Skip to content

M1: authenticate exact-version readiness without running jobs - #13

Draft
AyobamiH wants to merge 1 commit into
mainfrom
implementation/cloud-acceptance-m1-20260929
Draft

AyobamiH wants to merge 1 commit into
mainfrom
implementation/cloud-acceptance-m1-20260929

Conversation

@AyobamiH

Copy link
Copy Markdown
Collaborator

Approved milestone implementation

The owner approved all seven delivery milestones, with no new subscription/paid database branch, no mandatory laptop/WSL execution and no unapproved overage. This PR implements M1's runtime readiness prerequisite; it does not claim all milestones or hosted acceptance are complete.

Base 6e8ac018d4db4ebb726bd69c3a99569adad50a5d; head 2d00213a7a2a8aaa37e206cfbb865782b79089cf.

Implemented

  • Operator-authenticated GET /readyz, separate configuration and database modes.
  • Exact deployment version, source SHA and per-probe challenge validation.
  • Configuration mode has no database calls; database mode calls only three known metadata RPCs, with full capability checks.
  • No config globals, scheduler, job/tenant writes, paid generation or provider paths.
  • Bounded responses/deadline, no redirects, no raw errors/credential passthrough, no cached readiness.
  • 63 new adversarial regressions. Local TypeScript check and all 63 tests passed in the isolated coding environment (Node 22); repository CI still must validate the complete current head on Node 24.

Preserved boundaries

Existing production deployments, cron configuration, kill switches, tenant cohort, provider gates, billing and schemas are unchanged. No new dependency or lockfile change. No production deployment is requested by this PR. Readiness does not authorise a business effect.

The app-owned cloud harness will independently read active deployment/version metadata, perform bounded effect-free probes, and execute each trial's business ticks once. It must never turn a failed tick into retry-until-green. Previous authenticated 404/500 observations remain failures; a root cause/fix is not claimed from synthetic tests alone.

Validation uses the existing public Worker repository's standard CI only; private schema source must remain private. The app staging orchestration and its capacity/cleanup evidence are a separate paired change.

Separate configuration and database readiness from business execution.
Require exact deployed version, source tag and challenge identity; probe only
three metadata RPCs. Preserve existing publishing and rollout controls.
Add 63 regressions; no new dependencies or production deployment.
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
oneclickpostfactory-agent 2d00213 Commit Preview URL

Branch Preview URL
Sep 29 2026, 02:04 PM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant