[Task] Add multi-host orchestrator profile, fencing, and worker lifecycle #27
Open
opened 2026-07-30 18:56:08 +02:00 by zemion
·
9 comments
No Branch/Tag Specified
Labels
Clear labels
area/api
area/auth
area/db
area/devex
area/docs
area/governance
area/marketing
area/migrations
area/module-system
area/rbac
area/release
area/security
area/tenancy
area/webui
audit/complexity
audit/duplication
audit/false-positive
audit/needs-design
audit/quick-fix
audit/structural
codex/needs-human
codex/ready
module/access
module/addresses
module/admin
module/appointments
module/approvals
module/audit
module/calendar
module/campaign
module/cases
module/committee
module/connectors
module/core
module/dashboard
module/dataflow
module/datasources
module/decisions
module/dist-lists
module/dms
module/docs
module/encryption
module/erp
module/evaluation
module/files
module/fit-connect
module/forms
module/forms-runtime
module/helpdesk
module/identity
module/identity-trust
module/idm
module/ledger
module/mail
module/mandates
module/notifications
module/ops
module/organizations
module/parties
module/payments
module/permits
module/policy
module/poll
module/portal
module/postbox
module/projects
module/quick-access
module/records
module/reporting
module/risk-compliance
module/scheduling
module/search
module/services
module/tasks
module/templates
module/tenancy
module/tickets
module/views
module/voting
module/wiki
module/workflow
module/workflow-engine
module/xoev
module/xrechnung
module/xta-osci
source/backlog-import
source/security-audit
source/todo-scan
HTTP API contracts, routers, schemas, or API smoke behavior.
Authentication, sessions, access bootstrap, or login behavior.
Database sessions, models, transactions, or persistence primitives.
Local developer workflow, scripts, tests, tooling, or release helpers.
Durable documentation and project guidance.
Governance policy, audit, privacy, retention, or compliance behavior.
Public website, product messaging, publication copy, or legal page content.
Alembic migrations, schema bootstrap, or persistence evolution.
Module discovery, manifests, capabilities, routing, or optional integrations.
Permissions, roles, delegation, or authorization policy.
Versioning, release locks, tags, packaging, or dependency pins.
Security posture, static analysis, supply-chain hardening, or vulnerability remediation.
Tenant boundaries, provisioning, or tenant-scoped data behavior.
Shared WebUI shell, frontend components, routing, or frontend tests.
Complexity finding from Radon, Xenon, or equivalent maintainability scans.
Duplicated-code finding from jscpd or equivalent similarity scans.
Audit finding reviewed as a narrow false positive or acceptable risk.
Audit finding that needs an architectural or product decision before implementation.
Audit finding that appears narrow and directly fixable.
Audit finding that needs design, refactoring, or behavior review.
Needs an explicit human decision before Codex should implement.
Suitable for Codex to pick up with the existing issue context.
GovOPlaN access, identity, authentication, RBAC, and administration behavior.
GovOPlaN Addresses module behavior or integration.
GovOPlaN Admin module behavior or integration.
GovOPlaN Appointments module behavior or integration.
GovOPlaN Approvals module behavior or integration.
GovOPlaN Audit module behavior or integration.
GovOPlaN Calendar module behavior or integration.
GovOPlaN campaign module behavior or integration.
GovOPlaN Cases module behavior or integration.
GovOPlaN Committee module behavior or integration.
GovOPlaN Connectors module behavior or integration.
GovOPlaN core runner, shared primitives, shell, or extension points.
GovOPlaN Dashboard module behavior or integration.
GovOPlaN Dataflow module behavior or integration.
GovOPlaN governed datasource contracts, catalogs, and integrations.
GovOPlaN formal Decisions module behavior or integration.
GovOPlaN Distribution Lists module behavior or integration.
GovOPlaN Dms module behavior or integration.
GovOPlaN Docs module behavior or integration.
GovOPlaN Encryption key custody, cryptographic policy, and E2EE integration.
GovOPlaN Erp module behavior or integration.
GovOPlaN Evaluation module behavior or integration.
GovOPlaN files module behavior or integration.
GovOPlaN Fit Connect module behavior or integration.
GovOPlaN Forms module behavior or integration.
GovOPlaN Forms Runtime module behavior or integration.
GovOPlaN Helpdesk module behavior or integration.
GovOPlaN Identity module behavior or integration.
GovOPlaN Identity Trust module behavior or integration.
GovOPlaN Idm module behavior or integration.
GovOPlaN Ledger module behavior or integration.
GovOPlaN mail module behavior or integration.
GovOPlaN Mandates, jurisdiction, responsibility, and authority behavior or integration.
GovOPlaN Notifications module behavior or integration.
GovOPlaN Ops module behavior or integration.
GovOPlaN Organizations module behavior or integration.
