Skip to content

Add observers remove, and fix clear-quarantine and retry-partition - #188

Merged
einari merged 5 commits into
mainfrom
feature/observer-remove-and-fixes
Sep 25, 2026
Merged

einari merged 5 commits into
mainfrom
feature/observer-remove-and-fixes

Conversation

@einari

@einari einari commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Added

  • chronicle observers remove — removes an observer whose declaring code is gone (a deleted read model and projection, or a removed reactor), clearing its definition, state, handled counts and failed partitions across every namespace of the event store. Asks for confirmation first, stating what is deleted, that it reaches every namespace, that read models and their data are left alone, and that it cannot be undone. The kernel refuses while the observer is running or a client is still subscribed to it, and the command reports that refusal rather than reporting success.

Fixed

Changed

  • Chronicle bumped from 18.1.0 to 19.6.1 to pick up RemoveObserver and the RetryPartitionResponse outcome

…ection

clear-quarantine has never worked against a real kernel. It resolved
ClearObserverQuarantine with Type.GetMethods() on the client, and the client
protobuf-net.Grpc generates implements IObservers explicitly - GetMethods()
does not return explicitly implemented members, so the lookup found nothing
and the command reported that it could not clear the quarantine. Calling the
interface method directly lets the compiler bind it.

The specifications that covered this passed throughout, which is why it
shipped: they ran against a substitute, and Castle's proxy implements the
interface implicitly, so reflection found the method there and only there.
The double disagreed with the real client on the one property the command
depended on.

They are replaced with specifications that run against a double implementing
IObservers explicitly, like the generated client does. Restoring the
reflection lookup now turns those specifications red.

Fixes #185
… it started

retry-partition awaited the call and then printed that the retry had started,
whatever came back. The kernel declines outright in three cases - the observer
is quarantined, so recovery is paused by design; the partition is individually
quarantined; the partition is not among the observer's failures - and in each
of them the command told the operator to go and watch progress that was never
coming.

The kernel already reports which of those it did on RetryPartitionResponse, so
the command now reads the outcome, says what happened, and exits non-zero when
nothing was started. A script can no longer take silence for recovery.

Fixes #186
A deleted read model and its projection, or a removed reactor, leaves its
definition, state, handled counts and failed partitions in the event store
with nothing left to claim them and no supported way to clear them.

The command asks first, and says what it is about to do: what is deleted, that
it reaches every namespace of the event store, that read models and their data
are left alone, that it cannot be undone, and that a re-registered observer
starts over from the beginning of the sequence - which is the distinction from
a replay, and what an operator reaching for this may actually have meant.

The kernel refuses while the observer is running or a client is still
subscribed to it, so the command reports the refusal and exits non-zero rather
than leaving the impression that the store was cleaned up.
Cratis.Chronicle.Connections, .Contracts and .XUnit.Integration move from
18.1.0 to 19.6.1, the first release carrying RemoveObserver and the
RetryPartitionResponse outcome this branch already builds against.

19.5.0 exists as a release tag but was never published - the packages broke
consumer startup for an existing external IEventStore implementation, caught
and fixed in Chronicle before anything shipped (Cratis/Chronicle#4181). 19.6.1
is the first version after that fix actually reached NuGet.

The whole solution builds clean and 1656 specs pass, including the 24 new
ones written against the real contract types.
@einari einari added the minor New features, non-breaking additions label Sep 25, 2026
This asserted the exact bug #186 fixed: given a partition key that was never
a real failure, it expected "Retry started" and a zero exit code regardless -
which is what the command used to say no matter what the kernel answered.
Against the live server it now correctly asserts the refusal: a validation
exit code, no false claim of a started retry, and the kernel's own message on
stderr, where WriteError actually places it.
@einari
einari merged commit fe53183 into main Sep 25, 2026
9 of 10 checks passed
@einari
einari deleted the feature/observer-remove-and-fixes branch September 25, 2026 13:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

minor New features, non-breaking additions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant