mirror of
https://github.com/go-admin-team/go-admin.git
synced 2026-09-22 18:37:43 +00:00
The budget is one number in config/settings.yml. The deadlines that have to cover it are in four other files, none of which anybody edits while thinking about shutdown - so raising the budget passes every test, deploys, and has the cleanup callbacks killed on the next release. Two checks share one arithmetic and one five-second margin. shutdown-budget-overruns-grace compares preStop + drain + server + cleanup against terminationGracePeriodSeconds in the shipped manifest. Those two files are not merely adjacent examples: scripts/k8s/prerun.sh builds the settings-admin ConfigMap out of config/settings.yml and the Deployment mounts it, so the manifest deploys that file. docker-stop-cuts-shutdown-short covers the three ways this container is stopped: `docker stop` in the release workflow, the same in the Makefile, and stop_grace_period on a compose service that runs this repository's own image. A service running a database is not this process and is left alone. The duration is parsed rather than scanned for digits - compose accepts 1m30s, and reading the first number out of it would call ninety seconds one. All three spellings of the deadline are read: --timeout, the deprecated --time, and the short -t. A deadline the check cannot read is reported as no deadline at all, so recognising only one of them would call a correct command broken and send whoever fixed it towards the spelling docker is retiring. The message quotes the flag back in the spelling it was written in, for the same reason: suggesting a flag the line does not use is how a tool teaches people to disbelieve it. What neither covers is `docker rm -f`, which has no deadline to compare against: it is SIGKILL by definition. That gap is deliberate, and it is why the previous commit changed the one place that used it on a container that might still be running. Both report at two levels. A budget that already overruns is an ERROR; one that fits with nothing to spare is a WARN, because it works today and failing the build on a working configuration is how a project teaches people to ignore its warnings. The two are exclusive: an overrun satisfies the headroom condition as well, and an ERROR that always drags a duplicate WARN behind it teaches the same lesson. preStop is in the sum although the shipped manifest has no hook. That is the point - a hook added later is spent before the process is told anything, and a self-check that could not see it would understate the real budget by however long somebody set it to, which is worse than not checking. A hook whose duration cannot be read is reported rather than counted as zero. The fallbacks for fields the settings file leaves out are read from the constants in the scanned tree, not copied here; if they are renamed the run stops instead of going quiet with the wrong numbers. The wording differs by audience on purpose. At run time this is somebody else's deployment under constraints the process cannot see, so the log states a minimum. These checks read files this repository owns, where there is standing to ask for headroom, so they name a target. The table in AGENTS.md is relisted while it is being touched: the two new checks, plus datascope-route-unguarded, which has been missing since it was added. The hard-coded count is gone - it said seven and there were ten, which is what a written-down count does. AGENTS.md and docs/contract.md both sent readers to `go run ./tools/checksilent -h` for the list of checks; that prints command-line flags and has never printed a check, so both now point at runChecks. The yaml parser moves from an indirect requirement to a direct one - it was already in the module graph - and tidy drops four go.sum lines left over from two older releases of core.