Routing allowlists travel in the workflow env, not with the image: a self-heal can recreate Maui with a list its image cannot serve
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 65/100
- issue の種類
- リファクタリング
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 技術スタック
- dockerfile, typescript
調査の方向性
Examine backend-ts/Dockerfile to add ARG declarations for the routing lists and convert them to ENV. Remove WORKWELL_OFFICIAL_MEASURES and WORKWELL_DERIVED_MEASURES from the deploy and reconcile workflow env arrays. Update official-flip-config.test.ts to read these values from build args instead of jq arrays, and revise docs/DEPLOY.md to describe the new build args approach. Done when the reconciler no longer sets these keys and the parity test confirms the image carries its own routing lists.
索引モデルが issue の本文から書いたものです。
説明
The hazard
WORKWELL_OFFICIAL_MEASURES and WORKWELL_DERIVED_MEASURES live in the deploy workflow's env array and are mirrored by the reconciler (reconcile-maui-mieweb.yml), which recreates the container from maui-latest with main's env whenever an in-place restart fails. The lists therefore describe what main expects, while the image describes what the container can serve. The two drift in one realistic sequence, with no operator action:
- A merge adds an id to a list (a newly vendored official measure, or a translation under
measures/derived/). - The first deploy after it fails before its image is built (a VSAC outage at the vendor step is enough; deploys depend on VSAC).
maui-lateststays the older image. The next health event makes the reconciler recreate it withmain's env.- The router refuses at construction (
no executable translation is committedfor a translation; the artifact-not-committed sentence for an official id), the worker logsOFFICIAL_ROUTING_MISCONFIGUREDand still boots, and every evaluating route answers 500 for all routed measures while/actuator/healthstays 200, so nothing heals it.
The same state follows a deliberate rollback to an older image while the key stays on main. Both paths are documented in docs/DEPLOY.md (Step 1 and the rollback section, since #767) with the manual check: confirm the post-merge deploy promoted maui-latest, or unset the key on main. That is a checklist, not a guard.
The fix to decide
Make the routing lists travel with the image, so an image can never be started with a list it cannot serve:
backend-ts/Dockerfile:ARG WORKWELL_OFFICIAL_MEASURES/ARG WORKWELL_DERIVED_MEASURES→ENV, the same reasoning the Dockerfile already gives forWORKWELL_BUILD_SHA; the deploy passes them as build args from one place.- Drop both keys from the deploy and reconcile env arrays; the reconciler then needs no copy to keep in step.
official-flip-config.test.tsreads the build args instead of the jq arrays (the agreement, subset, TWH/staging-none and vendoring-before-build tests keep their meaning; the deploy↔reconcile parity test becomes "the reconciler sets neither key").- CI's
e2e-mauikeeps its plain env (it runs from source, not from the image); the parity test compares it with the build args. docs/DEPLOY.md: the "routing lists are workflow edits only, reconcile must match" trap becomes "routing lists are build args".
Alternative, smaller: the reconciler reads the image's baked build sha and drops a key whose artifact that sha predates. More moving parts for the same outcome.
Why it is not in #767
#767 turned the first translation on; widening it to move both allowlists into the image would have mixed two topics. The hazard class pre-exists for the official list and has been handled by convention; the translation adds one more way the first deploy can fail before the image builds.
Found by the adversarial review of #767 (finding 1).
- 主要言語
- TypeScript
- スター
- 0
- フォーク
- 0
- 平均マージ
- 2時間 51分
- マージ済み PR(30日)
- 109
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
Taleef7/workwell のほかの issue
-
documentation owner-ops waiting
難易度 1/5 1〜3時間 初心者へのやさしさ 86/100
メンテナーはふだん 1 日以内に返信
-
owner-ops waiting
難易度 1/5 1〜3時間 初心者へのやさしさ 85/100
メンテナーはふだん 1 日以内に返信
-
Measure labels carry no version outside the measure page, and several screens print a version that never ran対応中かも @Taleef7 が今日担当しました。 オープンmaui-pilot pilot-trust
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
メンテナーはふだん 1 日以内に返信
-
backend bug
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
メンテナーはふだん 1 日以内に返信
-
cql-engine pilot-trust
難易度 3/5 1〜2日 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
Taleef7/workwell の issue をすべて見る
似ている issue
-
component:sight
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
agentic-os-org/ANOLISA#6738 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
bug Durable Agents Observability (AI Telemetry) status: needs triage
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
mastra-ai/mastra#26470 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
paperclipai/paperclip#15630 ·
メンテナーはふだん 1 日以内に返信
-
[good first issue, hacktoberfest] ⛩️ Add new Theme: Sakura Latte (good-first-issue)対応中かも @PGrayCS が今日担当しました。 オープンcommunity first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
難易度 1/5 1〜3時間 初心者へのやさしさ 78/100
lingdojo/kana-dojo#31937 · コメント 1 件 · リアクション 5 件 ·
メンテナーはふだん 1 日以内に返信
-
feature/cohorts feature/feature-flags team/feature-flags
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
メンテナーはふだん 1 日以内に返信