Skip to content

feat(platform): verify local cross-cluster metadata recovery - #8

Open
zhouning wants to merge 1 commit into
feat/ar1-metadata-fabric-durable-backup-contractfrom
feat/ar1-metadata-fabric-cross-cluster-recovery
Open

feat(platform): verify local cross-cluster metadata recovery#8
zhouning wants to merge 1 commit into
feat/ar1-metadata-fabric-durable-backup-contractfrom
feat/ar1-metadata-fabric-cross-cluster-recovery

Conversation

@zhouning

Copy link
Copy Markdown
Owner

Summary

  • extend the metadata recovery runner so every kubectl call is explicitly bound to a source or recovery context
  • add a bounded Docker-host MinIO repository with versioning, COMPLIANCE/1 day Object Lock, separate writer/reader identities, and fail-closed artifact checks
  • restore OpenMetadata PostgreSQL, Gravitino PostgreSQL, and OpenSearch into a distinct kind cluster with independent cluster/PVC identities
  • register the local-only runtime, add required CI validation, ADR-040, roadmap/system-of-record updates, and committed evidence/current-contract tests
  • refresh the M2b-1/M2b-2 evidence invalidated by the shared recovery runner change

Live evidence

  • source context/UID: docker-desktop / c3c9bbab-2b36-4359-a7ac-e3de194445ab
  • recovery context/UID: kind-gda-metadata-recovery / 04ddf8f4-6d62-4e6d-bbd7-2eecb3f94858
  • cross-cluster duration: 122.791s
  • cross-cluster contract: 352f59b10d845b288a465b59386e7a15f42aa706559fe337db5ed1dcb7234815
  • cross-cluster evidence: 9eaf8cec9ec2d3763260c271c0c27c1c3251717820d38aadfef0bec7d7a574a8
  • refreshed repository evidence: 2897f9e6aaae21fb366da0b72edea5cf072d5b2c1aeac0807d263bd0a5f5f133
  • refreshed recovery evidence: da1214294045f8b0abe2e2775b81ef33967eac9ab0e97055ae80212ac0c08a4b

The source services returned Ready; recovery namespaces, temporary credentials, Docker containers/volumes, the temporary kind cluster, and test caches were removed after verification.

Validation

  • required platform tests: 492 passed
  • PostgreSQL ledger/gateway tests: 3 passed
  • route evaluation contract: 41 passed
  • final metadata/runtime focused tests: 36 passed
  • runtime dependency constraints: 4 passed
  • Python compile, shell syntax, git diff --check, static contract validators, evidence verification, and three Kustomize builds passed
  • npm ci and the production frontend build passed

Claim boundary

local_cross_cluster_recovery_verified=true is limited to two Kubernetes clusters on one Docker Desktop host with a Docker-host S3-compatible repository. Production bucket/durability/retention, TLS/KMS, workload identity, source-host loss, RPO/RTO, production cross-cluster or cross-region recovery, OIDC, NetworkPolicy enforcement, GDA writes, and production readiness remain false.

Stack

This PR is based on #7 and should be reviewed/merged after #7. It does not merge or modify #7 automatically.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant