Skip to content

Honor machine-cleanup policy directly instead of a global gate

Placeholder ppxd requested to merge fix/machine-cleanup-honor-policy-directly into main

Summary

Follow-up to #389. That PR added an extra global SQUID_MACHINE_CLEANUP_ENFORCEMENT env-var three-mode gate (default dry-run) on top of the per-policy DeleteMachinesBehavior. That was wrong:

  • The per-policy field (default DoNotDelete) is already the opt-in, so a policy explicitly set to DeleteUnavailableMachines would still delete nothing until a second, separate env var was flipped — surprising and contrary to the operator's stated intent.
  • It used the SQUID_* env-var / EnforcementModeReader mechanism rather than Squid's IConfigurationSetting pattern.

This removes the global gate entirely. The sweep now runs by default and deletes exactly what the policy opts in for: DeleteMachinesBehavior == DeleteUnavailableMachines (default DoNotDelete keeps it a no-op) and the target has been continuously unavailable past the grace period. Matches how the setting reads in the UI and how Octopus behaves.

Why non-breaking

  • Default policy is DoNotDelete ⇒ the sweep deletes nothing by default.
  • Removed code only (the env-var class + its tests); no public surface added; no enum/wire changes; no Octopus wording.
  • Machine.UnavailableSince, the grace-period evaluator, the recurring job, and the safe IMachineService.DeleteMachinesAsync delete path are unchanged.

Test plan

  • Unit — eligibility matrix + UnavailableSince transition (22 tests; removed the 7 now-obsolete env-var enforcement tests).
  • Integration (real Postgres) — eligible→deleted via the real path, DoNotDelete/within-grace/unknown-instant/healthy kept, UnavailableSince round-trip (6 tests).
  • Full solution build 0 errors; no residual references to the removed symbols.

Merge request reports

Loading