Skip to content

docs(#5354): production-HA acceptance plan — 10-issue topology (#5356-#5365) - #5366

Merged
qqeasonchen merged 1 commit into
developfrom
arch-review/production-ha-plan
Sep 8, 2026
Merged

qqeasonchen merged 1 commit into
developfrom
arch-review/production-ha-plan

Conversation

@qqeasonchen

Copy link
Copy Markdown
Contributor

What this PR does

Adds docs/architecture-review/production-ha-plan.md — the executable plan that restructures the production-HA acceptance work (#5352 / #5353 / #5354) into a tracked topology, in the same shape as the closed #5296 review.

The 10-issue topology

Phase Severity Issues
0 — Enforcement (arch-guard) P0 #5356 ban poll-all + InMemoryMetaStore, #5357 ban mutable EventMeshFrame, #5358 ban raw quota calls
1 — Wiring P0 #5359 DeliveryTopology/MetaStore/FencingToken boot wiring, #5360 fencing epoch propagation, #5361 FrameLimits
2 — Production behavior P1 #5362 QuotaHandle + A2A op classification, #5363 Testcontainers cross-instance takeover tests
3 — Chaos + ops P1 #5364 chaos + rolling upgrade + admin security
4 — Docs + evidence P2 #5365 doc sync + acceptance evidence

All 10 tracking issues are already opened and attached to parent #5354 as GitHub sub-issues (along with #5352 and #5353 — 12 children total).

What the plan document contains

  1. Topology table — Phase, Severity, dependency graph (Depends on / Blocks) for each issue.
  2. Phase breakdown — per-issue scope, why the severity rating, and the concrete ArchUnit rule names / class changes.
  3. Acceptance criteria → issue mapping — all 21 criteria from the three parent issues' bodies mapped to exactly one owning issue each (A1-A5 from [Bug] Harden data-path reliability, deferred ACK, and Frame safety #5352, B1-B6 from [Bug] Harden DeliveryTopology, SecurityGate, and control-plane fencing #5353, C1-C10 from [Bug] Production HA acceptance: wiring, takeover, chaos tests, and evidence #5354).
  4. PR plan — one PR per issue, with branch names, approximate file lists, and local verification commands (each Sub-PR is verifiable with a local ./gradlew command even during the ongoing Actions platform outage).
  5. Sequencing rationale — Phase 0 first (cheap guards stop regression), Phase 1 sequential wiring, Phase 2/3 parallel.
  6. Open risks — CI outage impact, Testcontainers E2E scope, LOCAL_STICKY_PULL multi-instance semantics documentation.

Verification

Docs-only PR. The plan references only classes/files that exist at the current develop tip (b08e591ac):

Cross-link check: every issue number #5356-#5365 in the doc matches an existing open issue (verified via the GitHub sub-issue list of #5354).

Relations

Co-authored-by: qqeasonchen qqeasonchen@gmail.com

Adds docs/architecture-review/production-ha-plan.md splitting the
production-HA acceptance work (#5352 / #5353 / #5354) into 10 tracking
issues (#5356-#5365, Phase 0..4, Severity P0..P2) with an explicit
dependency graph, per-issue acceptance criteria, and a PR plan.

Topology summary:
  Phase 0 enforcement (P0): #5356 ban poll-all + InMemoryMetaStore,
    #5357 ban mutable EventMeshFrame, #5358 ban raw quota calls
  Phase 1 wiring (P0): #5359 DeliveryTopology/MetaStore/FencingToken
    boot wiring, #5360 fencing epoch propagation, #5361 FrameLimits
  Phase 2 behavior (P1): #5362 QuotaHandle + A2A op classification,
    #5363 Testcontainers cross-instance takeover tests
  Phase 3 chaos (P1): #5364 chaos + rolling upgrade + admin security
  Phase 4 docs (P2): #5365 doc sync + acceptance evidence

All 12 sub-issues (10 new + #5352 + #5353) are attached to parent
#5354 via GitHub sub-issue relationships.

Refs: #5352, #5353, #5354, #5356-#5365.

Co-authored-by: qqeasonchen <qqeasonchen@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Architecture Review] Consolidate EventMesh boundaries and production-grade consistency

1 participant