GovOPlaN procedure Parties, representation, and delivery-authority behavior or integration.
GovOPlaN Payments module behavior or integration.
GovOPlaN Permits module behavior or integration.
GovOPlaN Policy module behavior or integration.
GovOPlaN Poll module behavior or integration.
GovOPlaN Portal module behavior or integration.
GovOPlaN Postbox module behavior or integration.
GovOPlaN Projects module behavior or integration.
GovOPlaN configurable task-local Quick Access behavior and integrations.
GovOPlaN Records and eAkte lifecycle behavior or integration.
GovOPlaN Reporting module behavior or integration.
GovOPlaN Risk Compliance module behavior or integration.
GovOPlaN Scheduling module behavior or integration.
GovOPlaN Search module behavior or integration.
GovOPlaN versioned institutional Services behavior or integration.
GovOPlaN Tasks module behavior or integration.
GovOPlaN Templates module behavior or integration.
GovOPlaN Tenancy module behavior or integration.
GovOPlaN Tickets module behavior or integration.
GovOPlaN governed task views, interface projections, and workflow view integration.
GovOPlaN Voting module behavior or integration.
GovOPlaN Wiki module behavior or integration.
GovOPlaN Workflow module behavior or integration.
GovOPlaN Workflow Engine runtime, persistence, or integration.
GovOPlaN Xoev module behavior or integration.
GovOPlaN Xrechnung module behavior or integration.
GovOPlaN Xta Osci module behavior or integration.
priority
p0
Immediate stop-the-line priority.
priority
p1
High priority for the next focused work window.
priority
p2
Normal planned priority.
priority
p3
Low priority or opportunistic cleanup.
Imported from markdown backlog, roadmap, plan, or TODO files.
Created from a structured security or code-quality audit report.
Imported from inline TODO/FIXME/HACK markers by the Gitea TODO importer.
status
blocked
Cannot progress without a decision, dependency, credential, or external change.
status
in-progress
Currently being worked.
status
needs-info
Needs clarifying input before implementation can proceed safely.
status
ready
Ready for implementation.
status
triage
Needs review, ownership, priority, or acceptance criteria.
type
bug
A reproducible defect, regression, or incorrect behavior.
type
debt
Cleanup, refactoring, risk reduction, or deferred engineering work.
type
docs
Documentation, process, or developer workflow work.
type
feature
New user-visible behavior or platform capability.
type
task
Implementation, maintenance, migration, or operational work.
type
user-story
End-to-end user journey or real-world process story used to steer product slices.
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: GovOPlaN/govoplan#27
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Objective
Extend the one-host replica contract delivered under #13 into a supported multi-host deployment profile without turning the Compose installer into a proprietary scheduler.
Parent story: GovOPlaN/govoplan#13.
Current baseline
docs/SCALING_AND_MULTI_HOST_DEPLOYMENT.mddefines the role and shared-state boundary.Scope
Acceptance criteria
Non-goals
Codex State: progress
Summary
Changed Files
tools/deployment/govoplan_deploy/kubernetes.pydocs/SCALING_AND_MULTI_HOST_DEPLOYMENT.mdVerification
tools/checks/check-focused.sh: passed, including 54 manifest contracts and 35 WebUI module permutationsNext / Blocked
Suggested status label:
status/in-progressCodex State: progress
Summary
Changed Files
docs/SCALING_AND_MULTI_HOST_DEPLOYMENT.mdtools/deployment/govoplan_deploy/kubernetes.pyVerification
33 deployment-installer tests passedNext / Blocked
Suggested status label:
status/in-progressAll source-controlled implementation that can be proven locally is pushed:
GovOPlaN/govoplan@ed31409).govoplan-core@d6255f9).govoplan-ops@b464d01).govoplan-deploy verify-kubernetesrecords sanitized evidence and can perform a bounded API-pod-loss drill while observing readiness and replacement. It requires at least two ready nodes and never stores the API key.Verification: deployment/inventory/publication suite
54 passed, 2 subtests; Core contract/runtime suite128 passed, 211 subtests; Ops5 passed; production WebUI build passed.This issue remains open only for target-environment evidence: deploy a pinned release on a real two-node Kubernetes cluster, then run:
The broader session/job/state-service recovery evidence remains tracked by #37. Source and local tests cannot manufacture that operational proof, so the issue is moved to
needs-info/needs-humanrather than closed.The previously missing immutable subject now exists and is independently verified:
1f039dd39c1ce2672f4978c8abc6dff862ef1445d703267e01855dee63200cb20921c91c3f95fbff550c8ca76e9a35cba3f69109runtime-distribution-2026-01git.add-ideas.de/govoplan/runtime-api@sha256:197ed01790986f2bc927eaa5d8348fa118702e5d2dc05feb851fc2643c23764agit.add-ideas.de/govoplan/runtime-web@sha256:e936cca124f1fad29a067834cf17627d4c236410fdc3fa129e0ccb26b8193812The release proves both architecture images and the one-host managed-ingress boundary. This pins the exact subject for the live Kubernetes acceptance run but does not replace it.
