Skip to content

M2: safely drain the Worker and verify production with read-only probe leases - #15

Merged
AyobamiH merged 2 commits into
mainfrom
codex/m2-operator-controls-20260930
Sep 30, 2026
Merged

AyobamiH merged 2 commits into
mainfrom
codex/m2-operator-controls-20260930

Conversation

@AyobamiH

Copy link
Copy Markdown
Collaborator

Continue the approved production handover, based on 2d0be2c44929ee604c0b04938ba34dde5d018cea.

Production recovery is now genuinely verified in private app run 36704719923 (55 tables / 19,932 rows; encrypted archive retained). The next boundary is stopping the old consumer and independently reading the new runtime without resetting or disclosing the existing operator tick token.

This small canonical-entry wrapper adds:

  • fail-closed WORKER_MAINTENANCE_MODE; business HTTP paths and scheduled work stop before core execution/config/database initialization;
  • a separately generated maximum-15-minute read-only probe lease for GET /readyz only, never /tick or ingestion;
  • exact owned-project matching before the native dependency probe;
  • reuse of the unchanged canonical readiness handler, including version/SHA/nonce checks and all three schema contracts;
  • removal of lease fields before passing env to normal execution (no process.env leakage).

No existing tick credential is rotated or exposed. Missing new bindings preserve current behavior. Release controls are not activated by merging. Publishing/generation controls remain false and automatic production activation remains held.

Tests exercise pause/default/typo behavior, all business paths, time bounds, wrong project/origins, credential isolation, native readiness and exact identity, and inability to turn a read-only lease into a tick. Existing readiness/workerd checks also run. CI and exact-pair cloud acceptance must pass before production activation. This is not itself a production migration or deployment.

Preserve existing tick authentication and native schema readiness. A separate
15-minute maximum probe lease can only access GET /readyz and must match the
owned project. Pause all business HTTP and scheduled execution before schema
handover, without changing credentials or granting the probe execution access.
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
oneclickpostfactory-agent cc11158 Commit Preview URL

Branch Preview URL
Sep 30 2026, 11:10 AM

@AyobamiH AyobamiH left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Technical implementation review of the exact Worker candidate cc11158, not an independent-reviewer approval. The owner has approved the guarded production handover.

Read the canonical wrapper changes and the completed exact-pair cloud acceptance 36724198906 (app aac7b6b92790c76eecf908e0974d38e37de652dc). The runtime retains native readiness, rejects wrong project/identity, bounds the independent probe lease to GET /readyz and 15 minutes, prevents it from invoking /tick, strips lease fields before normal execution, and blocks business handlers/scheduled execution before initialisation while paused. Missing new bindings preserve the existing default. Generation/publication controls are not enabled.

Exact Worker CI36706860708 and readiness36706861274 passed. The complete cloud acceptance repeated Worker CI,86 readiness/operator tests and10 workerd tests, then122 DB assertions, actual native atomic rollback and successful commit/restart,18 publication and13 job-ownership scenarios, then a deployed native Worker with six readiness checks, one durable completion, restart, independent fixture restore and no duplicate. 48 actual hosted database requests, denied requests=0, external effects=0. Temporary Worker/database cleanup and unchanged production deployments were verified.

I downloaded acceptance artifact11102394074 and verified ZIP SHA256 dbfb210d0170bc86de7994ffb140d99c3ca2e4df108c622f571696cb4e007f1f and result.json SHA2567742ff33f9457ef05568473156000e90d42a362ab5012fee414a128464934caa. No staging-only wrapper substitutes for the canonical Worker. Merge does not apply a migration or activate this version; production remains a separate exact-pair, recoverability-gated release.

@AyobamiH
AyobamiH marked this pull request as ready for review September 30, 2026 13:56
@AyobamiH
AyobamiH merged commit 66b17ef into main Sep 30, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant