Skip to content

M3-25: prove retained real-feature restart recovery #46

Description

@zhouning

Goal

Use the bounded M3-24 retention window to prove that the exact successful real Chongqing authority survives controlled process restart without re-ingestion, repair or new ledger facts.

Acceptance criteria

  • Bind the rehearsal to the checked M3-24 evidence SHA, retention ID and retained runtime identities before any restart.
  • Restart retained PostgreSQL, MinIO, Gravitino and dedicated GDA Control PostgreSQL in dependency order.
  • Require stable namespace/StatefulSet/Service/PVC/image/container/volume identities and rotated Pod UIDs plus control PostgreSQL PID/StartedAt.
  • Reopen the retained Iceberg snapshot and Parquet, recompute nine spatial quality checks and verify unchanged object, body and row-set fingerprints.
  • Read Gravitino and GDA Control independently; preserve the projection, ledger counts, facts SHA and succeeded@3 verdict.
  • Exact terminal replay must return promotion_created=false with no new ResourceVersion, Run or authority facts.
  • Keep backup/PITR, independent failure domains, production restart recovery and production_ready false.
  • Record ADR-071 and wire evidence validation, platform truth and focused tests into CI.

Evidence target

ADR-071 plus checked, path-free M3-25 evidence proving local retained process-restart continuity for the exact M3-24 authority.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions