QM-46: Drive Slack runtime reconciliation from one installation snapshot and change notifications - #1493
Merged
Conversation
…hot and change notifications
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes QM-46.
Changes
Why this matters: Every core instance re-read the Slack installation row twice
every five seconds, even for organizations that have never connected Slack, because
the reconciler had to ask two separate questions to tell "no Slack configured" apart
from "Slack was removed". That is roughly 94 pointless SELECTs per second across the
fleet, and the two reads could also disagree with each other when an uninstall landed
between them. Polling was also the only way a second instance learned about a save, so
an admin's change was invisible elsewhere until the next tick.
What changes:
startup and afterwards only when the installation actually changes, when its
listener reconnects, or on a slow five-minute repair tick (five seconds while a
reconcile is failing).
PUT/DELETE /api/slack-installationnow takes effect on every core instance in milliseconds instead of waiting for a
poll. The
GET/PUT/DELETEresponse bodies the admin console reads are unchanged.unmanaged, disabled, and active can no longer disagree; an uninstall still beats
SLACK_BOT_TOKEN/SLACK_APP_TOKENfrom the environment.DATABASE_URLset, the change notificationrides a Postgres
slack_installationnotify channel carrying only the recordversion and never token material; without it, an in-process bus keeps a
single-process dev instance just as instant.
Acceptance stories:
installation row twice every five seconds; now I read it once at startup and again
only on the five-minute repair tick.
plugin on another core instance used to catch up on its next poll; now it picks up
the change in milliseconds, and a rejected save still changes nothing.
hand back environment tokens for an installation that had just been removed; now one
snapshot decides, and a removed installation keeps the plugin off.
dropped and covered by the next poll; now it coalesces into exactly one follow-up
reconcile, with no two reconciles ever overlapping.
saving tokens; now activation is immediate through the in-process bus.
Test Plan
npm run typechecknpm run lintnpm run lint:oxnpm run lint:knipnpm run format:checkNODE_ENV=test ALLOW_UNSIGNED_TEST_IDENTITY=1 node --experimental-test-module-mocks --test test/slack-runtime.test.tsNODE_ENV=test ALLOW_UNSIGNED_TEST_IDENTITY=1 node --experimental-test-module-mocks --test test/slack-installation-store.test.tsNODE_ENV=test ALLOW_UNSIGNED_TEST_IDENTITY=1 node --experimental-test-module-mocks --test test/connector-byo-route.test.tsNODE_ENV=test ALLOW_UNSIGNED_TEST_IDENTITY=1 node .io-agent-qm-46/proof/qm46-runtime-proof.tsManual check: none beyond the above. This is a backend-only change; no admin console
or other rendered surface was touched.
Proof it works
All five acceptance stories were exercised at runtime against the real store,
reconciler, notify buses, and
/v1/admin/slack-installationhandlers, with thepre-fix modules run side by side over the same idle window as the "before" baseline.
qm46-runtime-proof.ts—.io-agent-qm-46/proof/runtime-proof.out—.io-agent-qm-46/proof/baseline-slack-installation.ts—.io-agent-qm-46/proof/baseline-slack-runtime.ts—.io-agent-qm-46/proof/