Honor machine-cleanup policy directly instead of a global gate
Summary
Follow-up to #389. That PR added an extra global SQUID_MACHINE_CLEANUP_ENFORCEMENT env-var three-mode gate (default dry-run) on top of the per-policy DeleteMachinesBehavior. That was wrong:
- The per-policy field (default
DoNotDelete) is already the opt-in, so a policy explicitly set toDeleteUnavailableMachineswould still delete nothing until a second, separate env var was flipped — surprising and contrary to the operator's stated intent. - It used the
SQUID_*env-var /EnforcementModeReadermechanism rather than Squid'sIConfigurationSettingpattern.
This removes the global gate entirely. The sweep now runs by default and deletes exactly what the policy opts in for: DeleteMachinesBehavior == DeleteUnavailableMachines (default DoNotDelete keeps it a no-op) and the target has been continuously unavailable past the grace period. Matches how the setting reads in the UI and how Octopus behaves.
Why non-breaking
- Default policy is
DoNotDelete⇒ the sweep deletes nothing by default. - Removed code only (the env-var class + its tests); no public surface added; no enum/wire changes; no Octopus wording.
-
Machine.UnavailableSince, the grace-period evaluator, the recurring job, and the safeIMachineService.DeleteMachinesAsyncdelete path are unchanged.
Test plan
-
Unit — eligibility matrix + UnavailableSincetransition (22 tests; removed the 7 now-obsolete env-var enforcement tests). -
Integration (real Postgres) — eligible→deleted via the real path, DoNotDelete/within-grace/unknown-instant/healthy kept, UnavailableSinceround-trip (6 tests). -
Full solution build 0 errors; no residual references to the removed symbols.