Skip to content

High Availability

"High availability" here means the operational procedures that keep customer workloads running while hardware is serviced or fails: live migration, cold migration and node evacuation.

Hardware-unproven

The panel-side orchestration and capability gating are implemented and mock-tested. Real live migration, disk transfer, route moves and agent-side execution have not been tested on physical hardware in this deliverable. Treat HA moves as capability-gated but hardware-unproven.

The invariant

Whatever the mode, the source stays authoritative until a commit. Failures before the point of no return roll back; failures at or after it surface as RECOVERY_REQUIRED and are never auto-resolved by blindly restarting the source.