Close Knative CPU request handoff with installer evidence

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e396-d089-7653-b0a1-734cac532913
This commit is contained in:
tegwick 2026-09-27 18:01:25 +02:00
parent 8caf491854
commit cd38dba365
4 changed files with 43 additions and 21 deletions

View file

@ -6,5 +6,9 @@ This rail inherits the versioned `rail-kubernetes` common workload contract and
owns only Knative-specific activation, scale-to-zero, revision, traffic,
cold-start, and rollback semantics.
The repo is currently at `declared` readiness. It does not claim that Knative
is installed or production-approved on any reef.
The [declaration](declarations/rail.yaml) records `verified` readiness, backed by
the [2026-07-26 lifecycle evidence](../reef-railiance/evidence/verification/rail-knative-v1.22.0-2026-07-26.json)
on reef-railiance. This is not production approval.
The [substrate runbook](docs/substrate-runbook.md) describes the declared CPU
requests consumed by the railiance-cluster installer.

View file

@ -9,11 +9,11 @@
| Kind | ID | Status | Lane | Source |
| --- | --- | --- | --- | --- |
| workplan | RAIL-KNATIVE-WP-0001 | finished | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md |
| workplan | RAIL-KNATIVE-WP-0002 | active | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md |
| workplan | RAIL-KNATIVE-WP-0002 | finished | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md |
| task | RAIL-KNATIVE-WP-0001-T01 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md |
| task | RAIL-KNATIVE-WP-0001-T02 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md |
| task | RAIL-KNATIVE-WP-0001-T03 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md |
| task | RAIL-KNATIVE-WP-0001-T04 | done | — | workplans/RAIL-KNATIVE-WP-0001-bootstrap-derived-rail.md |
| task | RAIL-KNATIVE-WP-0002-T01 | done | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md |
| task | RAIL-KNATIVE-WP-0002-T02 | done | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md |
| task | RAIL-KNATIVE-WP-0002-T03 | wait | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md |
| task | RAIL-KNATIVE-WP-0002-T03 | done | — | workplans/RAIL-KNATIVE-WP-0002-declare-substrate-cpu-requests.md |

View file

@ -22,10 +22,16 @@ upstream's. These values were set live on 2026-09-21 as
because the node had 100% of its allocatable CPU requested and backups could
not be scheduled. Record: `the-custodian/docs/kubernetes-change-gate-decision.md`.
A plain re-apply or upgrade of the upstream manifests restores the upstream
column. Every apply or upgrade must apply these patches afterwards, and an
upgrade to a new version needs a new `substrate/<version>/` with container
names re-checked against that release.
The owner installer now renders these requests into the manifests before apply,
using separate Serving and Kourier overlays. Its verifier checks all six values.
Implementation and read-only live diff evidence are recorded in
[RAIL-BS-WP-0015](../../railiance-cluster/workplans/RAIL-BS-WP-0015-knative-declared-cpu-requests.md),
implemented by railiance-cluster commit `3a5432270e275e978d6c8a99529fa7f8be6eef57`.
A plain re-apply of unpatched upstream manifests restores the upstream column.
Every apply or upgrade must preserve these patches, and an upgrade to a new
version needs a new `substrate/<version>/` with container names re-checked
against that release.
## Lessons

View file

@ -4,11 +4,11 @@ type: workplan
title: "Declare the Knative substrate CPU requests set live on railiance01"
domain: financials
repo: rail-knative
status: active
status: finished
owner: codex
topic_slug: railiance
created: "2026-09-21"
updated: "2026-09-21"
updated: "2026-09-27"
depends_on: []
state_hub_workstream_id: "8decbd8b-db3d-52b6-af16-ee84e2fd2e32"
---
@ -55,19 +55,31 @@ activator 2%/100%, webhook 10%/100%, gateway 10%/100%. Declared equals live.
```task
id: RAIL-KNATIVE-WP-0002-T03
status: wait
status: done
priority: high
state_hub_task_id: "7cd0355e-0c53-5931-8d2a-601a129ad7da"
```
Waits on railiance-cluster, which owns the install (`install/knative/`).
rail-knative does not edit that repository. The installer must apply
`substrate/v1.22.0/cpu-requests.patch.yaml` after each upstream apply, for
example by building the kustomization over its staged files, or by running
`kubectl patch deployment <name> -n <ns> --type strategic --patch-file <doc>`
per document; `verify.sh` should assert the six requests.
2026-09-27: Closed after checking railiance-cluster commit
`3a5432270e275e978d6c8a99529fa7f8be6eef57` and its completed
[RAIL-BS-WP-0015](../../railiance-cluster/workplans/RAIL-BS-WP-0015-knative-declared-cpu-requests.md).
The owner repository's [installer](../../railiance-cluster/install/knative/install.sh)
applies checksum-verified assets rendered through Serving and Kourier overlays
carrying all six declared CPU requests. Its
[verifier](../../railiance-cluster/install/knative/verify.sh) asserts those requests.
The [render tests](../../railiance-cluster/tests/test_knative_render.py) compare
the overlays with this repository's declaration and check that memory requests
and limits remain upstream's.
Because the values are already live, re-running the patched installer changes
no running state. Running the *unpatched* installer before this lands reverts
the requests and should not be done. Rollback of the installer change is a
revert of its commit; the live values need no rollback.
The owner workplan records read-only live diff evidence from 2026-09-21:
no Deployment changes remain. Re-running the installer is unnecessary for
this closure and was not performed. An apply can still reset runtime-managed
webhook rules before Knative fills them in again; it is not a blanket no-op.
Cluster-scoped installation remains owned by railiance-cluster.
Closure validation, 2026-09-27: `python3 -m pytest -q -p no:cacheprovider tests
/home/worsch/railiance-cluster/tests/test_knative_render.py` passed all nine
tests, including rendering checksum-verified upstream assets (no skips).
`python3 /home/worsch/rail-kubernetes/tools/validate_contracts.py --rail
declarations/rail.yaml` also passed. No open tasks remain in this repository's
two workplans; no new tasks or workplans were created.