Feature Pack: YU09-ops-hardening
- No PowerShell parity: the only shell script this pack names is
pipeline/publish-generated-state-branch.sh, and it is named in prose describing what the BUILD PIPELINE does; not as a command a reader runs. There are nopipeline/*.ps1at all; the repo's PowerShell scripts are lifecycle scripts (scripts/*-generated.ps1) for the numbered states, and this pack adds no lifecycle script of its own. The windows badge above already says this in an image; this bullet is the machine-readable form of the same claim.
Status: Implemented
Track: architecture
Lineage role: optional
Previous state: YU08-execution-algo-engine
This pack closes four operational gaps found while hardening every prior state (YU03βYU08) for
E2E health and throughput on top of the YU08-execution-algo-engine baseline: plaintext
credentials in committed manifests, unbounded journal growth on the order-matcher PVC, a Docker
build step that could silently deploy a stale jar, and no documented recovery procedure for the
cluster's actual (single-zone) failure modes.
Primary intent:
- move every database and JWT/dev-token credential out of committed manifests and into Kubernetes Secrets, created out-of-band and never committed; the same pattern YU07 already established for its GCS HMAC credential,
- rotate the order-matcher journal at each snapshot boundary and archive closed segments to GCS, off the journaler thread, gated behind a flag that defaults to the original unbounded-file behavior,
- make the shared build pipeline always rebuild a JVM service's jar before building its Docker image, closing the stale-jar Docker-layer-cache bug found deploying YU08,
- document the cluster's real failure modes (node, zone, database, journal loss) and their recovery procedures given its current single-zone topology.
Core artifacts:
spec.mdrequirements/functional-delta.mdrequirements/nonfunctional-delta.mdresearch.mddata-model.mdquickstart.mdcontracts/contract-delta.mdsystem/architecture.model.jsonsystem/architecture.mdsystem/runtime-topology.mdsystem/messaging-subject-map.mdsystem/dr-runbook.mdsystem/adr-032-journal-rotation-and-gcs-archival.mdsystem/adr-033-secrets-via-out-of-band-kubectl-secrets.mdgeneration/generation-hook.mdgeneration/implementation-status.md
Target runtime behavior:
database,order-matcher,trade-processor,account-service, andposition-servicepods read their database credentials from themariadb-credentialsSecret;order-matcherandtrade-processorread JWT/dev-token secrets fromauth-secrets. Neither Secret is committed.order-matcher, whenjournal.archive.enabled=true, rotates its journal file at every snapshot and uploads the closed segment to GCS via the optionalorder-matcher-journal-gcs-hmacSecret; by default this is off and the journal behaves exactly as in every prior state.pipeline/publish-generated-state-branch.shrebuilds a fresh jar before every JVM service's Docker build.- Everything else (deploy/runtime harness, observability stack, every existing service) is
inherited unchanged from
YU08-execution-algo-engine.