Live HTTP evidence transport, continuous Loop2 service, bounded auto failover trigger, runtime-managed frontend export, bounded replica repair, end-to-end RF2 handoff with continued I/O on new primary, bounded operator HTTP surface, and CSI V2 runtime backend adapter. 11 new proof tests covering the full M6-M10 chain plus CSI create/ lookup/publish through the V2 runtime path. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
4.4 KiB
V2 RF2 Runtime Bounded Envelope
Date: 2026-04-05
Status: draft
Purpose: freeze the bounded productionization envelope around the current
Phase 19 working RF2 block path without overclaiming broad product readiness
Reading Rule
This document defines the strongest bounded envelope currently justified by the
delivered Phase 19 path.
It does NOT mean:
- broad launch approval
- working block product approval
- support for broad frontend or transport matrices
- that remaining runtime/product gaps are minor polish
It means only:
- the current
masterv2 + volumev2 + purev2RF2 runtime slice has a named, reviewable productionization boundary - the current support statement, exclusions, and blockers are explicit
- later pilot or rollout work must stay inside this envelope or explicitly widen it with new evidence
Envelope Basis
This envelope is anchored on the delivered Phase 19 milestones:
M6: one live loopback HTTP transport now exists behind the evidence seamM7: one background Loop 2 service and one bounded auto-failover service now existM8: one runtime-managed iSCSI export path and one bounded replica repair wrapper now existM9: one end-to-end RF2 handoff proof now exists with continued I/O on the new primaryM10: one bounded operator surface and one bounded CSI runtime backend adapter now exist
The envelope is therefore about one bounded working RF2 block path, not broad product readiness.
Supported Envelope
The current bounded support statement is:
- one bounded working RF2 block path now exists with:
masterv2identity/promotion authorityvolumev2failover, takeover, active Loop 2 service, continuity, repair, frontend rebinding, and projected RF2 surface ownershippurev2execution adapter reuse
- one bounded live transport path now carries failover-time evidence and replica summaries
- one bounded real client handoff path now exists:
- write through runtime-managed iSCSI export
- bounded repair/catch-up on the runtime path
- lose primary
- auto fail over
- reconnect to the new primary
- continue I/O
- one bounded outward RF2 surface exists as projection only:
RF2VolumeSurface
- one bounded operator/CSI adapter layer exists on top of runtime-owned truth
Explicit Exclusions
The following are OUTSIDE this bounded envelope:
- broad multi-process or multi-host deployment approval
- broad transport/frontend matrix approval
- full rebuild orchestration beyond the current bounded repair/catch-up wrapper
- broad CSI lifecycle parity beyond the current bounded runtime backend adapter
- broad operator/API/metrics coverage beyond the current bounded HTTP surface
- broad launch or external customer support statements
Current Blockers
The main blockers between this envelope and a working RF2 block product are:
- the current path is still bounded to the current runtime harness rather than broad multi-process approval
- bounded repair/catch-up is not yet broad rebuild lifecycle closure
- CSI rebinding is still a bounded runtime backend adapter, not full lifecycle parity
- the operator surface is still a bounded HTTP view, not a full operational platform surface
Allowed Validation Shape
The allowed validation shape inside this envelope is:
- internal engineering validation only
- bounded lab/runtime exercise only
- explicit artifact-driven interpretation only
The following are NOT allowed interpretations:
- "the system is now production ready"
- "the system now supports real automatic failover"
- "the system now supports broad product traffic and rollout"
Evidence Anchors
Read this envelope together with:
sw-block/.private/phase/phase-19.mdsw-block/design/v2-kernel-closure-review.mdsw-block/design/v2-protocol-claim-and-evidence.mdsw-block/runtime/volumev2/runtime_manager.gosw-block/runtime/volumev2/continuity_runtime.gosw-block/runtime/volumev2/rf2_surface.gosw-block/runtime/volumev2/loop2_service.gosw-block/runtime/volumev2/frontend_runtime.gosw-block/runtime/volumev2/operator_surface.gosw-block/runtime/volumev2/poc_test.goweed/storage/blockvol/csi/v2_runtime_backend.go
Envelope Output
The correct current reading of this envelope is:
- runtime-bearing RF2 kernel slice: yes
- bounded working RF2 block path: yes
- bounded productionization artifact set: yes
- pilot-ready broad product path: no