Naeel
d1d1bffd7c
v0.1.13: Strategy Recreate + preStop + liveness fix (ERR-SQS-06 root cause)
...
- ensureDeployment: Strategy Recreate (not RollingUpdate) — prevents H2 file lock
when two pods mount same PVC simultaneously during rollout restart
- preStop: sleep 3 — graceful H2 shutdown before SIGTERM
- livenessProbe timeoutSeconds: 3 — prevents false positive on GC pause
- terminationGracePeriodSeconds: 15
- doc: thinking log, ERR-SQS-06, progress.md, architecture SVG schema
2026-04-09 07:49:11 +03:00
Naeel
6b7b60db1b
doc: sqs-operator v0.1.7-v0.1.12 — UI fixes, errors, thinking log 2026-04-08
2026-04-09 06:25:38 +03:00
Naeel
3adc0d8323
sqs-operator v0.1.12: ingress /queues/* -> elasticmq-ui (Next.js basePath fixes)
2026-04-09 06:17:21 +03:00
Naeel
516a5a209b
sqs-operator: test suite fixes -- E03/E05 WONTFIX, MT05 60s, SH06 wait_qs_phase
2026-04-08 22:26:27 +03:00
Naeel
a04d72052e
sqs-operator v0.1.11: fix ensureService UI port, FILE_LOCK=NO for H2
2026-04-08 22:17:41 +03:00
Naeel
7ea7e9b360
sqs-operator v0.1.9: fix SQS_ENDPOINT context-path, add sidecar to source
...
- ensureDeployment: sidecar elasticmq-ui добавлен в Go-код (не Python патч)
- SQS_ENDPOINT=http://localhost:9324/sqs/{tenantID} — с context-path
- ElasticMQ не отвечает на root /, только на /sqs/{tenantID}
- Sidecar условный: добавляется только при spec.enableUI=true
2026-04-08 20:08:25 +03:00
Naeel
657fc33119
sqs-operator v0.1.8: fix UI assets ingress (/_next/ path-based routing)
...
- ensureIngressUIAssets: Prefix ingress /_next/ без rewrite -> UI port 3000
- Next.js basePath="" захардкожен — static assets идут без тенантного префикса
- Решение через отдельный ingress объект (один на тенант, контент идентичен)
2026-04-08 19:40:42 +03:00
Naeel
64626659a9
sqs-operator v0.1.7: web UI sidecar, auto-create-queues, fix A06 long polling
...
- api/v1alpha1: добавлены поля EnableUI, AutoCreateQueues в QueueServiceSpec
- elasticmq_config.go: GenerateConfig принимает autoCreateQueues, добавляет HOCON блок
- controller.go: sidecar elasticmq-ui (port 3000), ensureIngressUI, ensureService UI port
- test_v2_suite.sh: A06 теперь PASS — PurgeQueue перед long polling тестом
- CRD обновлён: make install применён в кластере
Test run v0.1.7: 35 PASS / 3 FAIL / 4 WARN / 2 SKIP(WONTFIX)
2026-04-08 19:11:26 +03:00
Naeel
c4efc5c960
sqs-operator: docs + third test results (41 PASS, 0 OOM, 0 infra errors)
2026-04-07 20:44:56 +03:00
Naeel
c132c68d74
sqs-operator v0.1.6: SH02/SH03/SH04 fix + test_v2_suite + v2 test results
...
- v0.1.5: ensureHealthy checks all 4 resources (Deployment/Service/ConfigMap/Ingress)
Service/ConfigMap/Ingress now auto-recreate in 2-4s when manually deleted
- v0.1.6: revert MT03 configuration-snippet (nginx blocks risky annotations by default)
Tenant isolation deferred to Keycloak JWT in production
- test_v2_suite.sh: 8 phases, 52 tests, timing/resources/concurrent/30min marathon
- Results: 40 PASS / 4 FAIL / 7 WARN (known: OOM restart under burst load)
SH recovery: Deployment=48s Service=2s ConfigMap=4s Ingress=2s All3=2s
Marathon: 11815 iter, 10830 sent, 2 pod restarts (OOM under load)
2026-04-07 19:14:00 +03:00
Naeel
18e57cadc7
test(sqs-operator): полный тест-сьют 30мин — результаты + 2 новых бага (MT03, SH02)
2026-04-07 16:54:42 +03:00
Naeel
336ee7b869
fix(sqs-operator): persistence, OOM, Ingress routing (v0.1.2→v0.1.4)
...
Problem 1: elasticmq-native does not support H2 JDBC persistence
- GraalVM native build excludes H2 driver
- Fix: switch to softwaremill/elasticmq:1.7.1 (JVM image)
Problem 2: OOMKilled — JVM requires >150MB, spec.MemoryMB=64 too low
- Fix: enforce minimum 256Mi for JVM; add -Xmx (75% of limit)
Problem 3: AccessDeniedException on /data — PVC mounted as root:root
- JVM image runs as uid=999 (elasticmq)
- Fix: add fsGroup=999 to PodSecurityContext
Problem 4: 404 through HTTPS — nginx rewrite stripped context-path
- ElasticMQ JVM listens at context-path (/sqs/{tenantId})
- Native image tolerated /, JVM does not
- Fix: remove rewrite-target annotation, use plain Prefix path
Result: S6 PASS — 8 queues + messages survived graceful pod kill
2026-04-07 15:34:15 +03:00
Naeel
f8be5c8af1
feat(sqs-operator): v0.1.0 deployed and tested
...
- Fix Dockerfile: COPY internal/config/ and internal/elasticmq/, Go 1.22
- config/manager/manager.yaml: add SQS_EXTERNAL_HOST env, imagePullSecrets
- config/default/kustomization.yaml: disable kube-rbac-proxy (gcr.io N/A)
- config/samples/sqs_v1alpha1_queueservice.yaml: real test CR (test001)
- doc/progress.md: updated with deployment results
Smoke test: QueueService test-tenant-001 Phase=Ready in 27s
ElasticMQ pod 1/1 Running in sless-fn-test001
SQS CreateQueue via https://sqs.kube5s.ru/sqs/test001 OK
2026-04-07 14:43:41 +03:00
Naeel
52e9511d50
doc: план для Sonnet (sqs-operator deploy), обновлён progress.md
2026-04-07 14:30:34 +03:00
Naeel
66dcd99465
refactor(sqs-operator): переделка через Operator SDK v1.37.0
...
- operator-sdk init + create api (QueueService kind, group sqs, v1alpha1)
- Стандартная kubebuilder структура: cmd/, internal/controller/, config/
- CRD types с kubebuilder маркерами (validation, defaults, printcolumns)
- Reconciler перенесён из ручного кода в internal/controller/
- controller-gen v0.17.0 (совместимость с Go 1.26.1)
- Автогенерация: deepcopy, CRD YAML, RBAC ClusterRole
- Удалены все ручные файлы (controllers/, main.go, deployments/)
2026-04-07 14:25:14 +03:00
Naeel
cbe61d9f62
feat: sqs-operator — CRD QueueService, контроллер, ElasticMQ per-tenant
2026-04-07 13:56:53 +03:00
Naeel
a22a37bef3
doc: SQS Operator plan — ElasticMQ per-tenant, 10 этапов
2026-04-07 13:24:40 +03:00
Naeel
7220fe5b8b
feat: IoT Admin Stats page — /iot-admin (v0.1.70)
...
- GET /iot-admin — HTML страница администратора (go:embed)
- GET /iot-admin/stats — JSON API с данными (Bearer ADMIN_STATS_TOKEN)
- Источники: Kafka consumer lag, K8s pod statuses, PostgreSQL per-tenant stats
- Авторизация: ADMIN_STATS_TOKEN env var
- Auto-refresh каждые 30 секунд
- Nubes brand style
2026-04-06 19:14:57 +03:00
Naeel
69451007f6
test: re-test v0.1.69 — все 8 тестов PASS, 1000/1000 при нагрузке
2026-04-06 18:45:57 +03:00
Naeel
387932ce10
fix: bridge Kafka write async (v0.1.69) — MQTT callback не блокируется
2026-04-06 18:26:03 +03:00
Naeel
c0a08ae78d
test: полное суровое тестирование IoT pipeline — 7 сценариев, 4 критических находки
2026-04-06 18:14:50 +03:00
Naeel
815b861417
docs: Kafka pipeline v0.1.68 — полная документация, race condition fix, тесты
2026-04-06 17:42:44 +03:00
Naeel
07ada8e362
fix: kafka race condition — ensureKafkaTopic in consumer before group join (v0.1.68)
2026-04-06 17:31:19 +03:00
Naeel
63f834da2b
feat: Kafka pipeline v0.1.67 (mqtt-bridge→kafka→consumer→postgres)
2026-04-06 16:41:31 +03:00
Naeel
e46a8bb3e3
doc: 2026-04-06 thinking log + kafka integration plan
2026-04-06 16:03:57 +03:00
Naeel
184f5ceb91
doc: session 2026-04-05 thinking log + progress update (v0.1.66, incident)
2026-04-05 17:37:38 +03:00
Naeel
7e16dd0e0b
v0.1.66: token input visible, display name in navbar
2026-04-05 17:31:02 +03:00
Naeel
69dc023bf7
fix: make MQTTX Web visually a button-link, not plain text
...
Image: v0.1.65
2026-04-05 16:43:49 +03:00
Naeel
d2460ac988
fix: improve credentials tab readability
...
- cred-label: 11px→13px, убран uppercase, цвет #7eb8e0 (читаемый на тёмном)
- cred-value: 13px→14px, фон #0a1e30, текст #e2f0ff (светлый, контрастный)
- hint: 12px→14px, цвет #a0bcd8
- MQTTX-блок: заголовок 15px жирный #c8dff0, текст 14px #c8dff0,
code-теги со своим фоном и цветом #7dd3fc,
предупреждение ⚠️ жёлтым #fcd34d
Image: v0.1.64
2026-04-05 16:39:16 +03:00
Naeel
20846297af
fix: EnsureNamespace in doCreate + sanitize API errors in UI
...
- doCreate() calls EnsureNamespace before creating device (idempotent)
Fixes namespace-not-found when session was cached before v0.1.62
- Added sanitizeApiError() — hides internal details (namespace names,
k8s paths) from user, shows friendly Russian messages instead
- Patterns handled: namespace not found, already exists, HTTP 5xx
Image: v0.1.63
2026-04-05 11:11:50 +03:00
Naeel
11bc86d2c9
fix: call EnsureNamespace on login to auto-create k8s namespace
...
doLogin() now calls POST /v1/namespaces/{ns}/ensure before apiListDevices().
Prevents namespace not found error when user logs in for the first time
with a new token (test mode or real JWT).
Image: v0.1.62
2026-04-05 11:06:27 +03:00
Naeel
354fded5b9
fix: remove copyAll button, add MQTTX Web link in creds tab
...
- Removed 📋 Скопировать всё button and Подключение физического устройства block
- Added MQTTX Web link (https://mqttx.app/web-client ) with brief instructions:
Host, Port 443, Protocol wss, Path /mqtt — copy username/password above
- Warning: check port is 443 not 8084/1883 if connection fails
- Updated help step 1: removed mention of copyAll, added port 443 note
- Removed unused copyAll() function
Image: v0.1.61
2026-04-05 10:52:38 +03:00
Naeel
3bf1dd604c
feat: test auth mode — accept any plain token without JWT validation
...
authTestMode=true in middleware/auth.go:
- any non-whitespace, non-JWT string is accepted as Bearer token
- string is used as sub for namespace derivation (SHA256)
- JWT validation still runs for actual JWT strings (xxx.yyy.zzz)
- revert to strict mode: authTestMode = false
iot-console.html:
- namespaceFromToken: plain tokens use the string itself as sub
- login form: updated placeholder + hint explaining test mode
Image: v0.1.60
2026-04-05 10:46:29 +03:00
Naeel
763dca8653
fix(ux): credentials tab — copy button for password, port 443 in broker URL
2026-04-05 10:35:51 +03:00
Naeel
36789d6da2
doc: MQTTX Web подключение работает через wss://iot.kube5s.ru/mqtt
2026-04-05 10:14:18 +03:00
Naeel
661218bb73
doc: session 2026-04-05 — autoTimer fix deploy, progress и thinking log
2026-04-05 09:53:11 +03:00
Naeel
5e3c82d12a
fix: autoTimer runs as background process, not killed on tab switch
2026-04-05 09:50:48 +03:00
Naeel
911f2bdafe
fix: auto-send continues when switching to Telemetry tab, uses random payload
2026-04-05 09:17:54 +03:00
Naeel
233e28579d
fix: MQTT ACL — allow bridge subscribe +/telemetry/+, fix device topic {ns}/telemetry/{deviceId}
2026-04-05 09:06:31 +03:00
Naeel
b902e136ed
fix: QueryTelemetry returns empty array when tenant DB not yet created
2026-04-05 08:55:54 +03:00
Naeel
2bdd753f4e
v0.1.59: IoT telemetry pipeline — Postgres storage + REST API + UI table
2026-04-05 08:46:17 +03:00
Naeel
d51e33d876
doc: detailed telemetry pipeline plan for Sonnet (Postgres + REST API + UI)
2026-04-05 08:27:53 +03:00
Naeel
d078d3156f
doc(thinking): лог сессии 2026-04-04 — TLS, UX, Nubes rebrand
...
- Разбор проблемы crypto.subtle (HTTP → HTTPS)
- Проблема 404 после apply (Docker layer cache)
- Убраны поля API/MQTT из формы входа
- Ребрендинг Nubes: палитра #001C34, логотип SVG, favicon
- Таблица версий v0.1.54–v0.1.58 с коммитами
2026-04-04 20:39:51 +03:00
Naeel
93e87a3b30
fix(iot-console): favicon Nubes, v0.1.58
2026-04-04 20:37:44 +03:00
Naeel
0400f97eb6
design(iot-console): Nubes brand rebrand v0.1.57
...
- Палитра: #001C34 (Nubes navy) как фоновая карточек/navbar
- Логотип Nubes SVG в navbar и на экране входа (filter:invert → белый)
- Убраны эмодзи из brand-элементов
- Accent: #1a7fd4 (корпоративный синий на тёмном фоне)
- Badges: прямоугольные, UPPERCASE, строгие
- Кнопки/формы/таблицы: Nubes-спецификация
2026-04-04 20:34:23 +03:00
Naeel
e54787177b
fix(iot-console): убрать поля API/MQTT из формы входа, добавить Help блок
...
- Форма входа: только токен, без полей API адреса и MQTT broker
- Адреса zardcoded: https://sless.kube5s.ru и wss://iot.kube5s.ru/mqtt
- Страница устройства: блок «Как это работает» — 5 шагов с инструкцией
- operator.yaml: v0.1.55 → v0.1.56
2026-04-04 20:25:06 +03:00
Naeel
fb6f9d48cd
feat(tls): HTTPS + wss:// для iot.kube5s.ru
...
- emqx-ws-ingress.yaml: TLS секция + cert-manager letsencrypt-prod, ssl-redirect=true
- router.go: CORS Allow-Origin: http → https://iot.kube5s.ru
- iot-console.html: дефолт MQTT брокера ws:// → wss://
- operator.yaml: v0.1.53 → v0.1.54
- crypto.subtle теперь работает (HTTPS страница)
2026-04-04 19:56:31 +03:00
Naeel
017312f35c
fix(iot-console): убрать namespace из UI полностью
...
- Поле Namespace удалено из формы входа
- namespace вычисляется из токена: SHA256(sub) → sless-{hex}
- navbar: убран badge с ns
- Телеметрия: убрана техническая подсказка про namespace
- Пользователь не видит и не вводит namespace нигде
2026-04-04 19:38:32 +03:00
Naeel
b48c300ac5
feat(iot-console): IoT управляющий UI v0.1.53
...
- Добавлен HTML SPA: internal/api/ui/iot-console.html
Ванильный JS + mqtt.js (CDN), без фреймворков.
Страницы: вход, список устройств, credentials, эмулятор MQTT, заглушка телеметрии.
- Добавлен go:embed: internal/api/console_embed.go, GET /console
- Добавлен CORS middleware в router.go для http://iot.kube5s.ru
- Ingress emqx-ws-ingress.yaml: /console → sless-operator:9090
- Версия образа v0.1.53, задеплоен
Доступно: http://iot.kube5s.ru/console
2026-04-04 19:28:30 +03:00
Naeel
d57558c798
docs: IoT telemetry storage architecture decisions and thinking log
2026-04-04 18:41:29 +03:00
Naeel
b23ae40975
security(iot): MQTT ACL isolation via EMQX HTTP authorization
...
Each IoT device can only pub/sub to its own topics: {namespace}/{deviceId}/#
Any attempt to access foreign topics → EMQX denies and disconnects.
Changes:
- internal/api/handler: add MQTTAcl handler (POST /internal/mqtt/acl)
- internal/api/router: register /internal/mqtt/acl route
- deployments/k8s/emqx.yaml: add HTTP authorization backend, no_match=deny
- Operator v0.1.52 deployed
Tested: own topic ALLOWED, foreign topic → authorization_permission_denied + disconnect
2026-04-04 17:51:51 +03:00
Naeel
6e3e473551
feat(iot): MQTT over WebSocket workaround via nginx-ingress
...
Port 1883 blocked by NSX-T Edge firewall (DevOps to open on Monday).
Temporary solution: EMQX WebSocket listener (8083) via nginx-ingress.
