Repository navigation
Record exclusive-allocation deploys in run-key history - #536
Merged
TheGreatAxios merged 2 commits intoAug 31, 2026
Merged
TheGreatAxios merged 2 commits into
TheGreatAxios merged 2 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Exclusive-allocation deploys rotate
workflow_run.public_keythroughupdateAnchorPublicKeyUnderAllocationLock, then emitagent.deploy.ackwithallocatedset.@corbits/run-key-historyskipped those acks, matching the orchestrator listener's guard — but that guard is not how the service path writes the key. Result: zero history rows for that entire deployment class, so signature re-verification failed for it.This drops the
allocatedskip in our listener so every observed deploy ack is recorded, including exclusive-allocation deploys and post-failure allocation replacements. No dual path, no vendor edits.Shared-capacity writes (
deployCodeSourcedWorkflow,deployAdoptedCodeSourcedWorkflow) already emit ordinary acks and were already recorded.Test plan
test.failingto a passing test; inverted the skip-contract testHUB_DATA_DIR=$(mktemp -d) bun test packages/run-key-history— 26 pass, 0 failbunx tsc --noEmit -p packages/run-key-history/tsconfig.jsonprettier --check/eslinton the changed filescheck:report-erroris already red onmainand unrelatedCloses the live gap tracked in CL-7274.