Files
orca/cloud/dev/scripts/relay-cloud-sql-connection-budget.test.mjs
T
Jinwoo-H 380a5800fb infra(relay): raise asia-east2 cell pools to 16 and retire four idle cells
The three asia-east2 cells sit 176 ms from the Cloud SQL instance in
us-central1. Server-side statement time there is 0.2 ms, so a pool slot is
held by the round trip, not by the query. At a pool of 10 they measured
94-156 waiters and 2 s waits, and client accepts ran a ~4 s p95 against
222-646 ms in us-central1. Raising those three pools to 16 is the agreed
first step; every other cell stays at 10.

c4 and c5 join the committed fence set. Both are existing-only capacity the
admission selector can never place on again, they carried ~1 connection each
on 40-day-old images, and each still holds 10 Postgres connections. The fence
set is the prerequisite the fence-source workflow confirms before it drains
and attests a cell; it is not itself the resize.

c17 and c18 are not fenced here. They are migration-only, and the runbook
requires retire-migration-cell to move a migration-only cell to existing-only
through a generation-bound selector CAS before it can be fenced. Terraform
cannot express that step.

The Cloud SQL consumer contract carried two stale numbers: auth at 2 instances
when production has run a cap of 20 since 2026-09-04, and a 400-connection
ceiling when the live instance reports 500. Both are corrected, and the budget
now asserts its headroom in two named gates instead of one aggregate boolean.
Those gates fail: auth alone accounts for 200 configured connections and a
215-connection rollout overlap, so the operating maximum is 713 against a
usable ceiling of 490. Nothing here caused that, and no pool was lowered to
hide it.
2026-09-17 01:05:54 -04:00

