Commit Graph
8 Commits
Author SHA1 Message Date
Ettore Di Giacinto d1a59aae41 fix(failover): never load a warm target inside a probe
A warm target's liveness probe called ModelLoader.Load, which blocked
until the model finished loading (while the warm preload loaded it
too). Tick waited for every probe, so all probing froze, and the probe
then ran HealthCheck on an expired context and tripped the target at
every startup.

The prober now takes a function that returns the running backend
without loading it. A target that is not loaded passes liveness; its
recovery is neither confirmed nor failed and it returns to healthy
after min_dwell, like a cold target. Tick no longer waits for probes:
each probe applies its own result and a target whose probe is running
is skipped.

Assisted-by: Claude:claude-opus-5-5
2026-09-26 19:22:14 +00:00
Ettore Di Giacinto 9c239209e1 fix(failover): answer HasChains from a flag set at sync
The request path called HasChains on every request, and with no chains
it scanned the config source each time: the loader's lock plus a copy
and sort of every config, forever, on every installation without
chains. Sync now keeps an atomic flag and HasChains reads only that.
A chain added since the last sync is still served because Plan syncs
on a miss; only in-request retry waits for the next tick (at most 1s).

Assisted-by: Claude:claude-opus-5-5
2026-09-26 19:18:24 +00:00
Ettore Di Giacinto 798f6c5105 fix(failover): spill capacity and disabled targets without tripping them
An admission rejection or a disabled target moves the request to the
next target through Attempt.Skip, which records no failure. A 4xx
response no longer counts as a success. Requests skip body recording
when no chain is configured, and stop it once the model is known not
to be a chain.

Assisted-by: Claude:claude-opus-5-5
2026-09-26 17:24:53 +00:00
Ettore Di Giacinto 8a0bf410ee feat(failover): run the chain manager and keep warm targets loaded
Warm local targets are pinned in the watchdog and preloaded. Switches
and target health are exported as metrics, skipped attempts as traces.

Assisted-by: Claude:claude-opus-5-5
2026-09-26 16:06:15 +00:00
Ettore Di Giacinto 86a9597893 feat(failover): schedule liveness and recovery probes
Idle targets get a liveness probe each interval, recovering targets an
inference probe. Cold local targets are never loaded to be probed.

Assisted-by: Claude:claude-opus-5-5
2026-09-26 15:48:05 +00:00
Ettore Di Giacinto b403a8e1c6 fix(failover): emit chain.switched when leaving degraded in place
recomputeLocked only fired the event on an active-target change or on
entering degraded. When the active target itself recovered while every
target was down, the chain silently left degraded with no event, so
SSE/realtime consumers tracking chain.switched.state got stuck on
"degraded".

Assisted-by: Claude:claude-opus-5-5
2026-09-26 15:45:41 +00:00
Ettore Di Giacinto 5601692f55 fix(failover): satisfy lint on the manager package
errcheck flagged two side-effect-only m.Plan calls in tests, and unused
flagged close(), which Task 5's probe scheduler wires in.

Assisted-by: Claude:claude-opus-5-5
2026-09-26 15:41:24 +00:00
Ettore Di Giacinto 929085a030 feat(failover): add chain manager with trip, fail-back and pins
Health is tracked per target and the active target per chain. Fail-back
waits for recovery probes and a minimum time on the fallback.

Assisted-by: Claude:claude-opus-5-5
2026-09-26 15:40:35 +00:00