refactor(ic-admin): [CON-1637] halt a subnet without necessarily provisioning SSH keys#9780
refactor(ic-admin): [CON-1637] halt a subnet without necessarily provisioning SSH keys#9780pierugo-dfinity wants to merge 3 commits intomasterfrom
Conversation
…ingSubnetBackOnlineAfterRepairs
| admin_helper: &AdminHelper, | ||
| subnet_node: &IcNodeSnapshot, | ||
| subnet_id: SubnetId, | ||
| keys: &[String], |
There was a problem hiding this comment.
I removed this argument just for consistency with the signature of unhalt_subnet because it was not used anyways. If we'd ever want to set some keys while halting the subnet, we could re-introduce the argument at that moment.
There was a problem hiding this comment.
This pull request changes code owned by the Governance team. Therefore, make sure that
you have considered the following (for Governance-owned code):
-
Update
unreleased_changelog.md(if there are behavior changes, even if they are
non-breaking). -
Are there BREAKING changes?
-
Is a data migration needed?
-
Security review?
How to Satisfy This Automatic Review
-
Go to the bottom of the pull request page.
-
Look for where it says this bot is requesting changes.
-
Click the three dots to the right.
-
Select "Dismiss review".
-
In the text entry box, respond to each of the numbered items in the previous
section, declare one of the following:
-
Done.
-
$REASON_WHY_NO_NEED. E.g. for
unreleased_changelog.md, "No
canister behavior changes.", or for item 2, "Existing APIs
behave as before.".
Brief Guide to "Externally Visible" Changes
"Externally visible behavior change" is very often due to some NEW canister API.
Changes to EXISTING APIs are more likely to be "breaking".
If these changes are breaking, make sure that clients know how to migrate, how to
maintain their continuity of operations.
If your changes are behind a feature flag, then, do NOT add entrie(s) to
unreleased_changelog.md in this PR! But rather, add entrie(s) later, in the PR
that enables these changes in production.
Reference(s)
For a more comprehensive checklist, see here.
GOVERNANCE_CHECKLIST_REMINDER_DEDUP
No canister behavior changes.
This PR changes the arguments
ssh_readonly_accessandssh_node_state_write_accessinic-admin'sProposeToTakeSubnetOfflineForRepairsCmdcommand to be optional. This allows to halt the subnet without provisioning SSH keys as suggested in the PR introducing the command. This allows to replace all halting commands inic-recoverywith this one. This PR also addresses Leo's other comments in the linked PR.Behavioural changes/remarks:
ic-admin, this is still possible through a direct call to the governance canister'sSetSubnetOpereationalLevel).Unhaltstep will clear the list instead of overwriting it with a singleton empty string (this is actually an interesting artifact that you can deduce that a subnet was previously recovered by checking whether itsSubnetRecord::ssh_readonly_accessfield is[""]instead of[]).subnet_splitting.rs. This is actually probably the intended effect, which ensures that the SSH readonly key that was deployed to the subnet is cleared.