerProvider on Channel.
  • Introduce a feature-specific provisioning enum with the existing wire values
    plus a bilaterally gated FAILED value and structured read-only failureInfo.
    The shared provisioning enum and Connection lifecycle fields are unchanged.
  • Annotate existing CreateFeature, NotifyConnectionStatus, requestId, and
    connection-cleanup descriptions with the draft's opt-in semantics.

Existing three-of-four provisioning eligibility, full verification requirements,
L3 immutability, and the CreateConnection retry window of up to 60 seconds remain
unchanged. Five total foreground feature attempts are a proposed default, not an
existing agreement or an HTTP timeout policy.

Related public discussion: #51. This draft builds on the problem area without
assuming that unmerged proposal has been accepted.

Review Gates

Distributed fencing and ownership handoff are unresolved and block autonomous
replacement/cleanup. Additional decisions include capability negotiation,
generated-client compatibility, replay/retention details, failure codes, timing
budgets, maintenance/migration policy, and stricter coordination for the existing
seven-day cleanup permission. The existing deferConnection/deferProvisioning
naming mismatch is explicitly flagged, not silently changed.

Validation

  • Redocly CLI 2.35.0: OpenAPI lint using the minimal ruleset passes; 35 warnings,
    identical to unmodified main.
  • OpenAPI bundle generation and structured assertions pass for the feature enum,
    optional read-only owner, required failure fields, and existing query requestId.
  • Shared enum unchanged; no Connection provisioning-state field introduced.
  • Local Markdown links and git diff whitespace checks pass.

Conformance scenarios are proposed acceptance criteria, not executed distributed
integration tests. No repository CI workflows or test commands were present.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant