Skip to content

feat(cluster): transfer fresh S3 bootstrap ownership to the first server - #893

Open
aaltshuler wants to merge 4 commits into
ModernRelay:mainfrom
aaltshuler:codex/bootstrap-serving-handoff
Open

aaltshuler wants to merge 4 commits into
ModernRelay:mainfrom
aaltshuler:codex/bootstrap-serving-handoff

Conversation

@aaltshuler

Copy link
Copy Markdown
Contributor

Fresh S3 clusters can now initialize a management policy and start their first server without deleting the native lock between those owners. Core returns an exact bootstrap receipt; omnigraph-server --cluster <root> --bootstrap-handoff <receipt> conditionally replaces that retained lock and opens the admitted empty snapshot. The first graph is then created through the existing native HTTP deployment API.

The path is deliberately limited to fresh, zero-graph S3 roots and cluster-scoped policies. Wrong roots, modified receipts, replay, existing state and unsupported backends refuse. Lost acknowledgements and startup failures retain ownership; there is no readback adoption or fallback to ordinary boot. Later lock release still requires settlement of all previously accepted bootstrap I/O. General S3 writer replacement is outside this change.

Validation:

  • Core: 130 unit tests passed, including nine bootstrap and backend fault tests covering conditional writes, competing claims, lost acknowledgements, cancellation and absence of DELETE.
  • Server: 200 unit tests, CLI parsing, and 28 boot-settings tests passed; strict all-target Clippy passed for Core and server.
  • Real AWS S3: bootstrap, first claim, empty readiness, first HTTP graph deployment, wrong-root/replay refusal and post-claim startup failure passed (one non-skipped test, 72.69 seconds).
  • Required RustFS CI coverage, documentation guards, workflow checks and formatting are included.

The RFC and public operating documentation describe the retained-lock contract and its limits. This adds one opt-in server flag and Core APIs; existing boot behavior and HTTP contracts are unchanged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant