Skip to content

Commit db23982

Browse files
cardmagicclaude
andcommitted
docs: state what an administration event records
An event records an authorized press, not a state transition, and the redrive transitions are the opposite. The rule was implicit in the tests. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent 72aa494 commit db23982

1 file changed

Lines changed: 9 additions & 1 deletion

File tree

‎docs/operations.md‎

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -298,7 +298,15 @@ own resource name: `dead_letters`, `effect_dead_letters`,
298298
writes one row to `solid_objects_administration_events`, holding the action, the
299299
kind, the subject, the identity, and when it happened. The identity comes from
300300
`administrationIdentity`, which receives the authorization context the caller
301-
passed and defaults to its `String` form. A refused caller writes nothing.
301+
passed and defaults to its `String` form.
302+
303+
An event records an authorized press, not a state transition. Pressing retry
304+
twice writes two rows, because an operator did two things and a log that shows
305+
one cannot answer who pressed what. The row the event names carries the outcome.
306+
A refused caller writes nothing, and a retry that raises after the lookup writes
307+
nothing, because the event shares the transaction with the work. The redrive
308+
transitions are different: `redrive.start`, `redrive.finish`, and
309+
`redrive.cancel` are written only when the task actually changes.
302310

303311
The Durable Objects engine keeps its own message and outbox tables inside each
304312
object, so these scopes and redrive cover the SQL backends. `deadLetters` there

0 commit comments

Comments
 (0)