From 0a2b3a4a56e7556f1fda34933b1834914d77b69b Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Sun, 16 Aug 2026 17:37:28 +0200 Subject: [PATCH] CB-597: fix inaccuracies the example config already had, none actually missing MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Audited bridged.example.yaml against BridgedConfig's KNOWN_TOP_LEVEL_KEYS and found every top-level key already documented (broker, health, lifecycle, configReload, quarantineCooldownSeconds, fleet.leaders/architects/reviewers included) — CB-573/CB-566/CB-559/CB-579/CB-527/528 each updated the example alongside their feature. What was actually wrong: - health.workingSuspectAfterSeconds/paneProbeIntervalSeconds claimed enforced minimums (300/60) that don't exist in code — only intervalSeconds is clamped (floor 15); the other two are parsed but never read anywhere. - notifications.mode: webhook was undocumented as only flipping the healthCoverage label bridge_list reports — no webhook is ever sent. - lifecycle.clearAfterTurn was missing entirely. - the HOT bullet under configReload claimed the whole fleet: block reloads live, but ConfigRef's own javadoc carves out fleet.leaders as needing a restart with no deferred-list warning — added that exception. - fleet.leaders' demotion consequence (unmatched tab -> silent WORKER demotion, no startup error) is now stated inline next to the block, not just implied by the multi-lead rationale higher up. --- bridged/bridged.example.yaml | 41 ++++++++++++++++++++++++++++++------ 1 file changed, 35 insertions(+), 6 deletions(-) diff --git a/bridged/bridged.example.yaml b/bridged/bridged.example.yaml index 9b5b9eb..cec5520 100644 --- a/bridged/bridged.example.yaml +++ b/bridged/bridged.example.yaml @@ -88,15 +88,28 @@ bind: # backoffMs: 60000 # quietNudgeCap: 3 -# Fleet health detection is dormant unless enabled. It reads one whole-fleet agent list per tick. -# It can run without a webhook; bridge_list then reports healthCoverage: detection-only. +# Fleet health detection is dormant unless enabled (CB-573). It reads one whole-fleet agent list +# per tick. +# intervalSeconds → how often a tick runs (default 30). ENFORCED floor of 15: the code computes +# Math.max(15, intervalSeconds), so a lower value is silently raised, not +# rejected. +# workingSuspectAfterSeconds, paneProbeIntervalSeconds → accepted and parsed, but NOT YET READ by +# anything — the dormant monitor only consumes intervalSeconds today (CB-573 +# shipped ahead of the evidence publishers these two knobs are for). Setting +# them changes nothing right now, and no minimum is enforced on either, because +# nothing reads them to enforce one. They exist so a later build can start +# honouring them without another config-shape change. +# notifications.mode → "webhook" flips what bridge_list REPORTS (healthCoverage: "full" instead +# of "detection-only") — it does NOT make bridged send any webhook call; no +# delivery mechanism is implemented yet. Any other value, or omitting the +# block, reports "detection-only". # health: # enabled: true -# intervalSeconds: 30 # minimum 15 -# workingSuspectAfterSeconds: 600 # minimum 300 -# paneProbeIntervalSeconds: 60 # minimum 60 +# intervalSeconds: 30 +# workingSuspectAfterSeconds: 600 +# paneProbeIntervalSeconds: 60 # notifications: -# mode: disabled # disabled (default) or webhook +# mode: disabled # herdr Unix socket. Omit to use the client default # (${HERDR_SOCKET_PATH:-~/.config/herdr/herdr.sock}). @@ -286,6 +299,11 @@ placement: weighted # / credentialId. Those are hot because the placement policy (and, for credentialId, # the CB-578 stage B quarantine check) reads them through a supplier — being config is # not by itself enough to make a key hot. +# EXCEPT `fleet.leaders`: Bridged.main reads it once at startup to build the lead tab +# scanner and launcher, and neither is rebuilt on reload. A changed/added/removed +# `fleet.leaders` entry is silently accepted — the reload reports "config reloaded" +# with nothing in the deferred list — but has NO effect until you restart. Treat it +# as deferred in practice, even though today's reload output does not say so. # DEFERRED → accepted into the new config, but the wiring built at startup keeps the old value # until you restart: `lifecycle:`, `leadHeartbeat:`, `guard:`, `worktreeRoot:`, # `spawnReadyTimeoutMs` / `spawnReadyPollMs`, `quarantineCooldownSeconds` (CB-578 @@ -368,6 +386,12 @@ fleet: # An auto-launched lead is NOT a member: it gets no worker reply charter, is never registered with # the session lifecycle (the idle reaper would kill your orchestrator), and stays on the # subscription — ANTHROPIC_BASE_URL/AUTH_TOKEN are stripped from its env whatever the profile says. + # + # GET THE `tab:` VALUE RIGHT. A pane that does not match any configured `tab:` (a typo, a renamed + # tab, a pane no entry names at all) is not recognised as a lead — it resolves as an ordinary + # WORKER instead, silently, and every orchestration call it makes (spawn/stop/send/drain) is + # refused. There is no error at startup for this: an unmatched pane is simply not a lead. If your + # primary suddenly can't spawn or send, check this section first. # leaders: # opus-5.0: # profile: opus # omit to never create this lead, only recognise it @@ -423,10 +447,15 @@ guard: # idleTtlSeconds → reap READY/DONE sessions idle longer than this (never BUSY/SPAWNING) # contextCap → force-release a session after this many delegated turns # drainTimeoutSeconds → seconds to wait for BUSY sessions on shutdown before forced teardown +# clearAfterTurn → whether a reusable worker discards its conversation context after every +# completed delegated turn (default false). Works for claude-code workers +# only — any other peer kind (e.g. opencode) logs "context reset is +# unsupported for peer kind …" once and the reset is a no-op. # lifecycle: # idleTtlSeconds: 300 # contextCap: 10 # drainTimeoutSeconds: 5 +# clearAfterTurn: false # Durable reply delivery (CB-307 Stage 2). OMIT this block entirely to keep the default # in-memory, soft-state reply inbox (late worker replies are held only until a daemon bounce). -- 2.52.0