feat(reconciler): flip ADR 0035 cutover — container becomes sole applier (#226) #221
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!221
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/202-reconciler-flip-to-apply"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
⚠️ The ADR 0035 cutover flip — do not merge/apply until you're ready to cut over.
Flips the reconciler from bash-applies / container-dry-run to container-applies, bash retired:
reconciler_next_apply: false → true— thebitborg-auth-reconcilercontainer becomes the applier.reconciler_apply: true → false— the bash reconciler stops applying (also satisfies the double-reconcile guard the role asserts).reconciler_enabled: true → false— disables the bashgitborg-reconciler.timerentirely.Prerequisites (met on main)
Apply (guided, when ready)
reconciler-next/reconciler.promwrites cleanly + the diff still matches. 3.site.yml --tags reconciler --check --diff(review) → apply.RECONCILE_APPLY=true, real actions in journal), bashgitborg-reconciler.timerinactive, a spot-checked user's entitlements unchanged, noReconcilerStale(the container now feeds that metric).Backout
Revert this commit (re-enable bash + container back to dry-run) + apply.
Follow-up (after burn-in)
Remove the bash
gitborg-reconciler.sh.j2+ its templates/tasks in a cleanup PR.Refs #226, ADR 0035.
WIP: feat(reconciler): flip ADR 0035 cutover — container becomes sole applier (#202)till WIP: feat(reconciler): flip ADR 0035 cutover — container becomes sole applier (#226)04ae1199e978169b67e9✅ Cutover applied + verified on prod (2026-07-27)
Rebased onto
main(picks up #223/#225) and appliedsite.yml --tags reconciler. Two fixes were folded in beyond the original 3-boolean flip — without them the cutover would have broken monitoring:reconciler.prom.reconciler_next_textfile_dirnow points at the scrapednode_textfile_dir(was a dedicated, deliberately-unscraped dir for the parallel run). The container writes the same basename + metric names at0644, so theReconcilerStale/ReconcilerFailed/ReconcilerActionsEnforcementDegradeddeadman feed keeps ticking. Safe only because the bash writer is retired in the same apply (no duplicate-metric collision). Without this, the scraped file would freeze andReconcilerStalewould fire ~30 min post-cutover while the container's real metrics went unscraped.--check --diff). The reconciler-next dir task hardcodedmode: 0700; repointed at the shared scraped dir it would have clampednode_textfile_dir0755 → 0700, locking node_exporter out of everybitborg_*textfile metric. Split the task: config dir stays0700, textfile dir is0755(matches themonitoring-agent/runner-controllercanonical — idempotent, no flap).Runbook cutover step updated to include the repoint + backout.
Verification
gitborg-reconciler.timer→ inactive + disabled (retired).gitborg-reconciler-next.timer→ active + enabled; on-demand run exited0, log endsreconcile complete (APPLY=true), sane per-user projections, legacy LFS groups purged, no errors.reconciler.prom→ container-owned, fresh,0644,status=0,degraded=0.changed=0).Follow-up (after burn-in): remove the bash
gitborg-reconciler.sh.j2+ templates/tasks, and drop the now-stale "DRY-RUN parallel run" labels from the container/timer unit descriptions (it's the sole reconciler now, not "next"). Tracked on #226.Refs #226, ADR 0035.
WIP: feat(reconciler): flip ADR 0035 cutover — container becomes sole applier (#226)till feat(reconciler): flip ADR 0035 cutover — container becomes sole applier (#226)