Skip to content

feat: migrate PlanProof verification to zero-idle Cloud Tasks architecture - #1

Merged
NikhilRaikwar merged 6 commits into
mainfrom
cost-hardening-zero-idle
Sep 24, 2026
Merged

NikhilRaikwar merged 6 commits into
mainfrom
cost-hardening-zero-idle

Conversation

@NikhilRaikwar

Copy link
Copy Markdown
Owner

What changed

  • Replaced Redis-backed/persistent verification dispatch with MongoDB durable outbox + Google Cloud Tasks.
  • Added scale-to-zero private Cloud Run verification worker (min-instances=0, max-instances=1, concurrency=1, timeout=1800s).
  • Added execution-generation task naming (run-<run_id>-g<gen>) for deterministic deduplication across HUMAN_WAIT pauses and resumes.
  • Added claim leasing (120s duration), periodic heartbeat renewal, stale-generation fencing, and retry-safe execution (503 Service Unavailable with Retry-After: 15 on active unexpired leases).
  • Moved quota counters and reservation state to MongoDB with atomic transactions and TTL indexes.
  • Added API vs. worker runtime-role isolation via PLANPROOF_RUNTIME_ROLE (api vs. worker), failing closed on unknown roles.
  • Added Google Cloud IAM OIDC bearer token authentication with strict audience verification on internal task routes.
  • Added explicit 1800s Cloud Tasks dispatch deadline (dispatch_deadline = 1800s).
  • Added Cloud Scheduler periodic outbox recovery (/internal/tasks/process-outbox) for orphan recovery.
  • Removed active Redis dependency from Cloud Run API and deleted Memorystore Redis instance.
  • Updated frontend authentication integration with bearer token sessions and comprehensive documentation updates.

Production validation

Run ID: 375a0873-1fd5-4172-a025-19510cc03d6a
Task: run-375a0873-1fd5-4172-a025-19510cc03d6a-g0
Final domain result: INCONCLUSIVE
Worker execution: confirmed
Mongo persistence: confirmed
Redis-free API health: confirmed

Clarification: INCONCLUSIVE is a valid, correct domain verification result reflecting bounded lexical search without false positives, not an infrastructure or worker execution failure.

Infrastructure state

  • Memorystore Redis (planproof-redis) removed and decommissioned.
  • No persistent worker pool remains.
  • Verification worker configured with min-instances=0 (scale-to-zero).
  • Cloud Tasks queue (planproof-verification-queue) and Cloud Scheduler active.
  • Cloud Router (planproof-router), Cloud NAT (planproof-nat), and static external IP (34.93.153.36) deliberately retained for MongoDB Atlas access.
  • Near-zero idle verification execution cost (standard baseline Google Cloud platform service usage applies).

Validation

Current pre-merge quality gates passing cleanly on cost-hardening-zero-idle:

  • Pytest: 122 passed, 20 deselected, 19 warnings in 34.69s (Exit Code: 0)
  • Ruff: All checks passed! (Exit Code: 0)
  • Secret Scan: Secret scan passed: no tracked credential patterns detected. (Exit Code: 0)
  • TypeScript: tsc --noEmit passed (Exit Code: 0)
  • Next.js Production Build: All 16 routes optimized and compiled cleanly (Exit Code: 0)
  • Playwright UI: 6 passed (56.0s) (Exit Code: 0)
  • Git diff check: Clean (Exit Code: 0)

Safety

  • NAT, VPC, and MongoDB Atlas IP access lists remain completely unchanged.
  • Zero secrets, connection strings, or private credentials included.
  • Main branch is untouched and not yet merged.

…able MongoDB outbox

- Replace Redis queue transport with Google Cloud Tasks serverless dispatch
- Implement durable outbox pattern in MongoDB with run_dispatch_outbox collection
- Introduce monotonic execution generations (run-<id>-g<gen>) for safe task deduplication across HITL resume
- Add atomic MongoDB execution lease claiming, expiration fencing, and periodic heartbeats
- Implement multi-period quota buckets and atomic reservation tracking in MongoDB
- Add PLANPROOF_RUNTIME_ROLE (api vs worker) to partition public vs internal routes
- Implement fail-closed runtime startup on invalid role configuration in production
- Require Google Cloud IAM OIDC bearer authentication with target audience validation on internal worker endpoints
- Configure Cloud Tasks dispatch with explicit 1800s deadline matching Cloud Run timeout
- Bind frontend API requests to server-side authentication sessions with credentials inclusion
- Update GitHub app connection routes and workspace navigation to respect session states
- Configure security headers and caching policies in next.config.mjs and firebase.json
- Add comprehensive unit tests for Cloud Tasks dispatch deadline and task naming
- Test role-based route isolation for api vs worker and fail-closed boot behavior
- Test OIDC audience verification and invoker service account authorization
- Test execution claim leasing, expiration fencing, and retryable 503 responses
- Validate Redis-free boot and /health/ready check asserting mongo=ok and queue=cloud_tasks
… decommission

- Update architectural diagrams and descriptions for Cloud Tasks and scale-to-zero worker
- Document real production E2E proof run (375a0873-1fd5-4172-a025-19510cc03d6a)
- Document Redis decommission status and near-zero idle verification execution cost
- Update GCP deployment runbook with exact queue and scheduler targets
- Clarify lexical retrieval boundaries and obligation counting logic
@NikhilRaikwar
NikhilRaikwar merged commit 9a9d7d9 into main Sep 24, 2026
4 checks passed
@NikhilRaikwar
NikhilRaikwar deleted the cost-hardening-zero-idle branch September 24, 2026 20:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant