Skip to content

Promote pipeline-control follow-ons to main - #2656

Closed
twoimo wants to merge 9 commits into
mainfrom
data
Closed

twoimo wants to merge 9 commits into
mainfrom
data

Conversation

@twoimo

@twoimo twoimo commented Aug 19, 2026

Copy link
Copy Markdown
Owner

Summary

Promote merged data (#2655) onto main.

Includes:

  • #2654 GET /v1/runs FileStore collection
  • #2653 OTel SDK OTLP frozen counters
  • #2652 persist divergence fail-close
  • #2651 Slice 3 metric-name freeze
  • #2650 dual-read system-status
  • #2647 dual-write local jobs/locks/audit
  • #2648 Grafana CSP/auth gate
  • #2649 pipeline preview hashes off node:crypto

Test plan

  • Covered on #2653 / #2654 and prior develop PRs. #2655 CI: 24/24 pass.

Do not delete data on merge.

twoimo and others added 9 commits August 19, 2026 18:21
Client dashboard imported SHA-256 from node:crypto via the shared
preview-hash helper. Hash with a browser-safe digest so webpack does
not pull Node crypto into the admin bundle.

Co-authored-by: twoimo <twoimo@example.com>
Operator Grafana stays loopback-only and out of the admin dashboard.
Anonymous login and embedding are off; CSP is on; the admin password
must come from GRAFANA_ADMIN_PASSWORD instead of a compose default.

Co-authored-by: twoimo <twoimo@example.com>
Persist-on mutate writes pipeline_control jobs+locks+audit in one local
transaction. GET stays FileStore and non-mutating. Default persist remains off.

Co-authored-by: twoimo <twoimo@example.com>
Probe pipeline-api GET /v1/targets for job_api, else current-summary.json.
If neither is available, source is none instead of a fake job_api flag.

Co-authored-by: twoimo <twoimo@example.com>
* feat(pipeline): freeze Slice 3 metric names without OTel SDK

Pin the control-plane counters in metrics.v1.json. record() stays noop,
Kafka lag / ES rows/sec stay deferred, and the image stays copy-only.

* feat(pipeline): wire noop Slice 3 metric record call sites

MemoryStore enqueue/claim/Succeeded/Failed invoke record() as noop.
Idempotency replay and Cancelled/Paused finish_dry_run do not. No OTel SDK,
no export, no TZUDONG_PIPELINE_METRICS in overlay or GHA.

---------

Co-authored-by: twoimo <twoimo@example.com>
…m FileStore (#2652)

Persist-on dual-write still leaves GET on FileStore. After jobs+locks write, read those rows back and compare them to the FileStore RunRecord; mismatch rolls back and raises persist_divergence.

Co-authored-by: twoimo <twoimo@example.com>
Replace the copy-only image freeze with pinned OpenTelemetry SDK + OTLP HTTP
exporter so overlay record() can push the four frozen run counters to the
existing collector scrape path. Default export stays off; GHA export attempts
fail closed before the SDK import.

Co-authored-by: twoimo <twoimo@example.com>
Return the same allowlisted live jobs and capped failures as the operator
snapshot without targets. GET stays FileStore-backed and non-mutating.

Co-authored-by: twoimo <twoimo@example.com>
Promote pipeline-control follow-ons to data
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@twoimo

twoimo commented Aug 20, 2026

Copy link
Copy Markdown
Owner Author

Closing as superseded by the recovery and control-plane remediation series based on current origin/develop. The current promotion is diverged from main and includes unresolved control-plane correctness and security findings. No branch or data is deleted; the exact head remains recorded in PR #2656 and will be replaced through reviewed develop -> data -> main promotions.

@twoimo twoimo closed this Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant