Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Routing allowlists travel in the workflow env, not with the image: a self-heal can recreate Maui with a list its image cannot serve

Abierto
#768 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
3/5
Tiempo estimado
1-2 días
Aptitud para principiantes
65/100
Tipo de issue
Refactorización
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
dockerfile, typescript

Línea de trabajo

Examine backend-ts/Dockerfile to add ARG declarations for the routing lists and convert them to ENV. Remove WORKWELL_OFFICIAL_MEASURES and WORKWELL_DERIVED_MEASURES from the deploy and reconcile workflow env arrays. Update official-flip-config.test.ts to read these values from build args instead of jq arrays, and revise docs/DEPLOY.md to describe the new build args approach. Done when the reconciler no longer sets these keys and the parity test confirms the image carries its own routing lists.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

infra maui-pilot

The hazard

WORKWELL_OFFICIAL_MEASURES and WORKWELL_DERIVED_MEASURES live in the deploy workflow's env array and are mirrored by the reconciler (reconcile-maui-mieweb.yml), which recreates the container from maui-latest with main's env whenever an in-place restart fails. The lists therefore describe what main expects, while the image describes what the container can serve. The two drift in one realistic sequence, with no operator action:

  1. A merge adds an id to a list (a newly vendored official measure, or a translation under measures/derived/).
  2. The first deploy after it fails before its image is built (a VSAC outage at the vendor step is enough; deploys depend on VSAC).
  3. maui-latest stays the older image. The next health event makes the reconciler recreate it with main's env.
  4. The router refuses at construction (no executable translation is committed for a translation; the artifact-not-committed sentence for an official id), the worker logs OFFICIAL_ROUTING_MISCONFIGURED and still boots, and every evaluating route answers 500 for all routed measures while /actuator/health stays 200, so nothing heals it.

The same state follows a deliberate rollback to an older image while the key stays on main. Both paths are documented in docs/DEPLOY.md (Step 1 and the rollback section, since #767) with the manual check: confirm the post-merge deploy promoted maui-latest, or unset the key on main. That is a checklist, not a guard.

The fix to decide

Make the routing lists travel with the image, so an image can never be started with a list it cannot serve:

  • backend-ts/Dockerfile: ARG WORKWELL_OFFICIAL_MEASURES / ARG WORKWELL_DERIVED_MEASURES → ENV, the same reasoning the Dockerfile already gives for WORKWELL_BUILD_SHA; the deploy passes them as build args from one place.
  • Drop both keys from the deploy and reconcile env arrays; the reconciler then needs no copy to keep in step.
  • official-flip-config.test.ts reads the build args instead of the jq arrays (the agreement, subset, TWH/staging-none and vendoring-before-build tests keep their meaning; the deploy↔reconcile parity test becomes "the reconciler sets neither key").
  • CI's e2e-maui keeps its plain env (it runs from source, not from the image); the parity test compares it with the build args.
  • docs/DEPLOY.md: the "routing lists are workflow edits only, reconcile must match" trap becomes "routing lists are build args".

Alternative, smaller: the reconciler reads the image's baked build sha and drops a key whose artifact that sha predates. More moving parts for the same outcome.

Why it is not in #767

#767 turned the first translation on; widening it to move both allowlists into the image would have mixed two topics. The hazard class pre-exists for the official list and has been handled by convention; the translation adds one more way the first deploy can fail before the image builds.

Found by the adversarial review of #767 (finding 1).

Lenguaje dominante
TypeScript
Estrellas
0
Forks
0
Merge medio
2 h 51 min
PR fusionados (30 d)
109

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de Taleef7/workwell

Todos los issues de Taleef7/workwell

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.