Identity and ownership
Immutable identity
A source volume is identified by volume UUID, never by name. Names are useful for operators and destination naming, but ONTAP can reuse them.
When the same name appears with a different UUID, DonkeyFleet does not treat it as the same volume
and never auto-remediates it, because the new volume may contain unrelated data. DonkeyFleet detects
this case automatically: a managed or drifted relationship whose stored source UUID has disappeared
but whose source name now resolves to a new UUID is marked drifted with the source_replaced
reason, kept out of orphan cleanup, and raised as a warning notification for an operator to verify.
Ownership states
| State | Meaning | Mutating eligibility |
|---|---|---|
| Managed | Created by DonkeyFleet, or adopted and explicitly bound to an automation profile | Eligible for destination actions according to its ownership and automation mode |
| Adopted | Existing relationship awaiting explicit automation ownership | Excluded by mutation queries |
| Suspended | Observed state is outside supported active states and is not an initializing baseline | Excluded by mutation queries |
Binding is the authorization boundary: it grants destination management only, while an unbound adopted relationship is excluded from every write at the query level.
Binding an adopted relationship to an automation profile moves it to managed without assigning a
replication profile or taking creation ownership. The binding authorizes destination fill/grow,
approval-gated tiering-policy alignment, and approval-gated orphan cleanup under that profile. Unbound adopted and suspended protection is
excluded at the database-query boundary, not by an easy-to-forget conditional inside an action.
Binding never authorizes source writes or automatic deletion. A baseline that is actively
initializing is not suspended even when ONTAP reports uninitialized and unhealthy.
Successful binding requests an immediate reconcile so the destination is evaluated under its new
automation ownership without waiting for the normal interval.
A bound relationship can be rebound to a different automation profile, or unbound to return it to adopted (mutation-excluded) — for example before decommissioning. Unbind is refused while an autonomous grow or an approved cleanup is still in flight, so an in-progress action is never orphaned; retry once it settles.
As of 1.1.0 the controller does not yet move relationships into or out of suspended: the state
and its query-level mutation exclusion are defined, but automatic health-based suspension of a
broken-off, quiesced, or paused relationship is planned, not yet implemented.
Destination ownership marker
Provisioned destination volumes carry a DonkeyFleet intent identifier in their ONTAP comment. That durable marker helps recovery after a process crash and distinguishes controller work from unrelated storage.