Tasks: YU03-in-memory-risk-gateway
Deliveredβ
- T-01 Port
RiskReason/RiskMetrics/RiskRejectedException/RiskRejectionBody. - T-02 Adapt
BlpRiskStateto the YU02 base (reservations viaReservationHolder, snapshot tuples). - T-03 Adapt
GatewayReplicaStore(seeded + control-fed, SymbolTable id alignment, fail-closed). - T-04
InputEventtype-discriminated payload slots (keys/control); control ids 7β10. - T-05
OutputEventreject + trade-decision kinds;RestingOrderreservation fields + riskReason. - T-06
MatchingEngine: decide+reserve before book, consume on fill, release on cancel, market-trade decision, control-event handlers. - T-07
SnapshotStorev3 (risk sections + per-order reservation) +LmaxEnginecapture/restore. - T-08
LmaxEnginewiring: risk-state construction, ingress keys, control submission, trade ack, recovery-boundary policy re-alignment. - T-09
OrderMatcherServicescreening + rejection surface + risk metrics + price feed. - T-10
RiskControlController+RiskExceptionHandler+ config (risk.*). - T-11
ReplicaBootstrapjournaled startup fetch of the account/security universe (ADR-019). - T-12 Tests:
BlpRiskStateTest,GatewayReplicaStoreTest,RiskReplayDeterminismTest. - T-13 Spec pack (spec, requirements, ADRs 018/019/020, architecture, runtime-topology, data-model, contract-delta, plan, research, no-gc, this file); pipeline hooks; catalog.
- T-14 State registration under the
YUxx-lineage (parentYU02-lmax-kubernetes). - T-15 Runtime harness: YU03 start/stop/status/test scripts + generation-hook registration.
- T-16 Grafana dashboard for the risk metric set (
traderx-risk-gateway.json): decisions/ rejections by reason, control-update rejections, gateway/BLP decision latency p99, replica rebootstrap events. - T-17 Allocation gate:
AllocationGateTest.hotPathIsAllocationFreeInSteadyStateWithRiskGating()wires the realBlpRiskStateinto the BLP so every ORDER_NEW runsdecideAndReserve;noGcTest(Epsilon-GC) passes with risk gating on (NFR-IMRG02). - T-18 p99 latency CI gate over the risk path (NFR-IMRG01): 5Β΅s threshold (~5β8Γ the observed
600β950ns p99 on dev hardware), asserted in
AllocationGateTest(BLPdecideAndReserve) andGatewayReplicaStoreTest.screenLatencyP99StaysUnderGateway5usBudget()(edgescreen()). - T-19 UI: surface rejection reasons +
clientOrderId(FR-IMRG44).OrderResponsegained ariskReasonfield (REST create-order response and NATS live-blotter bridge); the order ticket has an optional Client Order ID field; the create-order alert shows the actual rejection reason for both the BLP-level (200 OK, status=REJECTED) and edge-level (422/503,RiskRejectionBody.reason) paths.
Still openβ
- Entitlement feeding into the admission-time replica/BLP check (FR-IMRG02 entitlement replica,
FR-IMRG30 full authn). The
principalKeyslot is already wired on the admission path; this threads a resolved principal's entitlements into it, using the real JWT auth built inYU05-post-trade-compliance. - Alert rules for the risk metric set (NFR-IMRG08). The dashboard is provisioned; alert thresholds (e.g. what rejection rate or replica-rebootstrap rate pages someone) are a paging-policy decision, not defined yet.
- Multi-Gateway deployment + concurrency-overshoot test (FR-IMRG25): deploy the Gateway as a separate tier and confirm the BLP's single-writer authority prevents overshoot under concurrent gateways.
- Full multi-scenario container smoke. Staging live-verification covers the
PRICE_COLLARrejection scenario (seegeneration/implementation-status.md); order/cancel/fill, projector convergence, NATS/WS delivery, durable control propagation, and kill-switch/restriction enforcement are not yet exercised end to end in one pass. - k8s manifest env plumbing for
RISK_*knobs (defaults are live-safe today).