Repository navigation
fix(chart): more than one portal replica on a pod-local /data is refused at render (#6052) - #6197
Merged
Merged
Conversation
…sed at render (#6052) /data holds the NodeType assembly cache (FileSystemAssemblyStore, collection "local") and every compiled NodeType's SHARED record names a file in it. On per-pod emptyDir a type compiled on pod A leaves a record naming bytes pod B never holds; B's instances render "its compiled assembly could not be loaded on this node", and a recompile does not help because it runs where the NodeType's own hub lives. The client estate in #6052 ran two replicas this way (/health bake-report bytesmissing=93 on both pods). chart-gate invariant 3 asserts RWX only over the values files tracked here; a client's are not. So deployment.yaml now fails the render when keda.enabled or replicas.portal > 1 and neither persistence.data.claimName nor persistDataVolume gives a shared /data. - check-chart-invariants.sh: refusal control with a fixture that is the valid two-replica shape minus the data claim. Neutralising the fail reds the gate (6 of 7 refusals held). - values.yaml: the replicas comment names the refusal. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Test Results 22 files ± 0 22 suites ±0 45m 19s ⏱️ +33s Results for commit 2bd8706. ± Comparison against base commit 3a0c2e9. This pull request removes 40 and adds 46 tests. Note that renamed tests count towards both.♻️ This comment has been updated with latest results. |
Contributor
Contributor
Contributor
Contributor
Contributor
Contributor
Test Results (shard 4) 4 files ± 0 4 suites ±0 17m 0s ⏱️ + 1m 36s Results for commit 2bd8706. ± Comparison against base commit 3a0c2e9. This pull request removes 716 and adds 891 tests. Note that renamed tests count towards both. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #6052. This PR is the platform half of ask 1. It does not close the issue; see below for what is left.
Root cause (mechanism traced in code)
On the estate in #6052, each pod's
FileSystemAssemblyStore(collectionlocal) sat under its own/data. The NodeType records that point into it are shared in the database.NodeTypeCompilationHelperswatcher →DispatchCompileTrigger). It uploads to that pod's store (NodeTypeCompilationHelpers.cs~3312) and writesLatestAssemblyCollection = "local"into the shared record (~3907).NodeTypeEnrichmentHelpers.cs~1512–1560) callsTriggerRecompileAndRetry. That flips the type to Pending through the owner hub, so the recompile runs on pod A again and the bytes land on pod A again. AfterMaxRecompileAttemptspod B shows the AssemblyUnavailable overlay — the page from the issue.ResolveAssemblyasks only the local store, andPluginBundleClientruns only at install and reconcile.persistence.data.claimNamedefaults to"", which rendersemptyDir. The chart only warns in comments, and chart-gate's invariant 3 checks only the values files tracked in this repository, not a client's.Our AKS instances avoid all of this:
/datais a ReadWriteMany Azure Files claim (values.aks.yaml, and theclient-brecord in Systemorph/Memex hasmemex-data).Fix
deploy/helm/templates/memex-portal/deployment.yamlnow fails the render under three conditions together:keda.enabledis on, orreplicas.portalis greater than 1;persistence.data.claimNameis not set;persistDataVolumeis off. That setting is a single-node hostPath, so it counts as shared.The message names the missing input and the issue. This is the chart's established refusal pattern (#3780, the fabrikam refusals).
Tests
check-chart-invariants.shgets a new refusal control. Its fixture is the valid two-replica shape (values.two-replicas-no-keda.yaml) minus the data claim, so the pod-local/datais the only thing the render can refuse. The run reports "All 17 values combinations render a self-consistent deployment, and all 7 refusal controls hold."failneutralised, the gate goes red: "only 6 of 7 refusal controls held".check-values-are-read.shandtest-chart-drift-render.shstay green.What this does NOT do / not established
/datawas pod-local there is inferred fromcollection=localbytes being missing on the other pod. The estate's values live in its own repository.helm upgraderefused until it setspersistence.data.claimName. That is intended: the shape cannot serve compiled NodeTypes across pods. Every tracked fleet record I could read (memex, memex-cloud, client-b) has a data claim.bundles.identityis static per helm release.bundles.identityFileis the existing dynamic alternative.Modules:RequirePrebuiltthe default for client instances (ask 1, "refuse local compile"). That is a policy decision.🤖 Generated with Claude Code