Skip to content

feat(models): CROW_DISABLE_MODEL_ORCHESTRATION — a host that never starts, stops or evicts a model - #387

Merged
kh0pper merged 11 commits into
mainfrom
feat/raven-instance-no-orchestration
Sep 24, 2026
Merged

kh0pper merged 11 commits into
mainfrom
feat/raven-instance-no-orchestration

Conversation

@kh0pper

@kh0pper kh0pper commented Sep 24, 2026

Copy link
Copy Markdown
Owner

Why

raven, the second Strix Halo box, is about to join the fleet as a paired Crow instance. Its production model engine (halogen, flash-next.service) is owned by systemd and by pi-lab's windows, never by Crow.

Today a gateway is kept from orchestrating a model only by per-row gates. On raven, any synced provider row whose base_url is raven's own LAN address would count as local there. So this PR adds a host-level switch.

What

When CROW_DISABLE_MODEL_ORCHESTRATION=1 is set (only 1/true, trimmed, any case; 0, empty or unset leave behaviour unchanged):

  • Orchestrator entry points:
    • maybeAcquireLocalProvider and resolveWarmableProviderName return null;
    • acquireProvider throws OrchestrationDisabledError before any probe or start;
    • ensureResident, retryDeferredResidents and checkIdleRevert are no-ops;
    • the new bootResidency(), extracted from initOrchestrator, logs one DISABLED line and arms no idle-revert timer.
  • Lowest-level primitives: bundleUp, bundleStop and startNativeAndAwaitReady throw too (defence in depth).
  • Model bundles: a bundle with inference, requires.gpu, requires.gpu_arch, providers[] or an STT/TTS seed (13 bundles today) gets 409 MODEL_ORCHESTRATION_DISABLED on install, start, stop, uninstall or shared-storage apply, including starts a peer forwards.
  • Models panel: Start returns 409 MODEL_ORCHESTRATION_DISABLED, the runtime strip shows a translated notice (en/es), and /api/models/runtime carries orchestrationDisabled.
  • meta-glasses: its direct acquireProvider call skips the new error quietly. The version is bumped to 0.1.1 and the registry regenerated.
  • Unchanged under the switch: the read-only residency and external-engine polls still run, and model downloads are not gated.
  • Docs: configuration.md, architecture/models.md, and a new raven: namespace in port-allocation.md (gateway raven:3009, loopback-only behind Serve raven:8444).

No behaviour change on existing hosts

The env var is unset on crow, r4, grackle and black-swan. Every added check returns immediately when it is off. The bootResidency extraction was reviewed as behaviour-identical: same order, same _deferredResidents set, the timer armed on both paths. scripts/run-suite.mjs deletes the env var so the suite always runs with the switch off.

Process

  • Spec: docs/superpowers/specs/2026-09-24-raven-instance-no-orchestration-design.md
  • Plan: docs/superpowers/plans/2026-09-24-raven-instance-no-orchestration.md. It took 3 rounds of adversarial review. Round 1 found the ungated model-bundle routes and a vacuous warm test; round 2 found ollama/localai missing from the predicate and a vacuous ensureResident test.
  • Build: subagent-driven, 5 tasks, each with a spec and quality review. The final whole-branch review returned Ready; its two doc/comment minors were fixed and re-reviewed.
  • Tests: full suite 5122 pass / 0 fail (Node 24). check-port-allocation and build-registry --check are green.

Follow-ups (not in this PR)

  • Hide or disable the Models panel's Start button when the switch is on. Today clicking it returns a clean, translated 409.
  • The source-scan tests search a fixed window of the source and are brittle.
  • Making the port checker host-aware.

@kh0pper
kh0pper merged commit 5818470 into main Sep 24, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant