docs(mesh): Phase 6 plan+ledger updates through Task 7
Records the Task 2/3 fallback+scoping corrections, the Task 6 no-flip decision (data-backed), and task statuses 0-7. Claude-Session: https://claude.ai/code/session_01GASWkNEi68FSCtvr6rLoEW
This commit is contained in:
@@ -354,34 +354,43 @@ legacy nodes unaffected.
|
||||
|
||||
---
|
||||
|
||||
### Task 6: Flip compiled transport-mode defaults to split-correct
|
||||
### Task 6: Compiled transport-mode defaults — DECIDED: do NOT flip (data-backed deviation)
|
||||
|
||||
**Classification:** small
|
||||
**Estimated implement time:** ~3 min
|
||||
**Parallelizable with:** Task 5 (disjoint files)
|
||||
**Classification:** small → **resolved as a no-code decision 2026-07-24**
|
||||
**Parallelizable with:** Task 5
|
||||
|
||||
**Context (decision 2):** so a fresh deploy is split-correct without per-node overrides, change the
|
||||
compiled defaults. `redundancy-state`/`fleet-status` stay DPS regardless.
|
||||
**Original intent (decision 2):** change the compiled `MeshTransport:Mode`/`Telemetry:Mode`/
|
||||
`TelemetryDial:Mode` defaults to the split-correct values so a fresh deploy is split-correct without
|
||||
per-node overrides.
|
||||
|
||||
**Files:**
|
||||
- Modify: `src/Core/ZB.MOM.WW.OtOpcUa.Cluster/MeshTransportOptions.cs` (default `Mode` → `ClusterClient`)
|
||||
- Modify: `src/Core/ZB.MOM.WW.OtOpcUa.Cluster/TelemetryOptions.cs` (`TelemetryOptions.Mode` and
|
||||
`TelemetryDialOptions.Mode` defaults → `Grpc`)
|
||||
- Leave `ConfigSourceOptions.Mode` default = `Direct` (fused central stays Direct; Phase 4 validator
|
||||
forces driver-only to FetchAndCache).
|
||||
- Update tests that assert the old defaults (grep for `ModeDps`/`Mode == "Dps"`/`.Mode.ShouldBe` in
|
||||
the Cluster.Tests and any options tests; adjust to the new defaults). Update `appsettings.json`
|
||||
comments/keys if they document the default.
|
||||
**What the blast-radius assessment found (read-only, this session):** flipping the compiled defaults
|
||||
is **HIGH-RISK and low-value**. Every one of the three transport-option validators fail-closes when its
|
||||
mode is the non-Dps value but the mode's prerequisites are unset — and *nothing in the repo sets those
|
||||
sections*:
|
||||
- `MeshTransport:Mode=ClusterClient` requires `CentralContactPoints` — no `appsettings*.json` and no
|
||||
test harness sets it → `ValidateOnStart` throws at boot.
|
||||
- `Telemetry:Mode=Grpc` requires `GrpcListenPort`+`ApiKey` on a driver node — same gap.
|
||||
- `TelemetryDial:Mode=Grpc` requires `ApiKey` with **no role gate at all** — breaks even roleless
|
||||
fixtures and docker-dev's 4 site nodes.
|
||||
- Concretely this hard-fails **all 14 `Host.IntegrationTests`** (via `TwoNodeClusterHarness`, which
|
||||
sets none of these), **all 5 shipped appsettings profiles**, and several unit tests asserting the
|
||||
Dps default.
|
||||
|
||||
**Steps:**
|
||||
1. Change the three default initializers.
|
||||
2. Grep + update every test asserting the prior default (there are a handful — do not miss the
|
||||
Phase 2/5 option tests).
|
||||
3. Confirm the docker-dev rig (Task 7) does not *rely* on the old default anywhere (it will set modes
|
||||
explicitly anyway).
|
||||
**Why not flipping is correct, not a compromise:** the Task 5 `SplitTopologyTransportValidator`
|
||||
already forces `ClusterClient`/`Grpc`/`Grpc` onto **exactly** the nodes carrying a post-Phase-6
|
||||
`cluster-{ClusterId}` role, fail-closed, with a precise message — which *is* "a fresh Phase-6 deploy is
|
||||
split-correct," achieved more robustly than a default flip (a split node cannot even boot on the wrong
|
||||
transport). Flipping the compiled defaults would merely duplicate that enforcement for split nodes
|
||||
while indiscriminately breaking every legacy/test/admin node that legitimately still runs Dps. The
|
||||
docker-dev rig (Task 7) sets the modes **explicitly** on its cluster-role nodes, so it never relies on
|
||||
the default anyway.
|
||||
|
||||
**Acceptance:** `new MeshTransportOptions().Mode == ClusterClient`; both telemetry defaults `Grpc`;
|
||||
all options tests green.
|
||||
**Decision:** keep `MeshTransportOptions.Mode`/`TelemetryOptions.Mode`/`TelemetryDialOptions.Mode`
|
||||
defaults at `Dps`. No code change. Enforcement of split-correctness lives in Task 5's validator + the
|
||||
explicit Task 7 rig config. Recorded in `docs/Configuration.md` (Task 8) so the next reader knows the
|
||||
defaults are intentionally Dps and the validator is the guardrail.
|
||||
|
||||
**Acceptance:** MET by decision — the split validator (Task 5) is the guardrail; no default flip.
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user