Repository navigation
Add bounded operator dashboard and release Server 2.5.3 - #305
Merged
Merged
Conversation
This was referenced Oct 6, 2026
rmcdaniel
marked this pull request as ready for review
October 6, 2026 18:26
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Supports durable-workflow/waterline#141 and durable-workflow/workflow#628.
Add
GET /api/system/operator-dashboard/boundedbeside the existing auditendpoint. It uses the same operator authentication, control-plane version and
namespace boundaries. Native's bounded dashboard returns aggregate data without
fleet-wide history audits. Unevaluated audit counts stay null with
history_audit_evaluation: not_requested. The existing dashboard and metricsendpoints retain full audits.
The bounded response includes namespace capacity evidence, so Waterline can
evaluate capabilities from the same response without a subsequent full audit.
Pin published Native 2.4.3 and prepare Server 2.5.3 / Helm 0.1.140 with the
repository's release synchronizer. The installed dependency names exact source
8fcfb002de337e341ef19e601d73e9e1424e09ec. The affected metrics/version suitepasses 349 cases / 1,441 assertions with zero skips on PHP 8.3.35, with six
existing PHPUnit configuration deprecations. No Native source override is used.
Merged at
2281e641d9035a1acd6d59e0154d44e720dfbed5, preserving qualified tree13afdd261dc4c5b90c044472a8f603aeff6b6d58. All final PR and main gates pass,including polling growth, MySQL/PostgreSQL rolling, HTTP replay/query and Helm
installation. The merged branch was deleted and verified absent.
Server 2.5.3
and chart 0.1.140 are published. Release verification
passes source-free Compose, first startup, rolling aliases and anonymous chart
installation. Both registries expose the same amd64/arm64 index:
sha256:7c62b388802dda1922ada0a920ea8335c6a05ed3638741137cea4c8ba228bf22.A fresh published PHP SDK 2.2.1 consumer passes all 13 real HTTP checks against
that digest: bounded single read, namespace isolation, null deferred counts,
ordinary full-audit compatibility and invalid-token refusal.
Published lifecycle verification
passes all 12 cells with Native 2.4.3, PHP SDK 2.2.1, Python SDK 2.4.0,
Rust SDK 3.2.0, CLI 2.2.0 and Waterline 2.1.0, with no findings.
The supporting PHP SDK 2.2.1 helper is published. Waterline must opt into this
route only when its SDK and Server can provide it, preserving older observers
and displaying unevaluated audits as unknown. This does not complete #141's
classification filters, bounded selected details or failure-event references.