Implement approval engine production readiness
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a05e2e-805b-7042-a750-71f473bceea2
This commit is contained in:
parent
ebce5abb27
commit
2bd2d19a98
30 changed files with 1679 additions and 53 deletions
31
docs/storage-operations.md
Normal file
31
docs/storage-operations.md
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
# Storage operations
|
||||
|
||||
Production uses one SQLite writer on persistent `ReadWriteOnce` storage.
|
||||
Production serve disables automatic migration and refuses schema drift or an
|
||||
in-memory database.
|
||||
|
||||
```bash
|
||||
approval-engine migrate --db /data/approvals.sqlite
|
||||
approval-engine verify --db /data/approvals.sqlite
|
||||
approval-engine backup --db /data/approvals.sqlite --output /backup/approval.sqlite
|
||||
```
|
||||
|
||||
Migration is repeatable and sets an explicit `PRAGMA user_version`. Backup uses
|
||||
SQLite's online backup API, verifies `PRAGMA integrity_check`, writes mode 0600,
|
||||
and refuses to overwrite a target.
|
||||
|
||||
Restore is a stopped-single-writer operation:
|
||||
|
||||
1. Stop the StatefulSet and confirm no approval-engine or migration process has
|
||||
the PVC open.
|
||||
2. Preserve the failed database and its `-wal`/`-shm` companions for analysis.
|
||||
3. Copy the verified backup to a new database path with owner 10001 and mode
|
||||
0600. Do not merge a backup with old WAL files.
|
||||
4. Run `verify`, then `migrate` if the release schema is newer, then `verify`
|
||||
again.
|
||||
5. Start exactly one replica and prove approval/entry/outbox counts, readiness,
|
||||
claim retrieval, and idempotent audit drain before reopening callers.
|
||||
|
||||
Approval mutation and outbox insertion share `BEGIN IMMEDIATE` and one commit;
|
||||
a failed outbox insert rolls the mutation back. Delivery occurs afterward and
|
||||
does not roll back a committed mutation.
|
||||
Loading…
Add table
Add a link
Reference in a new issue