Repository navigation
feat: add provider-level multi-instance failover (M5.1 core) - #41
Merged
Merged
Conversation
baseURLs config defines an endpoint pool (first entry primary, non-empty list wins over baseURL). Network/timeout/502/503/504/429 failures raise the endpoint's health penalty and fail over to the healthiest endpoint; penalties decay with a 30 s half-life so the primary is sticky and recovers the first slot about a minute after its last failure or on its next success. Pacing is per endpoint, the cache is keyed by the pool, and the totalBudgetMs deadline spans every endpoint's attempts. Contract failures and other 4xx never fail over; single-baseURL behavior is unchanged (existing tests pass unmodified). The CLI/state half of M5.1 (multi-entry setup --url, external endpoint list in state, per-endpoint doctor reporting) is deferred with its state-schema dependency recorded in the design doc.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The provider-level half of M5.1:
baseURLsconfig defines an ordered endpoint pool (first entry primary, non-empty list wins overbaseURL, at most 8 entries after duplicate collapse). A network error, timeout, or HTTP 502/503/504/429 raises that endpoint's health penalty and the next attempt — and the first attempt of later searches — goes to the healthiest endpoint. Penalties decay with a 30 s half-life, so the primary is sticky and regains the first slot about a minute after its last failure, or immediately after a successful search.Design:
docs/superpowers/specs/2026-09-19-external-failover-design.md· plan:docs/superpowers/plans/2026-09-19-external-failover.md.Semantics
contractfailures and other 4xx stay terminal — switching endpoints would silently mask a configuration problem, the same reasoning that keeps empty results honest.baseURLbehavior is unchanged.totalBudgetMsdeadline spans every endpoint's attempts;Retry-Afterstill binds 429 backoff; abort wins over everything.available()requires every named entry to be valid — one malformed entry makes the provider honestly unavailable instead of silently skipping it.Scope
The CLI/state half of M5.1 (multi-entry
setup --url, the external endpoint list in state, per-endpointdoctor/tunereporting) is deferred with its state-schema-3 dependency recorded in the design doc, not silently dropped. Configuring a pool today is a manual profile-config edit, documented in the README.Verification
pnpm verifygreen locally (typecheck, 901 tests passed / 4 opt-in skips, build, pack, packed-CLI check).baseURLtests pass unmodified.[dead, live]fails over and returns the same results as[live, dead]; subsequent searches keep steering away from the dead primary.