Tasks: YU09-ops-hardening
Build order follows the recommended v1 order: secrets → journal archival → pipeline fix → DR runbook.
Secrets
- T01
mariadb-credentialsSecret shape (username/password/root-password);secretKeyRefindatabase-deployment.yaml. - T02
secretKeyRefforDATABASE_DBUSER/DATABASE_DBPASSinorder-matcher,trade-processor,account-service,position-serviceDeployments. - T03
auth-secretsSecret shape (jwt-secret/dev-token-master-secret);secretKeyRefforAUTH_JWT_SECRET(order-matcher, trade-processor) andAUTH_DEV_TOKEN_MASTER_SECRET(trade-processor). - T04 Same
secretKeyRefwiring on the productioncluster-addons/order-matcher-statefulset.yaml. - T05 MariaDB readiness/liveness probes read
$MARIADB_USER/$MARIADB_PASSWORDfrom the container's own env instead of a hardcoded-utraderx -ptraderx.
Journal rotation + archival
- T10
Journaler.rotate(): close + rename the active file to a timestamped closed segment, reopen fresh, resetwrittenBytes/lastSnapshotOffsetto 0; called fromonEventright after a SNAPSHOT marker is journaled and forced. - T11
JournalArchiver: HMAC-authenticated S3 client against GCS's XML API, fire-and-forget upload on its own background thread, local file kept on any failure. - T12 Wire
journal.archive.*properties +@Valueparams throughLmaxEngineinto the newJournaler/JournalArchiverconstructor overload; legacy constructors preserved (archiver=null) so existing callers/tests are unaffected. - T13
journal.archive.enableddefaultsfalseinapplication.properties; manifests turn it on explicitly.
Pipeline fix
- T20
publish-generated-state-branch.sh's build loop: run./gradlew --no-daemon clean bootJarin any context with abuild.gradle, beforedocker build.
DR runbook
- T30
system/dr-runbook.md: blast radius + recovery procedure for BLP pod loss, node loss, zone loss, MariaDB data loss, grounded in the cluster's actual single-zone topology.
Verification
- T40 Generation hook + render wiring;
pipeline/generate-state.sh YU09-ops-hardeningexits 0. - T41
scripts/test-state-YU09-ops-hardening.sh: grep-verifies no literal credential remains in any touched manifest, and that the build loop'sgradlew bootJarstep is present. - T42
run-state-kindE2E bring-up with both required Secrets pre-created; smoke order accepted. - T43
bench-compareagainst the YU08 baseline withjournal.archive.enabled=false.