Purge the edge after a repair, or verify answers per PoP (#89) (#90)
build-binaries / build-binaries (push) Successful in 2m33s
build-binaries / build-binaries (push) Successful in 2m33s
#89 asked for a decision. This is it, and it is the laziest of the three options listed there: **purge the whole pull zone by hand after a repair, one call, documented in the repair procedure.** Why not the other two: - Purging from `emit --verify` needs a CDN credential `emit` deliberately does not hold, and `emit` reports how many blobs it wrote, never which ones — so it could not target the keys anyway. - Waiting out the TTL means 30 days. Whole-zone rather than per-key costs a cold cache on a zone whose objects are mostly cold, and a repair scatters thousands of keys across the tree regardless. Also answers the question #89 left open: **the zone does not negative-cache.** A missing key answers 404 with `cache-control: no-cache` and `cdn-cache: MISS`, still MISS on an immediate retry (checked credential-free, 2026-08-01). Docs only — `docs/command-surface.md` and `nwsync`'s usage text. The procedure itself lives in sow-platform's NWSync runbook, next to the zone it acts on. Closes #89. 🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #90 Reviewed-by: xtul <mpiasecki720@protonmail.com> Co-authored-by: vickydotbat <vickydotbat@tutamail.com>
This commit was merged in pull request #90.
This commit is contained in:
@@ -97,6 +97,18 @@ broken — is skipped by every later run forever and no backfill repairs it. Wit
|
|||||||
and replaced when it does not match. It costs a full GET per existing blob, so
|
and replaced when it does not match. It costs a full GET per existing blob, so
|
||||||
it is a repair pass, not the default.
|
it is a repair pass, not the default.
|
||||||
|
|
||||||
|
**After a repair, purge the pull zone before believing `verify`.** A repair is
|
||||||
|
the one thing that makes a key serve different bytes than it did before, and the
|
||||||
|
edge caches these objects for 30 days precisely because that normally cannot
|
||||||
|
happen. The two commands therefore look at different copies on purpose: `emit
|
||||||
|
--verify` repairs the **origin**, `verify` reads the **edge**, and in between a
|
||||||
|
warm PoP still answers with the old bytes while a cold one answers with the new.
|
||||||
|
Until the zone is purged `verify`'s verdict is per-PoP and settles nothing — a
|
||||||
|
pass is not proof, and a failure is not the repair having failed. The purge is
|
||||||
|
one call against the pull zone; it belongs in the repair procedure rather than
|
||||||
|
in `emit`, which holds a storage credential and no CDN one (sow-tools#89, and
|
||||||
|
the procedure itself is in sow-platform's NWSync runbook).
|
||||||
|
|
||||||
`emit` uploads blobs first and the index last, so the presence of an index is
|
`emit` uploads blobs first and the index last, so the presence of an index is
|
||||||
the publication marker: an artifact whose emit died halfway leaves real blobs in
|
the publication marker: an artifact whose emit died halfway leaves real blobs in
|
||||||
the zone and no index. Blob names are content hashes, so re-running skips
|
the zone and no index. Blob names are content hashes, so re-running skips
|
||||||
|
|||||||
@@ -67,6 +67,8 @@ check on a published blob upstream of a player's client.
|
|||||||
--verify makes emit hash what it would otherwise skip. emit normally treats a
|
--verify makes emit hash what it would otherwise skip. emit normally treats a
|
||||||
blob's presence as proof of its contents, so without this an object written
|
blob's presence as proof of its contents, so without this an object written
|
||||||
truncated, or written by an emitter since found broken, is skipped forever.
|
truncated, or written by an emitter since found broken, is skipped forever.
|
||||||
|
--verify repairs the storage zone, while verify reads the edge in front of it,
|
||||||
|
so purge the pull zone after a repair or verify answers differently per PoP.
|
||||||
|
|
||||||
--out DIR writes to a local repository tree instead of uploading, which is the
|
--out DIR writes to a local repository tree instead of uploading, which is the
|
||||||
conformance path against upstream nwn_nwsync_write. Without it, the zone comes
|
conformance path against upstream nwn_nwsync_write. Without it, the zone comes
|
||||||
|
|||||||
Reference in New Issue
Block a user