Re-cut v0.1.5: the temporal-adapter, the CDC producer, and an SNI lockout - #68
Merged
Merged
Conversation
…ut into v0.1.5
Re-points v0.1.5 at three fixes found after the tag was cut. Nobody had
installed the published 0.1.5 yet, so this moves the tag rather than
spending a 0.1.6 on it.
* The k8s temporal-adapter waits for Kafka. createKafkaProducer failing
is log.Fatalf with no retry, exactly like the orchestrator's
kafka.NewManager, but only the orchestrator was wired to wait. A fresh
kind install of chart 0.1.5 brought the adapter up after 4 restarts,
every one "Failed to create Kafka producer ... connection refused".
The guard that was supposed to catch this greps for the behaviour now
(a family of Kafka constructors, checked in both directions) instead
of for the one symbol the orchestrator happened to use.
* kafka-connect restarts. It defaulted to RestartPolicy=no, so one OOM
kill stopped CDC capture permanently while every topic still read
lag 0 and the pipeline still read `running` -- a dead producer and a
caught-up one look identical from lag. Its memory cap goes to 2 GiB,
which is what the measurement said was being used.
* sniStrict goes back to false. true refuses any handshake whose SNI
does not match a configured certificate, which makes https://<ip>/
unreachable -- the only address an operator has before DNS exists.
The TLS floor, the cipher suites and HSTS are unchanged.
No frontend or feature work rides along: this cut is the three fixes and
nothing else, so the tree differs from the published 0.1.5 in six files.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: rahulv8 <rahul.vishnoi@janio.asia>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three fixes found after
v0.1.5was tagged. Nobody has installed the published0.1.5 yet, so the tag gets re-pointed at this commit rather than spending a
0.1.6 on it.
The tree differs from the published 0.1.5 in six files — the three fixes and
nothing else. No frontend or feature work rides along; that waits for 0.1.6.
What changed
The k8s temporal-adapter now waits for Kafka.
createKafkaProducerfailing islog.Fatalfwith no retry — exactly like the orchestrator'skafka.NewManager—but only the orchestrator was wired to wait. A fresh
kindinstall of chart 0.1.5brought the adapter up after 4 restarts, every one
Failed to create Kafka producer ... connection refused.The guard that should have caught this asserted the literal
kafka.NewManagerwasabsent from the other two
main.gos — a symbol the adapter never uses, so the testwas green and the property untrue. It now matches a family of Kafka constructors
and checks the policy in both directions: a service that builds a client while
marked exempt fails, and one marked waiting whose constructor vanished fails too.
kafka-connect restarts. It defaulted to
RestartPolicy=no, so a single OOM killstopped CDC capture permanently while every topic still read lag 0 and the pipeline
still read
running— a dead producer and a caught-up one are indistinguishablefrom lag alone. Its memory cap goes to 2 GiB, which is what the measurement showed
it actually using; the overrun is native memory held by Debezium's change-stream
cursor, so raising
-Xmxwould have made it worse.sniStrictgoes back tofalse(Traefik's own default).truerefuses anyhandshake whose SNI does not match a configured certificate, which makes
https://<ip>/unreachable — the only address an operator has before DNS pointsanywhere. The TLS floor, the cipher suites, certificate validation and HSTS are
unchanged.
Verification
skip names a file
scripts/flip/excludes.txtdeliberately removes.test_the_census_is_not_vacuous.git ls-files -i -c --exclude-standard→ exactlyfrontend/next-env.d.ts,zero
.pycand zero.pytest_cache.🤖 Generated with Claude Code