Skip to content

Separate authenticated readiness from job execution for cloud acceptance - #14

Merged
AyobamiH merged 2 commits into
mainfrom
codex/cloud-readiness-20260929
Sep 29, 2026
Merged

AyobamiH merged 2 commits into
mainfrom
codex/cloud-readiness-20260929

Conversation

@AyobamiH

@AyobamiH AyobamiH commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Merged and accepted in cloud staging — Milestone 1

Merged as 2d0be2c44929ee604c0b04938ba34dde5d018cea, with zero file differences from reviewed/tested head 261adcd649b3c320a74ef93417122270508ff0a5. Paired app PR AyobamiH/oneclickpostfactory#15 is merged as 1292a2931f276fb699eae4abf1ad9c600720228d, preserving app candidate 525b981001795a9a90f3fe3d65ab08f0464e74b5.

Implemented

Authenticated GET /readyz is separate from public liveness and job execution. It checks exactly three read-only schema RPCs, with nonce-bound exact source/version identity, a shared 10-second deadline, bounded responses, no caching and redacted diagnostics. It does not initialise the scheduler, job claims, provider clients or process-global configuration. executionAuthorised remains false.

The actual workerd regression reproduced redirect:error throwing before outbound transport. The repaired native implementation uses manual mode and rejects every response except HTTP 200 with the required contracts/capabilities. It never follows Location or forwards credentials to a redirect. This resolves the reproduced readiness transport defect without changing tokens, buying infrastructure or making business execution a readiness retry.

Verification

  • Full Worker CI 36590556646 passed.
  • Readiness run 36590556545 passed 73 synthetic tests, five liveness checks and ten actual workerd regressions, including the unfixed zero-transport reproduction and five redirect-rejection cases.
  • Actual deployed cloud acceptance 36593974264 passed against this exact native Worker and app 525b981. It used the canonical entrypoint directly, not the old staging wrapper.
  • Native Worker version b599a480-e3e4-47fe-9898-d19508c9c4e4 passed exact configuration/source verification, six initial/post-restart dependency checks, competing requests with one durable job completion, database restart, independent bounded fixture restoration, and a third tick without duplicate work.
  • 49 actual hosted database requests, zero denied bridge calls; credential shell empty and unchanged; no cron triggers, model calls or social posts. Temporary Worker deletion and database shutdown were verified. Production deployments remained unchanged.
  • The final receipt was independently downloaded and checked: SHA-256 a2584073068367b46f78f26c0f2da5be7361b05e4a2ac553914f97e23e8130a0.

The earlier 36592291268 remains a failed run: the app harness incorrectly expected no credential row after the immutable signup trigger created an empty shell. Its corrected validation and fourteen negative/positive tests are in the paired app commit, not a runtime or schema weakening. Historical intermittent /tick errors are not all retrospectively assigned the same cause.

Technical implementation reviews are saved but are not independent-reviewer approvals. Existing Cloudflare capacity and bounded standard CI were used; no paid branch, new plan, larger runner, always-on Container or owner-PC step. Shared incremental charges are not independently attested.

Production boundary

This merge does not apply production migrations or deploy the consumer. Builds remain upload-only. Production still needs its separate environment/recoverability preflight, old-consumer drain, the two pending migrations in order, exact consumer deployment and independent verification with generation/publishing disabled. Synthetic restart/restore is not a full production backup or managed Supabase disaster recovery.

…tance

Separate dependency checks from the scheduler and job execution. Probe only
three read-only schema RPCs with bounded responses and cancellation; require
an exact version/SHA and fresh nonce, redact errors and prohibit caching.
Add 73 synthetic regressions and a credential-free standard-runner check.
No production deployment, schema change, model request or provider call.
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
oneclickpostfactory-agent 261adcd Commit Preview URL

Branch Preview URL
Sep 29 2026, 03:32 PM

Reproduce redirect:error throwing before transport in the actual Workers
runtime. Use manual mode and retain exact HTTP 200/contract validation.
Preserve all 73 synthetic tests and add ten real workerd regressions,
including cross-origin redirect rejection and zero-request auth failures.
No production deployment or schema mutation.

@AyobamiH AyobamiH left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Technical implementation review at exact head 261adcd; this is not an independent-reviewer approval.

The original native readiness code and app staging adapter used redirect:error. The actual workerd regression reproduces that unsupported mode throwing before outbound transport. The repair uses manual mode and accepts only HTTP 200 with complete schema contracts; Location is never followed and the five redirect cases prove credentials stay at the configured origin. Invalid auth and exact-version mismatch produce zero dependency requests. The readiness path does not initialise job execution, provider clients or process-global configuration.

Completed readiness run 36590556545 / job 109482223270 was read: all 73 synthetic cases, five liveness checks and ten actual workerd tests passed. Full Worker CI 36590556646 also passed.

The native, unwrapped candidate then ran on Cloudflare in app acceptance 36592291268 at app 947dfa93ac5ac4dcfb1e103b65d399ae233cd589. All six initial/post-restart dependency probes passed; competing ticks completed exactly one job; database-process restart and independent synthetic fixture restore passed. The final run remained BLOCKED because the app harness incorrectly expected zero credential rows despite the immutable signup trigger creating an empty shell. That fixture validator is being corrected in paired app PR #15, without a Worker or migration change. The failed receipt remains preserved; this review does not relabel that run PASS.

Fresh read-only Builds inspection 36500999886 attempt 4 at 15:47:57 UTC confirmed complete trigger inventories, upload-only Worker main/preview commands and unchanged active production versions. No production deployment or database migration is authorised by readiness alone. Final integration requires the corrected complete app acceptance and exact-head checks.

@AyobamiH
AyobamiH marked this pull request as ready for review September 29, 2026 16:00
@AyobamiH
AyobamiH merged commit 2d0be2c into main Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant