Skip to main content
Version: 1.3.0

Dry-run and emergency stop

Effective dry-run is resolved from deployment configuration and durable database settings.

effective dry-run = emergency stop OR (UI override value if unlocked, otherwise deployment dry-run)

If effective dry-run is true, no destination write client is resolved for Apply.

Deployment defaults​

  • RECONCILE_DRY_RUN defaults to true.
  • RECONCILE_DRY_RUN_UI_OVERRIDE defaults to false.
  • The Helm chart uses the same safe defaults.
  • The standalone evaluation stack unlocks the UI override so write paths can be exercised locally.

The one-way emergency stop​

From the Infrastructure Runtime safety pane an administrator can trigger Emergency stop, which forces dry-run. The setting is persisted in PostgreSQL as force_dry_run and always wins — including over an unlocked UI override. Release emergency stop lifts it again.

Recovery is an explicit database operation in production

The persisted force_dry_run row survives a pod restart and redeployment. When the UI override is locked, the console cannot clear it — there is no Release emergency stop button. After resolving the incident, a database administrator must deliberately remove the force_dry_run setting row through the approved change process.

Runtime safety controls​

The Runtime safety pane shows only the controls that apply to the current state; each carries a plain-language note beside it.

ControlEffect
Emergency stopImmediately forces dry-run and holds it until released; survives a redeploy
Release emergency stopLifts the emergency stop, so apply returns to the prior setting (requires the UI override unlocked)
Go liveTurns dry-run off through the UI override, so the next reconcile applies real changes — including a bounded autonomous grow in auto mode
Return to dry-runTurns the UI override back to simulation
Clear manual overrideStops using the UI choice; apply follows the deployment configuration instead

The button labels changed in 1.3.0 (the former "kill switch" is now Emergency stop); the endpoints, the persisted force_dry_run setting, and the resolution rules above are unchanged.

Safe enablement sequence​

  1. Leave deployment dry-run true and the UI override locked.
  2. Complete a clean observation and review all proposals.
  3. Back up PostgreSQL.
  4. Change deployment dry-run only through a reviewed deployment change.
  5. Watch the next reconcile and audit log.
  6. Use Emergency stop immediately if mutation must stop.