feat: reconcile dynamic capacity lifecycle hardening - #24
Merged
Conversation
Jordanmuss99
marked this pull request as ready for review
August 18, 2026 03:37
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This pull request supersedes #22 and #23 without rewriting either published branch.
It rebases the complete Paymenter 1.5.7 reservation, upgrade, and lifecycle
remediation onto the reviewed inventory, test-isolation, and Wiki work from
#23.
PterodactylInventoryService;customer-safe errors;
NodeCapacityPolicy, zero-as-unlimited rejection, durable checkoutand upgrade commitments, and Paymenter-owned provisioning transitions;
encrypted storage;
:temporary:SQLite test database with child-processisolation and permits the shared
paymenter_testdatabase only through aloopback MySQL/MariaDB connection;
action and MariaDB service image to immutable commits or digests;
DNS answers at send time, disables redirects and proxies, and pins the
connection to a validated address, including rejection of deprecated
site-local, IPv4-compatible, ORCHID, and current IANA non-public IPv6 space;
delivery history, and failure events;
retaining the HTTP status for diagnosis;
historical, and publishes the reconciled canonical architecture to the
standalone Wiki.
accidentally tracked despite the repository ignore rule.
Required companion
This extension branch must ship with
ObsidianNetwork/Paymenter-Obsidian-Network#24 at
d58ab220998947cbb05b3806484a69ed7a419def. Do not merge or deploy theextension by itself.
Verification
success=trueandnode_count=1; the temporary/tmpharness was removed.pages are explicitly historical, and source links are pinned to immutable
code checkpoints.
process-private SQLite test database.
security, and context/history all passed at
c8dcbb6f538b1d05fc569c9d73d3cf2868069ba0.3aee81b36b2e6a443d85897779ffa489887367a0adds only the Pint formatting correction found by the pull-request event;
its complete seven-job pull-request matrix passed.
Deployment state
No production deployment is included. All Mutagen sessions remain paused and
disconnected. Deployment requires backups, both repositories' migrations,
per-node capacity policies, confirmed exclusive provisioning control, a
successful real-panel staging lifecycle canary, and separate authorization.