Skip to content

docs(fleet): self-contained control plane design and implementation plan - #42

Merged
forhappy merged 2 commits into
codex/fleet-operations-foundationsfrom
codex/fleet-control-plane-plan
Oct 2, 2026
Merged

forhappy merged 2 commits into
codex/fleet-operations-foundationsfrom
codex/fleet-control-plane-plan

Conversation

@forhappy

@forhappy forhappy commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Define a supported Cellule control plane that reduces application-team integration and operational work, with explicit contracts for large fleets and production release evidence.

  • Ship a controller binary/container, CLI, bundled UI, and worker SDK. The supported integration requires no custom journal, observer, transport, election, or maintenance implementation from application teams.
  • Specify partition leases, atomic fleet and installation budgets, cross-partition movement, complete snapshot/delta inventory, and terminal-evidence archiving. These require versioned extensions to the existing framework contracts.
  • Cover capacity control, disruption limits, bulk maintenance, rolling upgrades, identity rotation, tenant isolation, restore-generation fencing, and operational diagnostics.
  • Define proposed qualification profiles up to 10,000 nodes and one million Cells, including failover, noisy-fleet isolation, historical churn, and a 72-hour soak. These are release targets, not measured capacity claims.
  • Provide ordered implementation packages CP0–CP13, source boundaries, acceptance commands, and a release evidence ledger that rejects skipped baseline capabilities.

docs/fleet-control-plane-audit.md records 18 design gaps, their evidence, design resolutions, implementation packages, and remaining qualification requirements. docs/fleet-control-plane-plan.md incorporates those resolutions into the self-contained implementation handoff.

Scope and dependency

This PR changes two documentation files and remains stacked on #37 (codex/fleet-operations-foundations). It consumes the canonical fleet safety contracts and explicitly requires versioned amendments before partitioning, inventory compaction, or restored-generation authorization can be enabled. Current framework limits remain authoritative until those extensions are implemented and qualified.

The documents do not implement the control plane or certify the unfinished native fleet/maintenance work. Production readiness requires the specified implementation, native fault tests, provider qualification, scale measurements, and operator acceptance. Retarget to main after #37 merges.

Validation

Checks passed in an isolated checkout of this PR's branch with only the documentation update:

  • python3 scripts/check-doc-links.py: 1,171 local links and anchors resolve.
  • python3 scripts/check-doc-rust-fences.py: 110 documented Rust snippets parse.
  • git diff --cached --check: passed.
  • Updated documents match the audited source copies; whitespace, code-fence balance, and JSON examples checked.

No runtime or process tests were run for this documentation-only change. Proposed binaries, APIs, and commands are clearly identified as implementation targets.

@forhappy
forhappy merged commit 353904e into codex/fleet-operations-foundations Oct 2, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant