S3 run-state retention/lifecycle to bound operator run-index prefix growth
Summary
The gateway's operator run index reads run-state objects from S3 per repo. There is no retention policy on those prefixes, so they grow unbounded over a deployment's lifetime. Beyond storage cost, this has a correctness edge: listWithMetadata paginates with a bounded iteration cap and then sorts, so an extremely large per-repo run-state prefix can miss newer objects that fall beyond the iteration cap. An S3 lifecycle/retention policy that bounds prefix growth is the operational mitigation.
Where it comes from
Split out from fro-bot/agent#1036 (operator run-index scale follow-ups). The two code-side items in that issue shipped in fro-bot/agent:
The remaining item is this retention policy, which is infra-side (object-store lifecycle), not a gateway code change.
What's needed
- A lifecycle/retention rule on the run-state object prefixes in the gateway's S3 bucket that bounds how large any single per-repo prefix can grow (by age and/or count), so the gateway's bounded list pagination always sees the newest objects.
- Decide the retention window in light of how the operator run index is used (it returns at most the newest 100 across repos; very old run-state objects are not surfaced).
Acceptance
- Per-repo run-state prefixes are bounded so the gateway's
listWithMetadata pagination cannot miss newer objects behind the iteration cap.
- Storage growth is bounded over a long-lived deployment.
- The retention window is documented alongside the gateway deploy config.
Cross-reference
Closes out the last item of fro-bot/agent#1036.
S3 run-state retention/lifecycle to bound operator run-index prefix growth
Summary
The gateway's operator run index reads run-state objects from S3 per repo. There is no retention policy on those prefixes, so they grow unbounded over a deployment's lifetime. Beyond storage cost, this has a correctness edge:
listWithMetadatapaginates with a bounded iteration cap and then sorts, so an extremely large per-repo run-state prefix can miss newer objects that fall beyond the iteration cap. An S3 lifecycle/retention policy that bounds prefix growth is the operational mitigation.Where it comes from
Split out from
fro-bot/agent#1036(operator run-index scale follow-ups). The two code-side items in that issue shipped infro-bot/agent:The remaining item is this retention policy, which is infra-side (object-store lifecycle), not a gateway code change.
What's needed
Acceptance
listWithMetadatapagination cannot miss newer objects behind the iteration cap.Cross-reference
Closes out the last item of
fro-bot/agent#1036.