CI Guardrails – Planetary Orchestrator Fabric v0
This demo ships with a dedicated CI workflow to check changed planetary demo code on pull requests and main. A passing run supports the tested scenarios; it is not a production certification.
Workflow Summary
- Location:
.github/workflows/demo-planetary-orchestrator-fabric.yml - Triggers:
- Any change beneath
demo/Planetary-Orchestrator-Fabric-v0/** - Dependency updates (
package.json,package-lock.json) - Manual runs via
workflow_dispatch
- Any change beneath
- Environment: Hardened Ubuntu 24.04 runner with outbound network locked to the declared GitHub, npm and Python dependency endpoints.
Job Stages
- Checkout & Hardening – Uses
step-security/harden-runnerto freeze outbound egress except the allowlist. - Dependency Sync –
npm ciensures deterministic dependency graphs. - Recovery and computer-work regressions – Run the Node regression suite and five Python checks, including the real adapter against an authenticated local fixture. No live provider is called.
- Type Safety –
npx tsc --noEmitvalidates the demo sources compile without generating JS. - Unit Tests –
npm run test:planetary-orchestrator-fabricexecutes deterministic simulations verifying shard balance, node failover (<2% drop), checkpoint resume, and the automated restart drill. - Demo Execution –
npm run demo:planetary-orchestrator-fabric:ciruns the fabric end-to-end in CI mode, producing reports underreports/ci-latest. - Acceptance Autopilot –
npm run demo:planetary-orchestrator-fabric:acceptance -- --label ci-acceptance --jobs-high-load 4000 --outage-node mars.gpu-helionproves the <2% drop rate and restart recovery criteria. - Artifact Validation – Node scripts ensure
summary.json,events.ndjson,dashboard.html, andowner-script.jsonexist and contain required sections.
Branch Protection
Add the following required status checks to the repository settings:
demo-planetary-orchestrator-fabric
With this in place, no pull request touching the demo can merge without a green, reproducible run.
Local Verification
Run the same steps locally:
npm ci --no-audit --prefer-offline --progress=false
npx tsc --noEmit --project demo/Planetary-Orchestrator-Fabric-v0/tsconfig.json
npm run test:planetary-orchestrator-fabric
npm run test:planetary-orchestrator-fabric:regressions
python -m pytest demo/Planetary-Orchestrator-Fabric-v0/tests/test_simulation.py -q
npm run demo:planetary-orchestrator-fabric:ci
# Optional: run the combined acceptance suite locally
npm run demo:planetary-orchestrator-fabric:acceptance -- --label local-acceptance
# Optional: replay the curated blueprint during acceptance
npm run demo:planetary-orchestrator-fabric:acceptance -- --label local-blueprint --jobs-blueprint demo/Planetary-Orchestrator-Fabric-v0/config/jobs.blueprint.example.json
# Optional: rehearse the restart drill locally
demo/Planetary-Orchestrator-Fabric-v0/bin/run-restart-drill.sh --label ci-drillDeliverables Captured by CI
| File | Purpose |
|---|---|
reports/ci-latest/summary.json |
Throughput, recovery, deterministic seeds |
reports/ci-latest/events.ndjson |
Event-by-event telemetry |
reports/ci-latest/dashboard.html |
Rendered mission control dashboard |
reports/ci-latest/owner-script.json |
Replayable owner command payloads |
reports/ci-latest/mission-chronicle.md |
Executive briefing with metrics, interventions, and resilience signals |
reports/ci-latest/mission-topology.mmd & mission-topology.html |
Planetary mermaid atlas for shard, node, and spillover visualization |
storage/checkpoint.json |
Most recent checkpoint snapshot |
These checks validate the simulator and allocation task. Record hosted CI results for the exact pull-request commit and commission production integrations separately. Browser checks can be run with node --import tsx demo/Planetary-Orchestrator-Fabric-v0/tests/browser-qa.cjs after installing Playwright Chromium.