Parent epic: #82
Outcome
Provide a deterministic drain, fencing, replacement, and cold-migration state machine that preserves exclusive workspace-storage ownership and never permits two writable generations.
Execution
- Priority: P1 post-0.5 Full C recovery.
- Deployment profiles: Hosted required; customer-managed recovery contracts remain compatible where applicable.
- Worktree boundary: Drain/replacement/migration state, fencing, storage-ownership transitions, rollback, verified purge, recovery tooling, and representative two-node qualification hooks. Avoid transparent live migration.
Scope
- Make drain block new placement while existing lifecycle operations continue safely.
- Stop the runtime, fence the old generation, transfer or restore exclusive storage ownership, start and verify on the target, then commit the new workspace owner.
- Define explicit rollback before ownership cutover and deterministic recovery after an ambiguous cutover.
- Permit failed-node replacement only when old-generation fencing and exclusive storage attachment can be proven.
- Preserve workspace identity, tenant ownership, data, audit history, and generation-fenced purge semantics.
- Prevent the old node from serving or purging after ownership changes.
Non-goals
- Transparent live migration of an active desktop.
- Generic load balancing in front of stateful lifecycle calls.
- Declaring Auto Scaling replacement safe without fencing and exclusive storage transfer.
Definition of success
Parent epic: #82
Outcome
Provide a deterministic drain, fencing, replacement, and cold-migration state machine that preserves exclusive workspace-storage ownership and never permits two writable generations.
Execution
Scope
Non-goals
Definition of success
npm run verify:quickpass on the exact candidate SHA.