Separate authenticated readiness from job execution for cloud acceptance - #14
Conversation
…tance Separate dependency checks from the scheduler and job execution. Probe only three read-only schema RPCs with bounded responses and cancellation; require an exact version/SHA and fresh nonce, redact errors and prohibit caching. Add 73 synthetic regressions and a credential-free standard-runner check. No production deployment, schema change, model request or provider call.
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
oneclickpostfactory-agent | 261adcd | Commit Preview URL Branch Preview URL |
Sep 29 2026, 03:32 PM |
Reproduce redirect:error throwing before transport in the actual Workers runtime. Use manual mode and retain exact HTTP 200/contract validation. Preserve all 73 synthetic tests and add ten real workerd regressions, including cross-origin redirect rejection and zero-request auth failures. No production deployment or schema mutation.
AyobamiH
left a comment
There was a problem hiding this comment.
Technical implementation review at exact head 261adcd; this is not an independent-reviewer approval.
The original native readiness code and app staging adapter used redirect:error. The actual workerd regression reproduces that unsupported mode throwing before outbound transport. The repair uses manual mode and accepts only HTTP 200 with complete schema contracts; Location is never followed and the five redirect cases prove credentials stay at the configured origin. Invalid auth and exact-version mismatch produce zero dependency requests. The readiness path does not initialise job execution, provider clients or process-global configuration.
Completed readiness run 36590556545 / job 109482223270 was read: all 73 synthetic cases, five liveness checks and ten actual workerd tests passed. Full Worker CI 36590556646 also passed.
The native, unwrapped candidate then ran on Cloudflare in app acceptance 36592291268 at app 947dfa93ac5ac4dcfb1e103b65d399ae233cd589. All six initial/post-restart dependency probes passed; competing ticks completed exactly one job; database-process restart and independent synthetic fixture restore passed. The final run remained BLOCKED because the app harness incorrectly expected zero credential rows despite the immutable signup trigger creating an empty shell. That fixture validator is being corrected in paired app PR #15, without a Worker or migration change. The failed receipt remains preserved; this review does not relabel that run PASS.
Fresh read-only Builds inspection 36500999886 attempt 4 at 15:47:57 UTC confirmed complete trigger inventories, upload-only Worker main/preview commands and unchanged active production versions. No production deployment or database migration is authorised by readiness alone. Final integration requires the corrected complete app acceptance and exact-head checks.
Merged and accepted in cloud staging — Milestone 1
Merged as
2d0be2c44929ee604c0b04938ba34dde5d018cea, with zero file differences from reviewed/tested head261adcd649b3c320a74ef93417122270508ff0a5. Paired app PR AyobamiH/oneclickpostfactory#15 is merged as1292a2931f276fb699eae4abf1ad9c600720228d, preserving app candidate525b981001795a9a90f3fe3d65ab08f0464e74b5.Implemented
Authenticated GET
/readyzis separate from public liveness and job execution. It checks exactly three read-only schema RPCs, with nonce-bound exact source/version identity, a shared 10-second deadline, bounded responses, no caching and redacted diagnostics. It does not initialise the scheduler, job claims, provider clients or process-global configuration.executionAuthorisedremains false.The actual workerd regression reproduced
redirect:errorthrowing before outbound transport. The repaired native implementation uses manual mode and rejects every response except HTTP 200 with the required contracts/capabilities. It never follows Location or forwards credentials to a redirect. This resolves the reproduced readiness transport defect without changing tokens, buying infrastructure or making business execution a readiness retry.Verification
a2584073068367b46f78f26c0f2da5be7361b05e4a2ac553914f97e23e8130a0.The earlier 36592291268 remains a failed run: the app harness incorrectly expected no credential row after the immutable signup trigger created an empty shell. Its corrected validation and fourteen negative/positive tests are in the paired app commit, not a runtime or schema weakening. Historical intermittent /tick errors are not all retrospectively assigned the same cause.
Technical implementation reviews are saved but are not independent-reviewer approvals. Existing Cloudflare capacity and bounded standard CI were used; no paid branch, new plan, larger runner, always-on Container or owner-PC step. Shared incremental charges are not independently attested.
Production boundary
This merge does not apply production migrations or deploy the consumer. Builds remain upload-only. Production still needs its separate environment/recoverability preflight, old-consumer drain, the two pending migrations in order, exact consumer deployment and independent verification with generation/publishing disabled. Synthetic restart/restore is not a full production backup or managed Supabase disaster recovery.