Dry-run and emergency stop
Effective dry-run is resolved from deployment configuration and durable database settings.
effective dry-run = emergency stop OR (UI override value if unlocked, otherwise deployment dry-run)
If effective dry-run is true, no destination write client is resolved for Apply.
Deployment defaults
- RECONCILE_DRY_RUN defaults to true.
- RECONCILE_DRY_RUN_UI_OVERRIDE defaults to false.
- The Helm chart uses the same safe defaults.
- The standalone evaluation stack unlocks the UI override so write paths can be exercised locally.
The one-way emergency stop
From the Infrastructure Runtime safety pane an administrator can trigger Emergency stop,
which forces dry-run. The setting is persisted in PostgreSQL as force_dry_run and always wins —
including over an unlocked UI override. Release emergency stop lifts it again.
The persisted force_dry_run row survives a pod restart and redeployment. When the UI override is
locked, the console cannot clear it — there is no Release emergency stop button. After resolving
the incident, a database administrator must deliberately remove the force_dry_run setting row
through the approved change process.
Runtime safety controls
The Runtime safety pane shows only the controls that apply to the current state; each carries a plain-language note beside it.
| Control | Effect |
|---|---|
| Emergency stop | Immediately forces dry-run and holds it until released; survives a redeploy |
| Release emergency stop | Lifts the emergency stop, so apply returns to the prior setting (requires the UI override unlocked) |
| Go live | Turns dry-run off through the UI override, so the next reconcile applies real changes — including a bounded autonomous grow in auto mode |
| Return to dry-run | Turns the UI override back to simulation |
| Clear manual override | Stops using the UI choice; apply follows the deployment configuration instead |
The button labels changed in 1.3.0 (the former "kill switch" is now Emergency stop); the
endpoints, the persisted force_dry_run setting, and the resolution rules above are unchanged.
Safe enablement sequence
- Leave deployment dry-run true and the UI override locked.
- Complete a clean observation and review all proposals.
- Back up PostgreSQL.
- Change deployment dry-run only through a reviewed deployment change.
- Watch the next reconcile and audit log.
- Use Emergency stop immediately if mutation must stop.