Skip to content

fix: ADR 0044 K5 follow-ups — operator /api/v1 paths + eviction-lease state re-check - #128

Merged
nikhilunni merged 2 commits into
mainfrom
fix/adr0044-k5-followups
Jun 8, 2026
Merged

nikhilunni merged 2 commits into
mainfrom
fix/adr0044-k5-followups

Conversation

@nikhilunni

Copy link
Copy Markdown
Contributor

Two bugs the live K5 cutover surfaced:

  1. Operator missing /api/v1 — the K3 operator's coord client called /api/admin/... / /api/hosts/:id without the version prefix; the dev-vm mock coord (accepts any path) masked it, but it 404s against the real coord, so drain-gated rollout + the K4 demand poll fail. Fixed via a centralized url() helper + a path-assertion test.
  2. idle-evict ↔ drain race — evict_session_to_state only guarded the in-memory binding, not the PG state; an idle-evict finishing as a drain dispatched the same session wedged it in Evacuating with no sandbox. Now re-reads the session under the lease and skips unless Active | Evicting.

just check green (1034 tests, incl. the new operator path test). Merging rebakes host-operator + coordinator and auto-rolls the prod coord with fix #2.

🤖 Generated with Claude Code

nikhilunni and others added 2 commits June 8, 2026 11:32
The K3 operator's coord client built paths like /api/admin/hosts/:id/cordon
and /api/hosts/:id — missing the /api/v1 prefix the whole coordinator
router is nested under (api/mod.rs). The dev-vm mock coord returned 200 for
any path and masked it; against the real coord every call 404s, so the
operator's drain-gated rollout (and the K4 fleet-demand poll) silently
fail. Caught by the live K5 cutover.

Centralise the prefix in a `url()` helper + a `urls_are_v1_prefixed` test
so a path typo can't slip past a permissive mock again.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… K5)

evict_session_to_state had a stale-binding guard on the in-memory registry
but not on the authoritative PG state. When an idle-evict completed exactly
as an admin drain dispatched the same session, the drain acquired the
(just-released) lease and drove an already-Idle session to Evacuating on a
destroyed sandbox — wedging it (Evacuating, no sandbox, no snapshot).

The lease is held until after the PG transition, so once held, any
concurrent eviction has fully completed. Re-read the session and skip
unless it's still Active or Evicting (the two legal inputs: direct
idle-evict/drain, and backstop-nominated). idle-evict and drain now
compose toward running_sandboxes=0 instead of colliding.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@nikhilunni
nikhilunni merged commit 50af6c8 into main Jun 8, 2026
12 checks passed
@nikhilunni
nikhilunni deleted the fix/adr0044-k5-followups branch June 8, 2026 18:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant