Skip to content

Roll out USD-M reference manifest V2 on existing ECS host #916

Description

@proerror77

Exact target identity

ECS i-6we6afeqsvv8uo1ixmyo (monday-trade-data-26, ap-northeast-1b): only binance-usdm-reference-collector.service, binance-usdm-reference-upload.service, and binance-usdm-reference-upload.timer, plus the digest-addressed isolated shadow unit.

Named controller

codex-root

Candidate identity

  • Source/main and PR fix(deploy): accept collocated reference uploader upgrades #808 merge: 9f2d3cbafe9dc9fee25447c0e755236f44a61785.
  • Release workflow: 32043628527 (success), artifact ID 9292453505, artifact binance-lob-archiver-linux-amd64-9f2d3cbafe9dc9fee25447c0e755236f44a61785, uploaded ZIP SHA-256 138c761f0c5b7eb7c0f7942b8d2d4c7a48a6e17d8639c253a14e2abf95e5eb0c.
  • Immutable image: crpi-ygobwehhof7qs9m3.ap-northeast-1.personal.cr.aliyuncs.com/wildcard0923/binance-lob-archiver@sha256:7e84dc6838cd646b1ebd71b486a43db2fba8fa2fde4d2c407b1d9eae55594d62.
  • Collector SHA-256: f3cd2e79179765fdbf71684b3ab6e6de339df24763e9d07e76938f4d6dc90f64.
  • Verifier SHA-256: d2c4c234e8fc2232937f1609df4bd30bc53918902586ad2e8577cb6826a4b92a.
  • Uploader SHA-256: 35891f1b7383e55a2c9f88e91c409f41cc4f751d8b8f4ff44d69fe77aca44b83.
  • Release JSON SHA-256: 3bc4c855199d11f9007f1289e83a3a743632fb77b0d3d6adc5643e1498c2bbd7.
  • Shadow control manifest SHA-256: b3ae87e6b7fb7f891f0b2733786c362f27702a6f2dc01d64d2245dd6a44d197a.
  • Production control manifest SHA-256: b762bf780d3efedc365ac70459248c1407b56c257be182b35f3d2d6b10d0c4ad.

Exact rollback identity

  • Source revision: 32e01918a88355f0708bbacd9ae6d4d5eb32aa13.
  • Collector: 8b5b724e49c32ac8ead32c68cc9b5942d9010c1268973785d816ddf9c647b7d4.
  • Uploader: 539d6b6530220dadedbe002f5bce4430ab5e572352ca84124295e310ded116b6; sidecar SHA-256 ac7b09f4cce5fbbdb02f44e96650872bd10a4902ebc65f7f8c2b1f9ea0c652d2.
  • Release JSON SHA-256: 84aa368d9385ad051ece449e041ede7ba457c9d662953f8e0c247f3f468892ea.
  • Installed collector/uploader/timer/env SHA-256: 0d15b20778c729059bfbe03d3498e4eb9e1a60f3f2e53a32f0053959f47e15a7, 0eb681c5b6270d2f86d7913f51f079d376c2a5f6204340d40e587518f1affdf8, 2e6823d2eeb4f5cd285dba9edd8547635c9ce1e372f5681af950785294d085c9, fc06c431c6f7baa94723543cdbc3c066432e4783846c8ce66f53782c56beb7f3.
  • Existing cutover script stages these exact assets and automatically restores the prior release after any post-transition failure; failed rollback must leave all four transition units runtime-masked.

Current read-only preflight

Stop rules

  • Stop before any production mutation on candidate/control/rollback digest drift, unsafe owner/mode/path, non-internal OSS configuration, wrong unit/process identity, active uploader at the cutover check, mount drift, or /data below the existing 25% free warning floor.
  • Stop the shadow on any restart, InvocationID drift, API/artifact error, V1 manifest, missing modality clock, gap above 90s, artifact discontinuity, or incomplete 3600-second observation.
  • Cut over only from exactly one immutable PASSED.sha256 bound to this candidate/control bundle. On production health, upload, identity, or readback failure, use only the cutover script automatic rollback/containment.

Success and independent readback

  • One isolated 3600-second V2 shadow gate passes; shadow is then inactive.
  • Cutover receipt and PASSED.sha256 validate; exact candidate process and upload timer are active/enabled with zero candidate restarts.
  • A fresh production manifest is binance.usdm_reference_manifest.v2 with separate mark_index_funding and open_interest clocks and max gap at most 90s.
  • OSS data, manifest, and _SUCCESS are independently read, hashed, and match the production receipt; uploader-owned local source is removed.
  • The temporary transport object is deleted only after on-host digest verification and the digest-addressed release remains as rollback/audit evidence.

Out of scope

No account credentials or fee files; no LOB/raw collector cutover; no Paper, Shadow trading, LiveSmall, orders, risk-limit change, or runtime resume. Research consumer/readback remains #606.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestready-for-agentFully specified and safe for an autonomous agentruntimeRequires deployment, runtime mutation, or live evidence for closure

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions