Skip to content

fix: move to scalo 2.14.1 and turn PGO and BOLT on for GA - #220

Merged
catinspace-au merged 3 commits into
mainfrom
fix/ga-scalo-2-14
Oct 6, 2026
Merged

catinspace-au merged 3 commits into
mainfrom
fix/ga-scalo-2-14

Conversation

@catinspace-au

@catinspace-au catinspace-au commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

GA rebuild of dfe-fetcher on scalo 2.14.1, with PGO and BOLT back on and two GA fixes.

  • scalo 2.14.1 in the workspace. 2.14.1 evaluates CEL on cel 0.14, so the workspace cel range is >=0.14.5, <0.15 and one cel resolves. The filter and template code builds unchanged and all 77 filter, template and predicate tests pass. No shipped profile or example calls contains() on a list or map.
  • scalo ships no vendor, licence, copyright or registry defaults now, so the contract names HYPERI PTY LIMITED, io.hyperi, BUSL-1.1, the copyright line and ghcr.io/hyperi-io itself.
  • DLQ: common_topic is an Option. A config file with no dlq: key now gets the fleet standard (common routing, dfe_fetcher_dlq, /var/spool/dfe/dlq). It got scalo's per-table defaults before, and the old schema default shows it.
  • config/defaults.yaml names the chart repo and the dfe namespace, so generate-artefacts writes the ArgoCD Application again.
  • build.skip_optimize is gone: a release build runs PGO and BOLT on scripts/pgo-workload.sh.
  • CloudWatch metric timestamps land in 1970: the fetcher emits float epoch seconds #218: CloudWatch metric rows carry timestamp as integer epoch milliseconds, not float epoch seconds. Pinned by a test on a real-shaped GetMetricData answer with fractional seconds. The loader end-to-end check the issue asks for is not done here, so this refs it.
  • a cursor-store read error slides the fetch window forward and skips what sat behind it #138: a cursor read that fails refuses the tick under either on_missing_cursor setting, so the next tick reads again from the stored cursor rather than fetching the lookback and writing the cursor past the gap. Pinned by a scheduler test with a store that fails one read.
  • The capability catalogue says the vault 'data' segment is required and names the mount -- neither is true #183 (part): the catalogue's credential_secret text and the README describe vault specs the way scalo parses them. crates/core/src/secret.rs:11 still carries the old wording.

Regenerated, expected diffs:

  • Dockerfile: the new regenerate header line.
  • chart/templates/deployment.yaml: the checksum/secret pod annotation.
  • docs/config-schema.*: x-scalo-secret beside x-dfe-secret, the fixed DLQ defaults, scalo 2.14.0's own doc text.
  • docs/capability-catalog.*: the credential_secret text.

Second commit, the GA deps pass:

  • Every crate on its newest in-major release, floors raised to the lock: tokio 1.53.2, uuid 1.27.0, thiserror 2.0.21, smallvec 1.16.2, reqsign 0.20.7, async-compression 0.4.50, odbc-api 29.2.0, tokio-test 0.4.6.
  • arrow-odbc 26.0.0 (its breaking change is insert-side, the fetcher only reads). arrow stays 59 because arrow-odbc 26 still needs it, so fix(deps): update Rust crate arrow to v60 #199 is closed with that reason. fix(deps): update rust-dependencies #219 is closed as covered.
  • Held on scalo's line: opentelemetry-proto 0.31. Held by testcontainers-modules 0.15: testcontainers 0.27.
  • GHSA-w9wp-h8wv-79jx stays accepted and unreachable; the osv reason names Move the OpenTelemetry stack off 0.31 once metrics-exporter-opentelemetry publishes scalo-rs#281.
  • Test brokers: apache/kafka 4.3.1 and ClickHouse 26.3.42.3 by digest, Redpanda v26.2.3 by digest in the PGO workload.
  • A manual dispatch no longer releases by default: from-head is an empty string, inputs match the other apps.
  • Unused workspace csv entry removed.

Local proof:

  • nextest after the deps commit, default: 1331 passed, 73 skipped. jemalloc: 1331 passed, 73 skipped. db-clickhouse,db-mongodb,file-tail: 1362 passed, 73 skipped. Docker was unreachable, so the testcontainers tests returned early; CI runs them, including the new Kafka and ClickHouse pins.
  • cargo clippy --all-targets -- -D warnings on rustc 1.99.0 is clean for all three feature sets, and cargo check -p dfe-fetcher-db --features odbc --all-targets compiles arrow-odbc 26.
  • Drift tests pass: checked_in_chart_matches_generated, checked_in_dockerfile_matches_generated, test_config_artifacts_do_not_drift.
  • generate-artefacts with config/defaults.yaml writes argocd-application.yaml with repoURL: https://github.com/hyperi-io/dfe-fetcher and namespace: dfe.
  • optimise probe: skip_optimize resolved=False, pgo=on, bolt=on.
  • hyperi-ci check --quick: Detected language: rust, quality complete, markdownlint 30 files clean, clippy src and tests on all three feature sets passed.

scalo 2.14.0 ships no vendor, licence, copyright or registry defaults, so the contract now names HYPERI PTY LIMITED, the io.hyperi label namespace, BUSL-1.1, the copyright line and ghcr.io/hyperi-io itself.

The DLQ common topic is now an Option. A config file with no dlq: key now takes the fleet DLQ standard: common routing to dfe_fetcher_dlq, spooled under /var/spool/dfe/dlq. It took scalo's per-table defaults before, because a field-level serde default skips the app's own Default.

config/defaults.yaml names the chart repo and the dfe namespace, so generate-artefacts writes the ArgoCD Application.

build.skip_optimize is gone, so a release build runs PGO and BOLT on scripts/pgo-workload.sh.

CloudWatch metric rows carry the timestamp as integer epoch milliseconds. They carried CloudWatch's float epoch seconds, which a DateTime64(3) column reads as milliseconds, so every row landed in January 1970.

A cursor read that fails now refuses the tick under either on_missing_cursor setting, so the next tick reads again from the stored cursor. It used to fetch the default lookback window and write the cursor past everything that sat behind it.

The capability catalogue and README describe vault specs the way scalo parses them: the first segment is the mount, and a data segment after it is optional.

The Dockerfile, chart and config schema are regenerated: the new header comment, a checksum/secret pod annotation, the projected service-account volume and the x-scalo-secret marker. The schema check in the tests reads x-scalo-secret.

Closes #138
Refs #218
Refs #183
@catinspace-au
catinspace-au marked this pull request as draft October 6, 2026 00:55
Every crate moves to its newest in-major release, and the manifest floors follow the lock: tokio 1.53.2, uuid 1.27.0, thiserror 2.0.21, smallvec 1.16.2, reqsign 0.20.7, async-compression 0.4.50, odbc-api 29.2.0 and tokio-test 0.4.6.

arrow-odbc moves to 26.0.0. Its one breaking change quotes column names in generated insert statements, and the fetcher only reads through OdbcReaderBuilder.

arrow stays on 59, because arrow-odbc 26.0.0 still depends on arrow 59 and arrow 60 would put two arrow majors in the graph. cel and opentelemetry-proto stay on the lines scalo pins, and testcontainers on the one testcontainers-modules 0.15 accepts.

The workspace csv entry goes: no member inherits it, only csv-core.

GHSA-w9wp-h8wv-79jx stays an accepted, unreachable risk on opentelemetry_sdk 0.31.0. The osv-scanner reason and the deny.toml note now name hyperi-io/scalo-rs#281 and metrics-exporter-opentelemetry, the crate that holds scalo on the 0.31 line.

The Kafka test broker moves to apache/kafka 4.3.1, the version the current stack deploys, and it and ClickHouse 26.3.32.14 are pinned by digest. The PGO workload broker moves to Redpanda v26.2.2, pinned by digest.

A manual dispatch no longer cuts a release by default: from-head is an empty string unless set, and the inputs match the other apps, optimize-tier included.
scalo 2.14.1 evaluates CEL on cel 0.14, so the workspace cel range moves to >=0.14.5, <0.15 and one cel resolves. The filter and template code builds unchanged, and no shipped profile or example calls contains() on a list or map.

The ClickHouse test fixture moves to 26.3.42.3 and the PGO workload broker to Redpanda v26.2.3, both pinned by digest.
@catinspace-au
catinspace-au marked this pull request as ready for review October 6, 2026 04:08
@catinspace-au
catinspace-au merged commit 0ae4a16 into main Oct 6, 2026
14 checks passed
@catinspace-au
catinspace-au deleted the fix/ga-scalo-2-14 branch October 6, 2026 04:08
@catinspace-au catinspace-au changed the title fix: move to scalo 2.14.0 and turn PGO and BOLT on for GA fix: move to scalo 2.14.1 and turn PGO and BOLT on for GA Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant