feat(overview): poller, leader aggregation and the dashboard UI

Tasks 3.4-3.6 of the overview-dashboard plan.

Polling (3.4/3.5):
- OverviewPollerService: one timer at the fastest configured cadence, each
  target polled when its own interval is due, fan-out per sweep, no retries
  (the next tick is the retry, so damping stays the only place that decides
  whether a failure is worth showing).
- OverviewSnapshotStore: atomic swap of a complete immutable graph plus a
  change event. Pages read it and never probe — the cache-first requirement.
- LeaderResolver: per-group leader from akka-cluster data, with the
  split-brain flag scoped to members that are actually answering, so an
  ordinary failover is not misread as a disagreement.

UI (3.6): ThemeShell + StatusPill/TechCard composition against the mockup;
instance cards carry the status stripe (dashed for Unreachable), the check
detail list and the raw ready/active signal line.

Two defects found by verification rather than by review:

- The active tier answers with a status code and an EMPTY body, but the client
  demanded parseable JSON on every probe — so a healthy pair rendered as
  "role unknown" instead of Active/Standby. Split into ProbeAsync (ready tier,
  body is the payload) and ProbeStatusAsync (active tier, code is the answer).
  Caught by a live smoke run against two fake health endpoints; the poller
  tests now serve an empty body so they hold the fix.

- SweepAsync published even when cancellation was already requested, leaving a
  half-probed registry as the store's final state on shutdown. It now checks
  the token itself rather than relying on the transport to throw.

Also: app.UseAntiforgery() is required despite the anonymous-by-design
pipeline — AddRazorComponents stamps antiforgery metadata unconditionally and
the endpoint middleware hard-fails without it (every page was 500). Chosen
over DisableAntiforgery() so a future form is protected by default.

147 tests, 0 warnings. Live-verified end to end against fake endpoints:
Up/Unreachable/Active/Standby, leader chip, cluster-data line, KPI counts.
This commit is contained in:
Joseph Doherty
2026-07-24 07:05:16 -04:00
parent 61fc88c8a8
commit 5fe7135e2c
24 changed files with 2829 additions and 11 deletions
@@ -169,6 +169,59 @@ public class ZbHealthReportClientTests
() => client.ProbeAsync("http://node/health/ready", ProbeTimeout, shutdown.Token));
}
[Theory]
[InlineData(HttpStatusCode.OK, 200)]
[InlineData(HttpStatusCode.ServiceUnavailable, 503)]
public async Task ProbeStatus_EmptyBody_IsStillAnAnswer(HttpStatusCode status, int expected)
{
// The active tier answers with a status code; the body is not part of that contract. An
// empty 200/503 is the endpoint telling us the role plainly, and insisting on parseable
// JSON here reports every such node as "role unknown".
var client = ClientReturning(status, string.Empty);
var result = await client.ProbeStatusAsync("http://node/health/active", ProbeTimeout);
Assert.True(result.Reachable);
Assert.Equal(expected, result.StatusCode);
Assert.Null(result.Report);
Assert.Null(result.Error);
}
[Fact]
public async Task ProbeStatus_StillParsesABodyWhenOneIsThere()
{
var client = ClientReturning(HttpStatusCode.OK, ReadyHealthyWithData);
var result = await client.ProbeStatusAsync("http://node/health/active", ProbeTimeout);
Assert.Equal("Healthy", result.Report!.Status);
}
[Fact]
public async Task ProbeStatus_TransportFailure_IsStillUnreachable()
{
// Relaxing the body requirement must not relax what "reachable" means.
var client = new ZbHealthReportClient(
new HttpClient(new ThrowingHandler(new HttpRequestException("Connection refused"))));
var result = await client.ProbeStatusAsync("http://node/health/active", ProbeTimeout);
Assert.False(result.Reachable);
Assert.Null(result.StatusCode);
}
[Fact]
public async Task Probe_ReadyTierStillDemandsAParseableBody()
{
// The ready tier's body IS the payload — the per-check list and the leader data come from
// it. An empty 200 there means something other than a family app is on that port.
var client = ClientReturning(HttpStatusCode.OK, string.Empty);
var result = await client.ProbeAsync("http://node/health/ready", ProbeTimeout);
Assert.False(result.Reachable);
}
private sealed class StubHandler((HttpStatusCode Status, string Body, string ContentType) response)
: HttpMessageHandler
{