- Service emqx-ws: selector app=emqx, port 8083
- Ingress emqx-mqtt-websocket: iot.kube5s.ru/mqtt → emqx-ws:8083
- pathType: Exact (prevents trailing slash redirect breaking WS handshake)
- ssl-redirect: false (IoT devices cannot follow HTTP 301 redirects)
- DNS A record iot.kube5s.ru → 185.247.187.147 created by user
Tested: Connected rc=0 via paho-mqtt WebSocket from inside cluster.
2026-04-04 14:06:17 +03:00
Naeel
857d057af9
feat(iot): деплой IoT MVP — Dockerfile, RBAC, EMQX fix, operator v0.1.50, mqtt-bridge, doc/iot
2026-04-04 10:29:47 +03:00
Naeel
b920dc5c9d
feat(iot): Этап 6 — Terraform ресурс sless_iot_device (провайдер v0.1.2)
2026-04-04 09:56:18 +03:00
Naeel
1e53766c46
feat(iot): Этапы 2-7 — MQTT auth, IoT API, EMQX, mqtt-bridge, E2E demo
...
Этап 2+4: internal/api/handler/iot_device_handler.go
- MQTTAuth: POST /internal/mqtt/auth (без JWT, для EMQX)
- CreateIoTDevice, ListIoTDevices, GetIoTDevice (c password), DeleteIoTDevice, UpdateIoTDevice
- crypto/subtle.ConstantTimeCompare против timing attacks
Этап 4: internal/api/router.go
- /v1/namespaces/{ns}/iot/devices CRUD
- /internal/mqtt/auth (без JWT middleware)
Этап 3: deployments/k8s/emqx.yaml
- EMQX 5.5.1, emqx.conf (HOCON) с HTTP auth backend
- Сервис exposure: 1883 (MQTT), 8083 (WS), 18083 (Dashboard)
Этап 3: iot/cmd/mqtt-bridge/main.go
- paho.mqtt.golang: подписка на +/telemetry/+
- amqp091-go: publish в iot.{namespace}.telemetry
- deployments/k8s/iot-mqtt-bridge.yaml
Этап 7: examples/IOT/ — E2E demo (main.tf, handler.py, README.md)
go.mod: добавлен github.com/eclipse/paho.mqtt.golang v1.5.1
go build ./... — ошибок нет
2026-04-04 09:45:23 +03:00
Naeel
716efafda8
feat(iot): Этап 1 — CRD IoTDevice + контроллер credentials
...
- iot/api/v1alpha1/device_types.go — CRD IoTDevice
- iot/api/v1alpha1/groupversion_info.go — API group iot.kube5s.ru/v1alpha1
- iot/api/v1alpha1/zz_generated.deepcopy.go — deepcopy (controller-gen)
- iot/config/crd/bases/iot.kube5s.ru_iotdevices.yaml — CRD манифест
- iot/controllers/iotdevice_controller.go — Reconcile: Secret с MQTT credentials
- main.go — регистрация IoT схемы и IoTDeviceReconciler
go build ./... — ошибок нет
2026-04-04 09:32:47 +03:00
Naeel
211563a87c
merge: examples/dev-from-ground → main
2026-03-30 09:28:39 +03:00
Naeel
4764e983f7
doc: обновлён log ошибок
2026-03-30 09:27:45 +03:00
Naeel
f869b7986e
feat: vdc_uid/nsxt_uid вынесены в tfvars; terraform.tfvars.template; README обновлён
2026-03-30 09:03:16 +03:00
Naeel
89d698fa47
fix: idempotency check 0 changed only, docker wait 360s nginx 240s
2026-03-30 08:48:49 +03:00
Naeel
e737f2687d
fix(vm_stress_test): fix idempotent check, sleep->poll, add HTTP/docker/disk tests
2026-03-30 08:00:17 +03:00
Naeel
56e6446310
fix(vm_stress_test): make read-only workflow, add instructions and docs
2026-03-30 07:16:35 +03:00
Naeel
fef441681e
examples/VM: sless_job provisioning (packages, nginx, docker)
...
- Add sless.tf: three sless_job resources with depends_on chain
- vm-install-packages: jq, python3-pip, htop, unzip
- vm-install-nginx: nginx 1.18 (HTTP 200 verified)
- vm-install-docker: Docker CE 29.3.1 + Compose v5.1.1
- Add functions/install-{packages,nginx,docker}/handler.py
- _wait_apt_lock: cloud-init status --wait + systemctl mask
fixes Ubuntu 22.04 first-boot apt lock (unattended-upgrades)
- DPkg::Lock::Timeout=600 on all apt-get calls
- Add variables.tf (install_run_id, vm_public_key, vm_private_key)
- Add outputs.tf (install_*_result)
- Bump nubes provider 5.0.49 -> 5.0.51
- doc/progress.md: document step 6 with bug analysis
2026-03-29 19:54:00 +03:00
Naeel
b4c2e7f6b1
doc: add handoff summary and postgres function-job plan
2026-03-29 08:31:16 +03:00
Naeel
f8f95d7147
examples/VM: bump nubes provider 5.0.49, rename resources vm-sless
2026-03-28 20:27:16 +03:00
Naeel
547994dc55
examples: DEVfromGround vc_org, NODEJS, VM, POSTGRES updates
2026-03-26 08:33:03 +03:00
Naeel
2b03ba520e
examples/DEVfromGround: add Terraform manifests (nubes_vc_org, DEV endpoint)
2026-03-26 06:43:53 +03:00
Naeel
bc0e00acca
feat(vm): add vApp + VM terraform example
2026-03-25 08:17:08 +03:00
Naeel
3404af578b
feat(builder): py_compile + node --check при сборке ловят синтаксические ошибки (v0.1.63)
2026-03-23 11:23:01 +03:00
Naeel
8051870208
fix(web-console): убраны память/таймаут, двойной рендер кода (v0.1.11)
2026-03-23 11:14:32 +03:00
Naeel
cad89fdbb6
fix(web-console): NotFoundError — urlRow создаётся сразу, не через insertBefore (v0.1.10)
2026-03-23 11:05:30 +03:00
Naeel
6e73729c46
feat(web-console): URL строкой ниже, статус сборки после Save (v0.1.9)
2026-03-23 11:01:01 +03:00
Naeel
470039f6d6
fix(web-console): таймер исчезает после Building→Ready, шаблоны без context (v0.1.8)
2026-03-23 10:52:37 +03:00
Naeel
f68b601484
fix(web-console): zip invalid — Close() после Bytes() (v0.1.6)
2026-03-23 10:47:25 +03:00
Naeel
442ba8bc2f
feat(web-console): deps, rename, Building poll+timer, kind=service — v0.1.5
2026-03-23 10:41:43 +03:00
Naeel
b7fa8acf76
feat(web-console): create/edit/delete functions in UI, v0.1.4
...
- services/funcs: новые маршруты POST create-function, POST save-function,
DELETE delete-function — создание/редактирование/удаление через браузер
- index.html: модалка создания с шаблонами Python/Node.js hello world,
кнопки edit/delete на каждой карточке функции
- sless-funcs-service:v0.1.4 задеплоен
- examples/POSTGRES: удалены логи, .bak, backup tfstate, лишние функции
оставлены 2 Python (pg-stats, pg-counter) + 2 Node.js (pg-info, js-idempotent)
2026-03-23 10:19:42 +03:00
Naeel
7a168185ea
fix: cache lag retry, go.work, провайдер rollback, test v4 no -target
2026-03-23 10:03:26 +03:00
Naeel
2e7cd7f4f7
feat(v0.1.60): sha256-based s3Key for content-addressed cache hit
2026-03-23 06:57:18 +03:00
Naeel
c033adec11
feat(v0.1.59): in-cluster registry:2 — insecure HTTP mode, ImageExists error handling
2026-03-23 06:41:30 +03:00
Naeel
9edd43edc5
feat(v0.1.58): ImageExists cache hit, timing analysis, in-cluster registry plan
2026-03-23 06:22:25 +03:00
Naeel
7023e0e6fc
feat(builder): add REGISTRY_PROJECT for easy registry migration
...
DockerHub (flat): REGISTRY_HOST=naeel, REGISTRY_PROJECT=<empty>
-> naeel/{nsPrefix}-{func}:{tag}
Harbor/GCR (project): REGISTRY_HOST=host, REGISTRY_PROJECT=proj
-> host/proj/{func}:{tag}
Switch registry by changing 2 env vars only.
2026-03-22 17:51:05 +03:00
Naeel
c762047234
fix(builder/go1.23): add require sless/fn/handler to server/go.mod at build time
...
go.work replace rule requires explicit require directive in server/go.mod.
Patch appended at kaniko build time - no base image rebuild needed.
2026-03-22 17:28:40 +03:00
Naeel
9b5dec4dde
fix: multiuser test — memory_mb + zip invalid + early return
2026-03-22 15:00:55 +03:00
Naeel
dca98aac97
test: G_MULTIUSER — 10 parallel users + Postgres (ready to run)
2026-03-22 14:36:52 +03:00
Naeel
d25fc608dd
test: G17/G18/G19/G20/G22 - 154/154 PASS
2026-03-22 14:09:15 +03:00
Naeel
40474324bd
feat: v0.1.51 + G13/G14/G15 tests (126/126 PASS)
...
- fix: UpdateService IsInvalid → 400 (was 500 for ruby3.0 runtime)
- test: G13 edge cases — 40 tests, 40 PASS (name validation, boundary values,
lifecycle, state transitions, update validation, upload edge cases)
- test: G14 cluster chaos — 20 tests, 20 PASS (self-healing, pod kill,
OOM kill, kaniko interrupt, operator restart)
- test: G15 combined chaos — 21 tests, 21 PASS (CRUD under chaos, upload
during self-heal, concurrent creates, errors after restart, rapid lifecycle)
- doc: progress.md, errors/log.md, decisions/log.md — полная документация сессии
2026-03-22 11:15:46 +03:00
Naeel
a76baa62a3
fix: v0.1.50 — runtime 400 + SLESS_ENTRYPOINT в Deployment
...
Bug 1: services.go — k8s IsInvalid error (CRD enum validation) маппился в 500.
Теперь errors.IsInvalid() → 400 Bad Request (invalid service spec).
Bug 2: service_controller.go buildServiceDeployment не передавал env SLESS_ENTRYPOINT
в под. Добавлен в envVars из svc.Spec.Entrypoint. Без него server.py использовал
fallback handler.handle и не замечал неверный entrypoint.
operator_failure_test.sh 12B-2: обновлён под новое правильное поведение —
create ruby3.0 → 400 (не 201). Старый 201-путь сохранён как warn для совместимости.
2026-03-22 08:11:05 +03:00
Naeel
d4ccbc7d15
test: operator_failure_test.sh — group 12 failure modes (43/45)
2026-03-22 07:49:58 +03:00
Naeel
19fbfb5502
fix: survival test — время в GMT+4 (TZ=Asia/Dubai)
2026-03-22 07:11:05 +03:00
Naeel
f6aaf15245
test: survival+pg — group 11 PG STORM + параметризация TOKEN/NS/PG
...
- TOKEN/NS параметризованы через env SLESS_TOKEN / SLESS_NS
- PG_HOST/PORT/USER/PASSWORD/DATABASE/TABLE добавлены в CONFIG
- make_python_pg_zip: Python handler с psycopg2 (init/insert/count)
- create_pg_deploy, pg_invoke_burst, pg_count_fn, pg_init_fn
- Group 11 PG STORM: 11 тестов, 300+ параллельных INSERT/COUNT
- Итоговый banner обновлён (G11 + PG STORM label)
2026-03-22 06:55:31 +03:00
Naeel
e6be6026fe
fix: survival test — false alarm at 5.2, empty CLEANUP entries, teardown guard
2026-03-21 19:22:50 +03:00
Naeel
a25725fdb7
test: operator_survival_test.sh — survival suite (группы 5-10)
...
5 FLOOD BUILD: 6 функций (3×Python + 3×Node.js) параллельно → все Ready
6 RAPID DISCARD STORM: 30 create→DELETE без build, orphan-check
7 CHURN UNDER FIRE: 10 PUT env-updates под 200 параллельными invokes, rate≥90%
8 PHOENIX: 3 цикла DELETE+recreate одного имени
9 SELF-HEALING MARATHON: 5×kubectl delete deployment → auto-recreate (RequeueAfter)
10 INVOKE HURRICANE: 500 параллельных invokes в 5 волнах (100 × 5), rate≥90%
Ожидаемое время прогона: 75-100 минут
2026-03-21 19:16:30 +03:00
Naeel
f65677a4d0
fix: operator v0.1.49 — Resources update + self-healing requeue
...
БАГ 1: ensureServiceDeployment UPDATE блок теперь обновляет Containers[0].Resources
→ memory_mb через PUT применяется к k8s Deployment
БАГ 2: ensureServiceDeployment возвращает RequeueAfter: 60s вместо Result{}
→ ручное удаление Deployment пересоздаётся контроллером в течение 60s
lifecycle-тест: 47/47 PASS (ранее 44/44 с 2 known bugs)
2026-03-21 18:51:02 +03:00
Naeel
9b74358979
docs: lifecycle test — 44/44 PASS; 2 бага оператора задокументированы в errors/log.md + progress.md
...
Баги:
1. memory_mb через PUT не обновляет k8s Deployment Resources → controllers/service_controller.go:~241
2. нет self-healing при ручном удалении Deployment → нет RequeueAfter / cross-namespace watch
2026-03-21 18:32:14 +03:00
Naeel
67e1bd4786
test(operator): lifecycle test — 44/44 PASS; 2 бага оператора задокументированы
...
Группы тестов:
1. Валидация API (8 тестов) — memory_mb, timeout_sec, missing fields, 404
2. Полный цикл одной функции (18 тестов):
- create → build → ready → invoke → env update → memory update → timeout → delete
- delete → k8s Deployment/Service удалены
3. Граничные сценарии:
- DELETE while Building → kaniko убит, Deployment не создан
- Reconcile: kubectl delete Deployment → [БАГ: не пересоздаётся]
4. Параллельные функции (10 тестов):
- 3 функции одновременно → delete одной в Building → 2 доходят до Ready
- 40 параллельных invoke → 40/40 OK
Найденные баги оператора:
БАГ 1: ensureServiceDeployment не обновляет Resources (memory_mb через PUT игнорируется)
БАГ 2: нет self-healing — если Deployment удалён вручную, контроллер не пересоздаёт
(нет cross-namespace watch, RequeueAfter не задан)
2026-03-21 17:58:14 +03:00
Naeel
b86ff3a62e
feat(service): timeout_sec без дефолта; 0=нет таймаута; operator v0.1.48
...
- api/v1alpha1/service_types.go: убрать +kubebuilder:default=30
- invoke.go: TimeoutSec=0 → &http.Client{} (без таймаута)
- services.go: валидация timeout_sec < 0 || > 900 → HTTP 400
- service_resource.go: TF schema Optional (без Computed); 0 → Int64Null()
- deployments/k8s/operator.yaml: v0.1.47 → v0.1.48
- doc/: progress.md + api/design.md (модель Service) + decisions/log.md
- examples/POSTGRES/: bug_hunter.sh, chaos_marathon.sh, chaos_marathon.tf
2026-03-21 16:58:43 +03:00
Naeel
7f7aa44e59
chore: удаление устаревших examples, новый doc, правки funcs-service
...
- examples/: удалены старые директории (TNAR, demo-event-log, demo-managed-functions,
hello-go, hello-node, notes-python, pg-list-python, simple-node, simple-python)
- examples/README.md: обновлён (только POSTGRES остался)
- doc/decisions/build-deploy-pipeline.md: новый документ по пайплайну сборки/деплоя
- services/funcs/main.go: правки из текущей сессии
2026-03-21 08:46:30 +03:00
Naeel
778cbc8b32
fix(runtime): Go panic→500 (recover), Python exception→500+threading+backlog
...
- go1.23 v0.1.2: defer recover() в HTTP handler — panic no longer closes connection → HTTP 500
- python3.11 v0.1.5: try/except в do_GET/_handle_with_body/do_HEAD → 500 вместо EOF
- python3.11 v0.1.5: ThreadingHTTPServer — concurrent requests (был single-thread)
- python3.11 v0.1.6: _HighBacklogHTTPServer(request_queue_size=128) — listen(128) вместо listen(5)
- context.go: go1.23 v0.1.1→v0.1.2, python3.11 v0.1.4→v0.1.6
- operator: v0.1.45 → v0.1.47 (два деплоя подряд с новыми runtime-версиями)
- examples/POSTGRES: stress.tf (10 сервисов), full_test.sh (48 тестов, 4 фазы)
- examples/POSTGRES: README.md, очистка от старых файлов (luceUNDnode.tf, funcs_list.py)
Результат: full_test.sh 48/48 PASS
- Фаза 3 PG-стресс: 40/40 parallel writer OK, 30/30 js-async OK, pgstorm 14k ops 0 err
- Фаза 4 краш-шторм: 75/75 × HTTP 500 (паники не роняют платформу)
2026-03-21 08:42:03 +03:00
Naeel
0592f57fb6
docs: log examples cleanup session 2026-03-21
2026-03-21 07:50:09 +03:00
Naeel
37a50c23c0
docs: document session 2 — API testing, DELETE 404 fix, funcs-console, source for services
2026-03-21 07:31:23 +03:00