Runtime Topology: YU09-ops-hardening
Parent state: YU08-execution-algo-engine
Entrypointsβ
No new HTTP or NATS entrypoint. This state changes configuration surface (Secrets, env vars) and
one internal file-format detail (journal segmentation) on existing components; every existing
entrypoint from 009 through YU08 is unchanged.
Componentsβ
- Inherits every Kubernetes/C3/FDC3/EOD/tick-store/algo-engine runtime component already present
in
YU08-execution-algo-engineunchanged. No new Deployment, Service, or PVC. database,order-matcher,trade-processor,account-service,position-servicenow read their database credential from themariadb-credentialsSecret instead of a literal manifest value.order-matcherandtrade-processornow read their JWT/dev-token credential from theauth-secretsSecret.order-matcher'sJournaler, whenjournal.archive.enabled=true, rotates its journal file at each snapshot boundary and hands the closed segment to a newJournalArchiver, which uploads it to GCS (gs://traderx-501015-order-matcher-journal-archive) on its own background thread, authenticated via the optionalorder-matcher-journal-gcs-hmacSecret.
Networkingβ
- No new network path.
JournalArchiver's GCS upload is the one new egress call fromorder-matcher(tostorage.googleapis.com, HTTPS, S3-compatible XML API); off the hot path, from a dedicated background thread, only when archival is enabled and configured.
Startup / Health Orderβ
mariadb-credentialsandauth-secretsSecrets must exist beforedatabase,order-matcher,trade-processor,account-service, orposition-servicecan reach Ready; neither isoptional, so a missing Secret is a visibleCreateContainerConfigError, not a silent fallback to a hardcoded value (seesystem/adr-033-secrets-via-out-of-band-kubectl-secrets.md).- Everything else follows the
YU08-execution-algo-enginestartup order unchanged. - If
journal.archive.enabled=true,order-matcherstarts normally regardless of whetherorder-matcher-journal-gcs-hmacexists; the Secret isoptional, and its absence only disables the GCS upload leg (rotation, which bounds local disk, still happens).
Degraded Behaviorβ
| Condition | Effect |
|---|---|
mariadb-credentials or auth-secrets Secret missing | Affected pods stay in CreateContainerConfigError, never reach Ready; visible in kubectl get pods/describe pod, not a silent dev-default fallback. |
order-matcher-journal-gcs-hmac Secret missing, archival enabled | Rotation still happens at every snapshot (local disk stays bounded); each closed segment logs a warning and stays on the PVC instead of uploading. |
GCS unreachable or a putObject call fails, archival enabled and configured | The failing segment is logged and left on local disk (never deleted without a confirmed upload); the next snapshot's rotation is unaffected; it produces its own new segment independently. |
| Journal rotation itself fails (e.g. a filesystem error renaming the active file) | Logged and swallowed; journaling continues on the current (unrotated) file; the same availability-over-durability posture Journaler already takes on an append failure. |