Files
orca/cloud/dev
Jinwoo Hong ab91559fb4 feat(relay): one-command director deploy driver (#25642)
* feat(relay): add an operator-local driver for director deploys

One command runs the audited director deploy: preflight, pause rehome if
enabled, publish, deploy, optional cell configure, a digest-bound inspect,
the monitor dry-run, and re-enable. It only dispatches the existing
workflows, reads the published digest from the registry and the run log,
reads the monitor verdict from its sealed state, and enables with the
digests gcloud reports after the deploy. It stops at the first failure,
records state, and resumes from it.

* fix(relay): report and own the rehome pause; operator types every phrase

- Read the control back from pause and enable runs whatever their conclusion,
  and report PAUSED or UNCONFIRMED loudly.
- Resume re-enables only the pause this driver recorded (generation and run).
- Ctrl-C and SIGTERM print the same state and resume report.
- The operator types every workflow confirmation. A 5-minute soak gated on
  director 5xx runs before configure.
- A dry run keeps no state file. The quiet check pages through all runs.
  Run IDs come only from the printed URL. One step table drives execute,
  dry run and resume. The monitor verdict reuses verify-authority.

* fix(relay): read back only the driver's own rehome run; anchor the soak at the traffic switch

- The pause and enable read-back accepts only the control line its own step's mode prints, at the
  generation its own dispatch expected. A run adopted after a crash is settled even when green.
- The soak window opens a minute before the deploy run completed and is read a minute after it
  ends, for log ingestion lag.

* fix(relay): say what typing ENABLE_REGIONAL_REHOMING commits to

* fix(relay): the ENABLE prompt also names the 150 s evidence budget

* refactor(relay): derive every deploy decision from live state; no resume machinery

The driver keeps no state between runs. Each run reads the serving
director, its configured cells and the rehome control, and skips what is
already done.

- The only rehome fact it owns is the run that paused rehome. A re-run
  names it (--pause-run), and the driver checks it against that run's log
  and the live generation.
- A recover-enable line counts as the driver's own pause only with
  recovered: true. A director safety pause is never adopted (F3).
- Publish runs before the pause. A fresh run that finds rehome paused
  stops unless given --pause-run or --rehome-disabled (F2).
- Interrupts report a pause or enable still in flight as REHOME IS
  CHANGING (F1). PAUSE UNCONFIRMED and ENABLE UNCONFIRMED are distinct.
- A tripped soak is judged again on fresh traffic (F5). SIGHUP is
  handled, and a pending signal stops the driver before its next dispatch.
- Every stop prints the single command that finishes the deploy.

Removes the state file, --resume, step statuses, monitor adoption and
interrupted-dispatch adoption.

* fix(relay): never report done over an unexplained pause; prove pause ownership by actor

- G1: always read rehome; no early DONE.
- G2: --pause-run must be a rehome-control run by the same user.
- G3: a failed enable run is never an enable.
- C1: a pause or enable is reported as changing from the moment it is
  dispatched.
- C2: --leave-rehome-paused (was --rehome-disabled) refuses an enabled
  switch. Every printed command parses.
- G4: the enable-in-flight report prints both finishing commands.
- G5: the driver's own runs never block the quiet-lane check.

* test(relay): port the round-3 probes: hard kill mid-pause, unexplained disable after a failed enable

Claude-Session: 1145a80d-dec4-4a9b-9373-bbbb876b9041
2026-10-05 18:51:18 -04:00
..