Skip to content

feat(media): add sharded media object-key paths - #4533

Open
bradseiler wants to merge 16 commits into
mainfrom
seiler/media-layout-migration
Open

feat(media): add sharded media object-key paths#4533
bradseiler wants to merge 16 commits into
mainfrom
seiler/media-layout-migration

Conversation

@bradseiler

@bradseiler bradseiler commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Why

Media payload keys are currently flat, so high-volume traffic lacks hash-leading S3 prefix entropy. Existing deployments also need a safe, explicit rollout that preserves old reads and rollback behavior without changing storage behavior merely by upgrading.

What

  • moves media payloads to media/<sha[0:2]>/<sha[2:4]>/<community>/<filename> while leaving Git/CAS namespaces unchanged
  • adds BUZZ_MEDIA_MIGRATION_PHASE with three complete media object-key path policies:
    • legacy-only (default): read and write only legacy paths, preserving existing deployment behavior
    • dual-read-and-write: prefer sharded reads with legacy fallback and write both paths
    • sharded-only: read and write only sharded paths
  • defines the existing-deployment rollout as legacy-onlydual-read-and-write → backfill → sharded-only
  • recommends that new deployments start with sharded-only before their first upload, avoiding any future backfill or legacy cleanup
  • adds sharded-first/legacy-fallback read telemetry, strict bucket classification, logical billing deduplication, duplicate-layout gauges, and authoritative payload keys in upload records
  • includes buzz-media-layout-backfill and buzz-media-layout-delete-legacy in both relay image targets, with bounded paging, checkpoints, request-rate limiting, idempotency, destination verification, dry-run, and destructive confirmation
  • documents new-install and existing-deployment flows and provides Kubernetes Job examples

Validation

  • cargo test -p buzz-media --all-targets: 119 passed; live-MinIO test ignored
  • cargo test -p buzz-relay --lib config::tests::: 32 passed
  • cargo test -p buzz-relay --lib storage_sweep: 15 passed
  • cargo clippy -p buzz-media -p buzz-relay --all-targets -- -D warnings: clean
  • cargo fmt --all -- --check, desktop Tauri fmt, and git diff --check: clean
  • pre-push hooks after merging current origin/main: Rust, desktop, Tauri, mobile, and typecheck suites passed
  • Helm values/test YAML and values schema JSON parse cleanly; Helm CLI is unavailable locally

Generated with Goose

@bradseiler bradseiler changed the title feat(media): add phased S3 layout migration feat(media): add sharded media object-key paths Aug 6, 2026
@bradseiler
bradseiler marked this pull request as ready for review August 7, 2026 04:55
@bradseiler
bradseiler requested a review from a team as a code owner August 7, 2026 04:55
@bradseiler
bradseiler force-pushed the seiler/media-layout-migration branch from ada0dd3 to 828b51e Compare August 7, 2026 05:13
npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch and others added 16 commits August 10, 2026 16:12
Co-authored-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Signed-off-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Classify sharded payload keys in storage sweeps, preserve physical totals, and deduplicate logical legacy/sharded copies. Export read resolution, fallback, and duplicate-layout metrics.

Co-authored-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Signed-off-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Co-authored-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Signed-off-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Co-authored-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Signed-off-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Keep self-hosted upgrades on legacy writes by default, expose the write-layout gate through Helm and Compose, and document the explicit legacy-to-dual-to-sharded migration sequence.

Co-authored-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Signed-off-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Consolidate read and write policy behind one upgrade-safe phase and ship guarded maintenance binaries for backfill and legacy cleanup.

Co-authored-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Signed-off-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Co-authored-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Signed-off-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Co-authored-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Signed-off-by: npub128x7j3pwgm4vs8yra3c42fcgcwcvh94g3luwzkqa376du2q6l0esqcrwch <51cde9442e46eac81c83ec71552708c3b0cb96a88ff8e1581d8fb4de281afbf3@buzz.block.builderlab.xyz>
Signed-off-by: Brad Seiler <seiler@squareup.com>
Signed-off-by: Brad Seiler <seiler@squareup.com>
Replace the Option + expect("checked above") pattern in both upload
short-circuit paths with a filtered if-let binding, so the presence of
the blob key is guaranteed structurally instead of by a comment on a
non-local invariant. Also collapse the longhand match on
existing_write_key into `?`. No behavior change.

Signed-off-by: Brad Seiler <seiler@squareup.com>
Document that returning to legacy-only after accepting uploads in
sharded-only makes sharded-layout objects unreadable until the phase is
raised again. Ship sharded-only in the Compose example environment so
fresh stacks never need a backfill, and correct the chart README to
reflect that only the chart default remains legacy-only for upgrade
safety.

Signed-off-by: Brad Seiler <seiler@squareup.com>
Co-authored-by: Brad Seiler <seiler@squareup.com>
Signed-off-by: Brad Seiler <seiler@squareup.com>
Co-authored-by: Brad Seiler <seiler@squareup.com>
Signed-off-by: Brad Seiler <seiler@squareup.com>
Co-authored-by: Brad Seiler <seiler@squareup.com>
Signed-off-by: Brad Seiler <seiler@squareup.com>
Co-authored-by: Brad Seiler <seiler@squareup.com>
Signed-off-by: Brad Seiler <seiler@squareup.com>
@bradseiler
bradseiler force-pushed the seiler/media-layout-migration branch from 5fc442c to 1cfde28 Compare August 10, 2026 20:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant