Repository navigation
test(kubernetes): verify external-worker restart and quiesced state restore - #252
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and result
Operators need evidence that the control-plane chart can preserve work and state before a Kubernetes alpha is published. This delivery installs the real chart in isolated Kubernetes 1.37.0, connects an external operator Docker worker, replaces API/orchestration during a pending confirmation, and proves same-release quiesced recovery into independent PostgreSQL/S3 stores.
The system test preserves public IDs, File/Skill bytes and checksums, Memory Versions and original encryption keys. Read-only Temporal queries establish the original Run ID and complete history prefix after restore, then prove advancement of that same execution after the original custom-tool result; duplicate submission returns 409. Reconstructing a new Workflow from Mango rows cannot pass. Existing Vault GET verifies/decrypts the restored envelope before returning secret-free metadata. The stateless Messages endpoint is explicitly simulated; actual Mango HTTP, adapter, state services and sandbox execution are exercised.
Fixtures own unique projects, cluster, images and workspace volumes and use an explicit kubeconfig. Supervisor receives an Environment-scoped key; no provider credential is needed in CI. Shutdown covers the full worker grace; fallback removal rechecks exact container identity and an uncertain stop aborts backup. A paused orphan/unrelated-item probe verifies cleanup safety. Read-only transport failures during single-replica replacement are retried within a bound; mutation/admission is never automatically retried. Production runtime, persistence schema, HTTP/OpenAPI and SDK surfaces are unchanged.
Scope and evidence
docs/design/kubernetes-recovery.md,docs/design/kubernetes-alpha.md,docs/provenance.md. Operator recovery is Mango-owned; CMA hosted rollout policy is not inherited.Validation
make test-kubernetes KIND=... KUBECTL=... HELM=...— corrected full acceptance passed290.34s, including original Temporal execution/history continuation and paused orphan/unrelated-item cleanup. Final CI runs the complete tier at this PR head.make test-service-core MANGO_TEST_S3_ENDPOINT=http://localhost:19000— passed, isolated schemas and temporary SeaweedFS; existing local stack unchanged.make verify— lint/unit/race/vet passed;make chart-check— six contracts passed; Actions validation passed;make docs-check—62pages/links/anchors/exports passed.scripts/with-dev-env make test-self-hosted-live— actual model → authenticated HTTP → external Docker worker passed5.04s, no credential output.