Remaining target inputs are now concrete: a reachable Kubernetes cluster with at least two schedulable nodes; a namespace and public target; external shared PostgreSQL, Redis, and S3 bindings; the adopted v0.1.14 installation state; and a temporary Ops read API key. During an approved node-loss window, run:
The current workspace has no Kubernetes client, kubeconfig, cluster credentials, Ops API key, or target endpoint, so it cannot truthfully produce this operational receipt. Once supplied on the target, the command fails closed unless API/WebUI pods span at least two nodes, all deployments are available, Ops reports the pinned release/composition, every worker queue is covered, database capacity is within budget, and the API pod-loss drill preserves readiness. Attach the sanitized receipt here; broader state-service/session/job recovery remains #37.
Codex State: needs-info
Summary
be51a9c).Changed Files
docs/PRODUCTION_TARGET_HANDOFF.mddocs/SCALING_AND_MULTI_HOST_DEPLOYMENT.mdVerification
tests.test_assessment_authority_keypair: passedNext / Blocked
Suggested status label:
status/needs-infoCodex State: needs-info
Summary
a24c94435e, signed manifest SHA-256 09ac1ade6ede4958bab0dfb7fd8f99246f4d991846308db1f410b25b46267840, and passing amd64/arm64 runtime receipts.Next / Blocked
Suggested status label:
status/needs-infoCodex State: progress
Summary
Changed Files
tools/lab/govoplan-lab.pytools/lab/govoplan_labtools/lab/govoplan-lab.example.tomltools/lab/govoplan-lab.acceptance.example.tomldocs/KUBERNETES_TEST_LAB.mdtools/deployment/govoplan_deploy/kubernetes.pyVerification
python -m unittest tests.test_kubernetes_lab tests.test_deployment_installer: 47 tests passedtools/checks/check-focused.sh: passed, including 50 WebUI module permutationsPinned v0.1.15 manifest, keyring and K3s installer digests reverified against their HTTPS sourcesNext / Blocked
Suggested status label:
status/in-progressCodex State: progress
Summary
Changed Files
tools/lab/tools/deployment/govoplan_deploy/cluster_evidence.pytools/deployment/govoplan_deploy/kubernetes.pytools/release/runtime/docs/KUBERNETES_TEST_LAB.md../govoplan-core/src/govoplan_core/db/migrations.py../govoplan-core/src/govoplan_core/server/default_config.pyVerification
66 deployment/runtime/lab unit tests passed8 Core runtime-agent/database-wait tests passedtools/checks/check-focused.sh passed, including 50 WebUI module permutationsSanitized evidence: ~/.local/share/govoplan/labs/govoplan-k8s-lab/evidence/kubernetes-multi-host.json (passed)Next / Blocked
Suggested status label:
status/in-progressCodex State: target rehearsal passed
Immutable subject
v0.1.187003232331780add84a167169398918c707b19a9f8e8329c0d105184ee4d6009git.add-ideas.de/govoplan/runtime-api@sha256:be9fb2b14b03232b820ee9bdb57d4ad34b753f28765813eac728bf1869ccb8dcgit.add-ideas.de/govoplan/runtime-web@sha256:54a1a6ab0a304f22a852d6fa131c598de4ec8287a5a5a880e36b2a3f0217f2d6Live rehearsal
A four-VM K3s rehearsal deployed the signed release with one control, two workers and one external shared-state VM. API, WebUI and workers span both Kubernetes workers. All readiness, deployment, composition, version, queue and database-budget checks passed.
The first pod-loss run exposed a real endpoint-termination race. The generated API workload now has a 10-second pre-stop drain and 30-second termination grace period (
GovOPlaN/govoplan@389df7c). A repeated public-path drill then deleted and replaced one API pod with zero observed readiness failures.Private sanitized receipt:
kubernetes-multi-host-v0.1.18-20260805T195355Z.json259f8e33b7b7a7161e1278f3ae94d52d99d88fcc2659fd1f1f8a2808cfb08abcpassedThe strict private-CA profile was also corrected and verified with
openssl verify -x509_strict(GovOPlaN/govoplan@3b9ae90).Remaining acceptance boundary
This inventory is deliberately
mode = rehearsal: both worker VMs share the same physical hypervisor and failure domain. It proves Kubernetes behavior and removes the previous release/tooling blockers, but it cannot prove independent-host failure.Keep this issue open until the same pinned process is run with at least two independently controlled physical hypervisors or availability zones and the operator supplies that out-of-band topology evidence. The broader session/job/state-service and maturity evidence remains #37.