Skip to content

Audit deployment timeouts as DeploymentTimedOut, not DeploymentFailed

Placeholder ppxd requested to merge feat/deployment-timedout-audit-category into main

Summary

  • A wall-clock deployment timeout now pauses the deployment and preserves its checkpoint for resume (shipped in the resumable-timeout change). Recording its audit event as DeploymentFailed misrepresented this recoverable outcome, so a timed-out deployment showed up in the audit feed as a failure.
  • Adds EventCategory.DeploymentTimedOut = 19 and repoints DeploymentAuditEventHandler.OnDeploymentTimedOutAsync to it, so the audit feed distinguishes a timeout (paused/resumable) from a genuine failure.

Why it's non-breaking

  • 19 is additive — no existing value (1–18) is renumbered, and EventCategory stays short-backed. The event.category column is a plain smallint with no CHECK constraint / enum type, so no migration is needed.
  • The new EventCategoryRegistry descriptor is mandatory, not optional: the read path (EventService.ToDto → EventCategoryRegistry.Describe) throws on an unmapped category, and the EveryEventCategory_HasANonEmptyDescriptor drift test enforces it. Both are satisfied by the added descriptor.
  • No switch/exhaustive match over EventCategory anywhere in src/ lacks a default. The handler diff is surgical — only OnDeploymentTimedOutAsync changed; OnDeploymentFailedAsync and the other 8 mappings are untouched.

Pairs with

The resumable-timeout change (separate PR on this milestone) is what makes a timeout paused/resumable. This PR is independently correct — the DeploymentTimedOutEvent is emitted on timeout regardless — and the two together make task state and audit category fully consistent.

Test plan

  • Unit: EventCategoryRegistryTests — display-name InlineData + 19 numbering pin; DeploymentAuditEventFactoryTests — passthrough InlineData. (23/23)
  • Integration (real Postgres): DeploymentAuditEventHandlerTests.TimedOutEvent_IsAuditedAsDeploymentTimedOut asserts the timeout records DeploymentTimedOut; FailedEvent_PersistsDeploymentFailed retained as the contrast proving genuine failures are unaffected. (7/7)
  • dotnet build src/Squid.Core — 0 errors.
  • Adversarial review (independent agent): ship, no blocking issues.

Follow-up (frontend, separate repo)

SquidWeb feat/deployment-timedout-event-tone tones the new category as warning (orange) — opened alongside.

Merge request reports

Loading