29 lines
1.1 KiB
Markdown
29 lines
1.1 KiB
Markdown
# ADR-0034: Retention and dependency-aware cleanup
|
|
|
|
## Status
|
|
|
|
Accepted in M12 on 2026-08-26.
|
|
|
|
## Context
|
|
|
|
Unused-looking model bytes may still back a deployment, rollback, evaluation, project, migration or
|
|
another node. Immediate deletion after promotion destroys recoverability and provenance.
|
|
|
|
## Decision
|
|
|
|
RetentionPolicy is revisioned; prior stable targets receive a minimum rollback window. Deprecation,
|
|
archive and physical removal are separate. Cleanup always begins with a dependency-digest dry-run,
|
|
requires explicit operator execution and rechecks dependencies transactionally. Location removal is
|
|
node-specific and records prior facts; metadata/provenance remain.
|
|
|
|
## Consequences
|
|
|
|
Storage recovery may be delayed by valid dependencies or retention. Cleanup races return stale/409
|
|
instead of deleting. Multiple node copies are reconciled independently and audit remains queryable.
|
|
|
|
## Rejected alternatives
|
|
|
|
- Age-only automatic cleanup: cannot see active or rollback dependencies.
|
|
- Cascading deletes: erases evidence and makes blast radius implicit.
|
|
- Treating one removed location as global deletion: is incorrect in a multi-node registry.
|