Document provider recovery reconciliation

This commit is contained in:
2026-08-03 05:00:37 +02:00
parent 63f393afcb
commit e3e0fdaab5
3 changed files with 11 additions and 1 deletions
+6
View File
@@ -57,6 +57,12 @@ manual-intervention record means an operator must repair the current release or
restore a separately verified coordinated backup. Ops does not convert that
state into a safe rollback.
An `outcome_unknown` provider operation must be resolved in its owning module.
Mail SMTP and IMAP APPEND operations, for example, carry stable attempt IDs and
digest-only evidence; use Mail's command reconciliation with provider evidence.
Do not replay the original effect from Ops. Read-only Mail index/source scans
are fenced across nodes and may be repeated only after the prior fence closes.
For the `shared` profile, missing expected replicas, release/composition skew,
unserved queues, or an invalid PostgreSQL connection budget are readiness
errors. Stale historical records remain visible, but cannot downgrade one of