R2D2-MERIDIAN/docs
Joshua Belke b6443a823b
Some checks failed
control plane / chart (push) Has been cancelled
control plane / test (push) Has been cancelled
control plane / browser-e2e (push) Has been cancelled
control plane / Build control plane image (linux/amd64) (push) Has been cancelled
control plane / Build control plane image (linux/arm64) (push) Has been cancelled
control plane / Publish signed control plane image (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Meridian Harness / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Meridian Harness / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Meridian Harness / Publish rolling release (push) Has been cancelled
Meridian Harness / Publish tagged release (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Isolated DB Gate (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Admin Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Server Cross-Compile (push) Has been cancelled
CI / Server Cross-Compile-1 (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
fix(bus): report Zenoh reachability separately instead of overclaiming ready
`meridian_zenoh_ready` was 1 and `/_readiness` `bus.ready` was true on both
pods for the entire period during which cross-pod delivery was completely
broken (meridian-ty6l). The cause is structural: `probe()` publishes on the
session's own health key and is satisfied by that same session's subscriber,
which Zenoh delivers without involving the router at all
(`zenoh-1.8.0/src/net/runtime/mod.rs:325`). The probe proves the session
object is alive and proves nothing about reachability.

The obvious fix -- require a witness for readiness -- is wrong, because a
single-relay deployment has no peer to witness it and would be held closed
for ever. So the signal is split rather than tightened:

- `bus_ready()` / `meridian_zenoh_ready` keep exactly their conditions and are
  now named as liveness in code, in `/_readiness` and in the runbook. Redis and
  Shadow paths are untouched: Shadow still answers from Redis alone.
- A separate `ZenohReachability` is reported and gates nothing. It carries two
  router-external witnesses that fail independently. The declaration plane is
  `Publisher::matching_status()` on a publisher restricted to
  `Locality::Remote`, which `net/runtime/mod.rs:326` answers by
  `matches.values().any(|dir| dir.id != face_id)` -- every face but our own,
  and for a client session those faces are populated only by declarations the
  router forwarded. The data plane is the health subscriber widened from
  `_health/<own-zid>` to `_health/*`: a sample keyed to an id this process does
  not own cannot have been delivered locally. The peer map is bounded in both
  directions, since its key now arrives over the bus.
- `meridian_zenoh_received_total` is registered at 0 for all eleven lanes at
  startup, and every new series likewise. An absent series and a zero series
  are the same picture on a dashboard and opposite facts, and the live re-probe
  hit exactly that ambiguity.

`MeridianBusPeersUnreachable` pages when a pod reports ready, sees no peer on
either plane, and more than one pod in the namespace has an open session. That
last clause is the whole design: no single session can tell "alone" from "cut
off", so the discriminator is the fleet's own pod count. A one-pod deployment
never trips it. Listed in `MUST_BE_ALERTED` under a second, written-down
criterion -- a metric whose failure to *move* is the fault -- with a runbook
section and an inventory row, in this commit rather than a later one.

The reproduction test keeps asserting the absence of delivery and now also
asserts that reachability reads zero on every field while it happens. Its
counterpart, `an_isolated_pod_is_indistinguishable_from_a_lone_one`, stands up
one relay against a real zenohd and proves it reaches readiness with no witness
-- the evidence that this must not gate.

Verified: `just zenoh-check` 0, `just zenoh-router-check` 0 (3/3 against a live
eclipse/zenoh:1.8.0), clippy `-D warnings` with `--features zenoh` 0,
`just fmt-check` 0, `just check-alert-runbooks` 0 (35 alerts / 204 metrics),
`just check-unwrap-budget` 0, `cargo test -p meridian-relay --lib` 889 passed.

Refs: meridian-ty6l
Signed-off-by: Joshua Belke <joshua@innovationhub-act.org>
2026-08-20 21:03:51 -04:00
..
admin feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
assets/screenshots feat(rebrand): finish the conversion — sprig, sprout, and a lost-identity bug 2026-08-04 23:50:47 -04:00
benchmarks feat(brand): square 5x5 M, and move the pile holes to fit it 2026-08-05 08:16:29 -04:00
formal feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
mips docs(mips): adopt MIP-RT and withdraw the on-chain payments scope 2026-08-20 18:34:48 -04:00
nips refactor: move clients under REMAPPING deployable grammar 2026-08-19 14:01:39 -04:00
plans feat(brand): square 5x5 M, and move the pile holes to fit it 2026-08-05 08:16:29 -04:00
runbooks fix(bus): report Zenoh reachability separately instead of overclaiming ready 2026-08-20 21:03:51 -04:00
spec feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
AGENTS.md docs(mips): adopt MIP-RT and withdraw the on-chain payments scope 2026-08-20 18:34:48 -04:00
bridge-channel-window.md feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
community-registration-launch-policy.md feat(brand): square 5x5 M, and move the pile holes to fit it 2026-08-05 08:16:29 -04:00
control-plane-deployment.md fix(control-plane): retire "communities" from the relay host and the address placeholders 2026-08-05 21:33:44 -04:00
git-on-object-storage.md feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
linux-rendering-troubleshooting.md fix(repo): point the repo slug at the real remote, not the guessed one 2026-08-05 13:00:51 -04:00
MCP_DRIVEN_HOOKS.md feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
meridian-shared-compute-dev.md fix(repo): point the repo slug at the real remote, not the guessed one 2026-08-05 13:00:51 -04:00
multi-tenant-conformance.md feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
multi-tenant-relay.md feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
nostr-nip-support-matrix.md docs(mips): adopt MIP-RT and withdraw the on-chain payments scope 2026-08-20 18:34:48 -04:00
projects-qa-runbook.md feat(brand): square 5x5 M, and move the pile holes to fit it 2026-08-05 08:16:29 -04:00
push-gateway-deployment.md feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
ux-end-to-end-workflow.md test(bus): compile the Zenoh backend in a gate, and correct eleven stale claims 2026-08-19 17:02:03 -04:00
welcome-kickoff-silent-failures.md feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00
workflow-variables.md feat: rebrand Codebase Chat to Meridian 2026-08-04 14:06:04 -04:00