feat(traffic): one-box traffic shifting — weighted router in front of production #404
No reviewers
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
gmackie/ForgeGraph!404
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/one-box-traffic"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Optional per-app one-box: a second Cloudflare Worker on the production stage (
<slug>-onebox) sharing production's database, secrets and resources, behind a ForgeGraph-managed router Worker. A production deploy lands on the one-box first, shifts a configurable slice of real traffic to it, bakes while comparing it against production on the same traffic, then promotes the primary and drains to zero — or drains to zero and fails.Apps that do not enable it are byte-for-byte unchanged.
Phases 1–7c of the plan. Phase 8 (verification suites) follows in a separate PR.
Engineering review
/plan-eng-reviewran against this stack and found 6 issues, 2 of them critical gaps (silent failure, no test, no handling). All were fixed before landing — details in the plan's "Engineering review findings" section. The two that matter most:withLaneHeaderdidnew Response(res.body, res), which rejects status 101 and drops thewebSockethandle. Enabling the router at all would have broken any WS app. The idle path is now a true passthrough returning the upstream response untouched — which is what the plan claimed it already was.MIN_REQUESTS_FOR_VERDICT(100) requests, every metrics tick returnsinsufficient-datawithok: true, so a quiet app auto-promoted on health-probe evidence alone and reported a clean bake. It still promotes (a low-traffic app must not hang forever) but is now recorded and surfaced as promoted without traffic evidence.Known gap
The lane override's query-param form is gone, and forced requests are marked upstream with
x-fg-lane-forced. Excluding that traffic from the bake verdict is not done:fg.laneis a resource attribute fixed at deploy, so exclusion needs a per-span attribute in@forgegraph/otelplus a ClickHouse filter, and only takes effect once apps upgrade. Today's verdict still counts header-forced traffic. Filed rather than half-built.Verification
go build ./...+go test ./...— greentsc --noEmit— clean forapps/web,packages/api,packages/dbvitest run— 174 web files / 1105 tests, 138 api files / 974 tests, all passingMigrations renumbered to 0092–0095 around the mise (#399) and worker-budget (#402) migrations that landed first.
🤖 Generated with Claude Code