Close Knative CPU request handoff with installer evidence

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e396-d089-7653-b0a1-734cac532913
This commit is contained in:
tegwick 2026-09-27 18:01:25 +02:00
parent 8caf491854
commit cd38dba365
4 changed files with 43 additions and 21 deletions

View file

@ -6,5 +6,9 @@ This rail inherits the versioned `rail-kubernetes` common workload contract and
owns only Knative-specific activation, scale-to-zero, revision, traffic, owns only Knative-specific activation, scale-to-zero, revision, traffic,
cold-start, and rollback semantics. cold-start, and rollback semantics.
The repo is currently at `declared` readiness. It does not claim that Knative The [declaration](declarations/rail.yaml) records `verified` readiness, backed by
is installed or production-approved on any reef. the [2026-07-26 lifecycle evidence](../reef-railiance/evidence/verification/rail-knative-v1.22.0-2026-07-26.json)
on reef-railiance. This is not production approval.
The [substrate runbook](docs/substrate-runbook.md) describes the declared CPU
requests consumed by the railiance-cluster installer.

View file

@ -9,11 +9,11 @@
| Kind | ID | Status | Lane | Source | | Kind | ID | Status | Lane | Source |
| --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- |
| workplan | RAIL-KNATIVE-WP-0001 | finished | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md | | workplan | RAIL-KNATIVE-WP-0001 | finished | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md |
| workplan | RAIL-KNATIVE-WP-0002 | active | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md | | workplan | RAIL-KNATIVE-WP-0002 | finished | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md |
| task | RAIL-KNATIVE-WP-0001-T01 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md | | task | RAIL-KNATIVE-WP-0001-T01 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md |
| task | RAIL-KNATIVE-WP-0001-T02 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md | | task | RAIL-KNATIVE-WP-0001-T02 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md |
| task | RAIL-KNATIVE-WP-0001-T03 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md | | task | RAIL-KNATIVE-WP-0001-T03 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md |
| task | RAIL-KNATIVE-WP-0001-T04 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md | | task | RAIL-KNATIVE-WP-0001-T04 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md |
| task | RAIL-KNATIVE-WP-0002-T01 | done | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md | | task | RAIL-KNATIVE-WP-0002-T01 | done | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md |
| task | RAIL-KNATIVE-WP-0002-T02 | done | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md | | task | RAIL-KNATIVE-WP-0002-T02 | done | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md |
| task | RAIL-KNATIVE-WP-0002-T03 | wait | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md | | task | RAIL-KNATIVE-WP-0002-T03 | done | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md |

View file

@ -22,10 +22,16 @@ upstream's. These values were set live on 2026-09-21 as
because the node had 100% of its allocatable CPU requested and backups could because the node had 100% of its allocatable CPU requested and backups could
not be scheduled. Record: `the-custodian/docs/kubernetes-change-gate-decision.md`. not be scheduled. Record: `the-custodian/docs/kubernetes-change-gate-decision.md`.
A plain re-apply or upgrade of the upstream manifests restores the upstream The owner installer now renders these requests into the manifests before apply,
column. Every apply or upgrade must apply these patches afterwards, and an using separate Serving and Kourier overlays. Its verifier checks all six values.
upgrade to a new version needs a new `substrate/<version>/` with container Implementation and read-only live diff evidence are recorded in
names re-checked against that release. [RAIL-BS-WP-0015](../../railiance-cluster/workplans/RAIL-BS-WP-0015-knative-declared-cpu-requests.md),
implemented by railiance-cluster commit `3a5432270e275e978d6c8a99529fa7f8be6eef57`.
A plain re-apply of unpatched upstream manifests restores the upstream column.
Every apply or upgrade must preserve these patches, and an upgrade to a new
version needs a new `substrate/<version>/` with container names re-checked
against that release.
## Lessons ## Lessons

View file

@ -4,11 +4,11 @@ type: workplan
title: "Declare the Knative substrate CPU requests set live on railiance01" title: "Declare the Knative substrate CPU requests set live on railiance01"
domain: financials domain: financials
repo: rail-knative repo: rail-knative
status: active status: finished
owner: codex owner: codex
topic_slug: railiance topic_slug: railiance
created: "2026-09-21" created: "2026-09-21"
updated: "2026-09-21" updated: "2026-09-27"
depends_on: [] depends_on: []
state_hub_workstream_id: "8decbd8b-db3d-52b6-af16-ee84e2fd2e32" state_hub_workstream_id: "8decbd8b-db3d-52b6-af16-ee84e2fd2e32"
--- ---
@ -55,19 +55,31 @@ activator 2%/100%, webhook 10%/100%, gateway 10%/100%. Declared equals live.
```task ```task
id: RAIL-KNATIVE-WP-0002-T03 id: RAIL-KNATIVE-WP-0002-T03
status: wait status: done
priority: high priority: high
state_hub_task_id: "7cd0355e-0c53-5931-8d2a-601a129ad7da" state_hub_task_id: "7cd0355e-0c53-5931-8d2a-601a129ad7da"
``` ```
Waits on railiance-cluster, which owns the install (`install/knative/`). 2026-09-27: Closed after checking railiance-cluster commit
rail-knative does not edit that repository. The installer must apply `3a5432270e275e978d6c8a99529fa7f8be6eef57` and its completed
`substrate/v1.22.0/cpu-requests.patch.yaml` after each upstream apply, for [RAIL-BS-WP-0015](../../railiance-cluster/workplans/RAIL-BS-WP-0015-knative-declared-cpu-requests.md).
example by building the kustomization over its staged files, or by running The owner repository's [installer](../../railiance-cluster/install/knative/install.sh)
`kubectl patch deployment <name> -n <ns> --type strategic --patch-file <doc>` applies checksum-verified assets rendered through Serving and Kourier overlays
per document; `verify.sh` should assert the six requests. carrying all six declared CPU requests. Its
[verifier](../../railiance-cluster/install/knative/verify.sh) asserts those requests.
The [render tests](../../railiance-cluster/tests/test_knative_render.py) compare
the overlays with this repository's declaration and check that memory requests
and limits remain upstream's.
Because the values are already live, re-running the patched installer changes The owner workplan records read-only live diff evidence from 2026-09-21:
no running state. Running the *unpatched* installer before this lands reverts no Deployment changes remain. Re-running the installer is unnecessary for
the requests and should not be done. Rollback of the installer change is a this closure and was not performed. An apply can still reset runtime-managed
revert of its commit; the live values need no rollback. webhook rules before Knative fills them in again; it is not a blanket no-op.
Cluster-scoped installation remains owned by railiance-cluster.
Closure validation, 2026-09-27: `python3 -m pytest -q -p no:cacheprovider tests
/home/worsch/railiance-cluster/tests/test_knative_render.py` passed all nine
tests, including rendering checksum-verified upstream assets (no skips).
`python3 /home/worsch/rail-kubernetes/tools/validate_contracts.py --rail
declarations/rail.yaml` also passed. No open tasks remain in this repository's
two workplans; no new tasks or workplans were created.