171 lines
5.7 KiB
JavaScript

import assert from 'node:assert/strict'
import { readFileSync } from 'node:fs'
import test from 'node:test'
import {
calculateRelayCloudSqlConnectionBudget,
readRelayCloudSqlConnectionBudget
} from './relay-cloud-sql-connection-budget.mjs'
const shortfall = (report) =>
[
`cells ${report.consumers.cells}`,
`directors ${report.consumers.directors}`,
`auth ${report.consumers.auth}`,
`api ${report.consumers.api}`,
`= ${report.configuredMaximum} configured`,
`+ ${report.rolloutOverlap.maximum} rollout overlap`,
`+ ${report.maintenanceAdminAllowance} admin allowance`,
`= ${report.operatingMaximum} operating`,
`against ${report.maxConnections} max_connections less a ${report.explicitReserve} reserve`
].join(', ')
test('the production budget reads the committed pools and the measured ceiling', () => {
const report = readRelayCloudSqlConnectionBudget()
assert.equal(report.maxConnections, 500)
assert.deepEqual(report.consumers, { cells: 228, directors: 15, auth: 200, api: 50 })
assert.deepEqual(report.asia, { cells: 3, poolMax: 16 })
assert.equal(report.configuredMaximum, 493)
assert.equal(report.rolloutOverlap.relayDirectorCandidate, 30)
assert.equal(report.rolloutOverlap.apiCandidate, 65)
assert.equal(report.rolloutOverlap.authCandidate, 215)
assert.equal(report.rolloutOverlap.relayCells, 15)
assert.equal(report.rolloutOverlap.retainedDirectorRollback, 15)
assert.equal(report.rolloutOverlap.maximum, 215)
assert.equal(report.maintenanceAdminAllowance, 5)
assert.equal(report.explicitReserve, 10)
assert.equal(report.usableCeiling, 490)
assert.equal(report.operatingMaximum, 713)
})
test('configured pools fit under the ceiling less the stated reserve', () => {
const report = readRelayCloudSqlConnectionBudget()
assert.ok(
report.configuredMaximum <= report.usableCeiling,
`configured pools exceed the usable ceiling: ${shortfall(report)}`
)
})
test('a serialized rollout still fits under the ceiling less the stated reserve', () => {
const report = readRelayCloudSqlConnectionBudget()
assert.ok(report.withinBudget, `the operating maximum exceeds the usable ceiling: ${shortfall(report)}`)
})
test('fails closed when pool growth consumes the explicit reserve', () => {
const report = calculateRelayCloudSqlConnectionBudget({
cellPoolTotal: 200,
asiaCellCount: 3,
asiaPoolMax: 20,
directorInstances: 5,
directorPoolMax: 3,
authInstances: 2,
authPoolMax: 10,
apiInstances: 20,
apiPoolMax: 5,
maxConnections: 400,
maintenanceAdminAllowance: 5,
explicitReserve: 10
})
assert.equal(report.operatingMaximum, 515)
assert.equal(report.withinBudget, false)
})
test('excludes fenced cell pools and reads per-cell pool overrides', () => {
const report = readRelayCloudSqlConnectionBudget({
proposedAsiaCellCount: 1,
appConsumers: { authInstances: 1, authPoolMax: 10, apiInstances: 1, apiPoolMax: 5, maxConnections: 100 },
sources: {
productionTfvars: `
relay_max_instances = 1
relay_gce_fenced_cells = ["production-gce-c1"]
relay_gce_cells = {
"production-gce-c1" = { database_pool_max = 99
}
"production-gce-c2" = { database_pool_max = 4
}
}
`,
terraformVariables: [
'variable "relay_director_database_pool_max" { default = 3 }',
'variable "push_max_instances" { default = 1 }',
'variable "push_database_pool_max" { default = 2 }'
].join('\n'),
relayConfig: 'export const RELAY_DATABASE_POOL_MAX = 10'
},
maxConnections: 100,
maintenanceAdminAllowance: 1,
explicitReserve: 1
})
assert.equal(report.consumers.cells, 14)
assert.equal(report.operatingMaximum, 46)
assert.equal(report.budgetedTotal, 47)
})
test('dedicated push scaling does not consume shared capacity', () => {
const report = readRelayCloudSqlConnectionBudget({
proposedAsiaCellCount: 1,
appConsumers: { authInstances: 1, authPoolMax: 10, apiInstances: 1, apiPoolMax: 5, maxConnections: 100 },
sources: {
productionTfvars: `
relay_max_instances = 1
push_max_instances = 3
relay_gce_fenced_cells = []
relay_gce_cells = {
"production-gce-c2" = { database_pool_max = 4
}
}
`,
terraformVariables: [
'variable "relay_director_database_pool_max" { default = 3 }',
'variable "push_max_instances" { default = 1 }',
'variable "push_database_pool_max" { default = 2 }'
].join('\n'),
relayConfig: 'export const RELAY_DATABASE_POOL_MAX = 10'
},
maxConnections: 100,
maintenanceAdminAllowance: 1,
explicitReserve: 1
})
assert.equal(report.consumers.push, undefined)
assert.equal(report.rolloutOverlap.pushCandidate, undefined)
assert.equal(report.operatingMaximum, 46)
})
test('requires strict headroom below the physical ceiling', () => {
const report = calculateRelayCloudSqlConnectionBudget({
cellPoolTotal: 20,
asiaCellCount: 0,
asiaPoolMax: 10,
directorInstances: 1,
directorPoolMax: 3,
authInstances: 1,
authPoolMax: 10,
apiInstances: 1,
apiPoolMax: 5,
maxConnections: 50,
maintenanceAdminAllowance: 9,
explicitReserve: 3
})
assert.equal(report.budgetedTotal, 63)
assert.equal(report.withinBudget, false)
})
test('pages Relay channels when Cloud SQL backends consume headroom', () => {
const terraform = readFileSync(
new URL('../../infra/terraform/relay-observability.tf', import.meta.url),
'utf8'
)
const policy = terraform.match(
/resource "google_monitoring_alert_policy" "relay_cloud_sql_backends" \{([\s\S]*?)\n\}/
)?.[1]
assert.ok(policy)
assert.match(policy, /notification_channels\s*=\s*var\.relay_alert_notification_channels/)
})