Skip to content

Execution: document running-pod convergence window + break-glass drain (layer 2) #27

Description

@Kenny-Heitritter

Parent

Map #16 · implements the layer-2 decision locked in #21 (running-pod refresh policy). Doc-only.

What to build

Capture the layer-2 policy in CODEQ_DEPLOYMENT.md so operators know what to expect and what levers exist. Layer 2 = passive convergence for routine updates; documented manual break-glass for security-critical; no in-Lab banner, no automated drain.

Document:

  1. The expected convergence window for routine updates — approximately the idle-cull timeout, plus the absolute max-server-lifetime cap if one is configured — as the convergence SLA.
  2. The security-critical break-glass drain runbook: who pulls the lever and the one-line step (force-stop stale singleuser pods via JupyterHub admin "stop server" or kubectl delete pod → each user re-logs into a fresh pod on the patched image).

Full spec: #21.

Acceptance criteria

  • CODEQ_DEPLOYMENT.md states the routine-update convergence window (idle-cull timeout + max-server-lifetime cap) as the convergence SLA.
  • It documents the security-critical break-glass drain: who runs it and the one-line runbook step.
  • It records that there is deliberately no in-Lab banner and no automated drain.

Blocked by

Metadata

Metadata

Assignees

No one assigned

    Labels

    ready-for-agentTicket is scoped and ready for an agent to grab and implement

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions