Skip to content

Rework postprocess Job upgrade semantics - #28

Merged
RayLi-Muye merged 1 commit into
mainfrom
feature/postprocess-job-upgrade-semantics
Jun 19, 2026
Merged

RayLi-Muye merged 1 commit into
mainfrom
feature/postprocess-job-upgrade-semantics

Conversation

@RayLi-Muye

Copy link
Copy Markdown
Owner

Closes #16

Scope

  • Make postprocessJob.mode: hook the default ownership model.
  • Render enabled postprocess Jobs as Helm post-install,post-upgrade hooks with before-hook-creation,hook-succeeded deletion.
  • Keep postprocessJob.mode: managed as an explicit opt-out for environments that want a stable release-owned Job and accept delete/recreate responsibility on pod-template changes.
  • Add schema validation for postprocess mode, hook events, and hook delete policy.
  • Extend chart contract tests and docs/evidence to cover the ownership model.

Decision

I chose Helm hook ownership over generated-name or a separate one-shot template because it is the smallest chart-native change that avoids normal Helm patch attempts against immutable Kubernetes Job.spec.template fields. Generated names would create orphan/cleanup ambiguity in this public chart; a separate one-shot template would move ownership outside the chart without giving reviewers a default safe contract.

Acceptance Criteria

  • Postprocess image, args, env, and pod-template changes avoid the normal Helm release patch path in default hook mode.
  • The ownership model is documented in README and architecture/evidence docs.
  • Managed mode remains available for private environments that intentionally want a stable release-owned Job.
  • Helm lint, template rendering, kubeconform, smoke, schema, and contract tests pass locally and in CI.

Validation

  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make test
  • make smoke-local
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make lint
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make template >/tmp/renderfarm-template-aws.yaml
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make template-local >/tmp/renderfarm-template-local.yaml
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make template-minio >/tmp/renderfarm-template-minio.yaml
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make template-security >/tmp/renderfarm-template-security.yaml
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH scripts/render-examples.sh
  • python3 -m json.tool charts/render-worker/values.schema.json >/tmp/render-worker-values.schema.json
  • bash -n scripts/chart-contract-tests.sh
  • git diff --check
  • python3 /Users/winnie/.codex/skills/autoreview/scripts/autoreview --mode local

render-examples.sh validated default, local, local-minio, AWS GPU/SQS, and security manifests with kubeconform strict.

Docs Impact

  • README documents postprocessJob.mode and the hook/managed ownership tradeoff.
  • Architecture and evidence docs now describe hook mode as the upgrade-safe default.
  • Roadmap/VISION/delivery prompts no longer treat Rework postprocess Job upgrade semantics #16 as pending.

Risk And Rollback

Risk is moderate but bounded: enabled postprocess Jobs now default to hook ownership instead of normal Helm release ownership. This intentionally changes upgrade behavior to avoid immutable Job pod-template patch failures. Roll back by reverting this PR, or set postprocessJob.mode: managed in private values to preserve release-owned stable Job behavior.

Safety Boundary

No deploy, release, live cluster migration, real cloud resource operation, production data access, sensitive credential use, paid API access, or destructive git operation was performed.

@RayLi-Muye
RayLi-Muye merged commit 1fa754f into main Jun 19, 2026
1 check passed
@RayLi-Muye
RayLi-Muye deleted the feature/postprocess-job-upgrade-semantics branch June 19, 2026 02:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Rework postprocess Job upgrade semantics

1 participant