Repository navigation
revert(seinode): restore the create-only spec.nodeConfig rule (spec 013 reverted) - #610
Conversation
…13 reverted) Reverts #608 (21ae61d). Every non-frozen arctic-1 node moved to spec.nodeConfig in place on 2026-10-08 (PLT-1410), so the temporary switch goes: the CRD rule is again has(self.nodeConfig) == has(oldSelf.nodeConfig), and SyncStatefulSet no longer recreates a StatefulSet whose podManagementPolicy differs. The spec 013 document stays, marked Reverted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
PR SummaryMedium Risk Overview
Docs mark spec 013 as Reverted; tests drop switch/recreate coverage and envtest Reviewed by Cursor Bugbot for commit e6501f4. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
This reverts #608. spec.nodeConfig is fixed at creation again, through has(self.nodeConfig) == has(oldSelf.nodeConfig), and SyncStatefulSet no longer recreates a StatefulSet with orphan propagation or waits for a terminating one. It touches the same ten files as #608, the CRD output matches the marker, and the remaining impostor-recovery path is unchanged, so nothing blocks; codex's reading found nothing, which agrees with this review but added no finding of its own.
Non-blocking
- Removing the recreate-and-wait path makes this rollout safe only if no node is still mid-switch in any cell when the new controller starts. A node in that state would have
spec.nodeConfigbut still an OrderedReady StatefulSet, or have its old StatefulSet still terminating under the orphan delete. Every reconcile of such a node would then fail its Apply against the immutablepodManagementPolicy, or patch the terminating object, and no code path would recover it. The description puts the rollout after the PLT-1410 waves, but nothing enforces that order, so check the live state per cell before bumping the pin: every nodeConfig SeiNode's StatefulSet is Parallel and none is terminating.
seidroid review · decision approve · session 5005721810e046afbdc7316ff5f48a7e · turn resp_claude_466510bcf693a09c1abad0d991451883 · item fa505833065d50019774ac982fcf8186
Findings: 0 blocking | 1 non-blocking | 0 posted inline
Summary
Reverts #608 (
21ae61d), the temporary spec 013 switch. Every non-frozen arctic-1 SeiNode moved tospec.nodeConfigin place on 2026-10-08 (PLT-1410: 46 nodes in prod, prod-euw1, prod-use2, and harbor). The frozen nodes stay controller-configured by decision.has(self.nodeConfig) == has(oldSelf.nodeConfig), sospec.nodeConfigis again fixed at creation.podManagementPolicydiffers. It also no longer waits for a terminating StatefulSet.Reverted. The runbook (sei-protocol/runbooks#168) cites it for a later in-place move.Why this is safe to roll
noderesource.gochanged only a comment, so the rendered StatefulSet is the same. A controller roll restarts no SeiNode pod.ParallelStatefulSet that matches its desired policy. Every controller-configured node, including the frozen ones, matchesOrderedReady.nodeConfig.Verification
gofmt -l .: no files.go vet ./...: clean.staticcheck ./...: only theSA1019client.Applydeprecation notes, whichmainalso has.make manifests: no drift.go testwith coverage, go1.26.0): pass.make test-modules: pass.make test-integration(envtest): pass.golangci-lint(the local binary is built with go1.25 and refuses a go1.26.0 module) andgovulncheck(the run errored on the package pattern). CI runs lint.Rollout
The rollout comes after the PLT-1410 peer-ID waves finish, so a controller restart cannot stall a wave's gate. It is one cell at a time, through the platform controller pin.
🤖 Generated with Claude Code