hub v0.110.0: allowlist + operator-only for offsite_proof_empty (R-87)
gates / gates (push) Successful in 15s
gates / gates (push) Successful in 15s
Controller v0.231.0 adds a nightly job that proves an app's newest off-site snapshot still CONTAINS that app's data. When it finds one that does not, it emits offsite_proof_empty. Two register lines, both load-bearing and both in this commit: - allowedEventTypes - an unallowlisted type is answered 400 and VANISHES, so this entry is what makes the alarm exist at all. - operatorOnlyEvents - a missing customerMessages entry is NOT a routing block (FormatCustomerEmail falls back to the raw message, the v0.78.0 defect that register was built for). A customer can take no action on a hollow recovery unit. DELIBERATELY NOT reusing backup_integrity_failed, which is the nearest existing type: it means THE STORE IS DAMAGED and carries the Hungarian template saying so. Here the store is sound and the CONTENT is absent - different cause, different action, and telling a customer their backups are damaged when they are not is the more expensive mistake. Same asymmetry looksLikeRepositoryDamage is shaped around. DELIBERATELY no customerMessages entry (the controller's dynamic Hungarian names the app and what is missing; a template would discard it) and DELIBERATELY not in perAppCooldownEvents (a fenced act - this job proves ONE app per night, so the coarse hourly cooldown is already the right grain). This widens the R-87 task's stated repo scope to felhom.eu/hub/. The reason is recorded in felhom-controller/CONTEXT.md ruling 4 rather than left as an unexplained diff. Hub green gate: go build/vet/test all pass, 18 packages.
This commit is contained in:
@@ -2005,6 +2005,20 @@ var allowedEventTypes = map[string]bool{
|
||||
"db_dump_failed": true,
|
||||
"backup_integrity_ok": true,
|
||||
"backup_integrity_failed": true,
|
||||
// controller v0.231.0 (R-87) — the nightly off-site PROOF found a backup that is READABLE and
|
||||
// contains none of the app's data. DELIBERATELY NOT `backup_integrity_failed`, which is the
|
||||
// nearest existing type and would be the wrong sentence: that one means the STORE IS DAMAGED and
|
||||
// carries a Hungarian template saying the integrity check found an error. Here the store is sound
|
||||
// and the CONTENT is missing — a different fact, a different cause and a different action.
|
||||
// Telling a customer their backups are damaged when they are not is the more expensive mistake,
|
||||
// and it is the one R-359's own `looksLikeRepositoryDamage` is shaped to avoid.
|
||||
//
|
||||
// NO `customerMessages` entry, deliberately: the controller sends a dynamic Hungarian message
|
||||
// naming the app and what is missing, and a template would DISCARD those specifics
|
||||
// (templates.go priority) — the `offbox_enlarge_blocked` / `disk_health_degraded` precedent.
|
||||
// Operator routing is enforced by `notify.operatorOnlyEvents`, in this same commit; this entry
|
||||
// alone does NOT make it operator-only (the v0.78.0 defect that register records).
|
||||
"offsite_proof_empty": true,
|
||||
"crossdrive_completed": true,
|
||||
"crossdrive_failed": true,
|
||||
// controller v0.134.1 — enlarged offsite push refused by the quota gate (warning; the controller's
|
||||
|
||||
Reference in New Issue
Block a user