Reliability › Audit (1.0 → 1.1)

Reliability audit: 1.0.0 baseline → 1.1.0

Every row was checked against the source, not the documentation. Before = NestLaravel 1.0.0. After = state at 1.1.0, with the automated evidence. A row is only marked COMPLETE when a test proves the behaviour; anything not proven is listed as PARTIAL / NEEDS TESTING with the reason. The full list of unproven items is in RELIABILITY.md § Remaining risks.

Legend: COMPLETE · PARTIAL · MISSING · UNSAFE (works but can lose/duplicate data or fail open) · NEEDS TESTING

#CapabilityBefore (1.0.0)After (1.1.0)Evidence
1CLICOMPLETECOMPLETE (+generate event, production:check, events:list/check, kafka:health, outbox:status, dlq:list, tenant:check, richer doctor)packages/cli/test/*.test.js (19 tests)
2Generated Laravel servicesCOMPLETECOMPLETE (health probes, metrics, inbox, structured logs)service feature tests
3Gateway auth + rate limitsPARTIAL (limiter store per instance)PARTIAL: state is in the shared cache; requires a shared CACHE_STORE for >1 replica (checked by production:check, documented)GatewayResilienceTest, ProductionChecker
4Gateway → service HMACPARTIAL (no rotation)COMPLETE: zero-downtime rotation (…_PREVIOUS), replay protection fails closed if the nonce store is downGatewaySignatureTest (per service)
5Timeouts / retries / circuit breakerMISSINGCOMPLETE for gateway → service (connect+total timeouts, error classification, safe-only retries, shared breaker, 502/503/504)ResilienceTest, GatewayResilienceTest
6Event envelope + schemasPARTIALCOMPLETE: event_version, causation/correlation inheritance, schema registry, compatibility gateSchemaGovernanceTest, OpsCommandsTest
7ProducerCOMPLETE (NEEDS TESTING vs broker)COMPLETE: real-broker produce → consume → DLQ in CIRdKafkaBrokerTest (CI job)
8Transactional outboxUNSAFE with >1 publisherCOMPLETE: atomic claim, backoff, stale recovery, lost-claim protection, DLQ copy, metrics. Ordering across several publishers is still not guaranteed (documented)OutboxReliabilityTest, ChaosScenariosTest
9Inbox / idempotencyUNSAFECOMPLETE (opt-in KAFKA_INBOX_ENABLED, on in the generated Compose stack): dedup + business writes atomic; multi-process race verified on PostgreSQL and MySQLInboxTest, ConcurrentInboxTest (CI, pgsql + mysql)
10Consumer pipelinePARTIALCOMPLETE: classification, no ack before success, DLQ failure ⇒ no commit, commit failure tolerated, broker backoffConsumerFailureTest, PipelineReliabilityTest
11Graceful shutdownNEEDS TESTINGCOMPLETE for consumer + outbox daemon on Linux (real SIGTERM in flight); HTTP drain is orchestrator config (manifests provided, not deployed by CI)GracefulShutdownTest (CI)
12Saga / workflowsMISSINGCOMPLETE for the orchestrated model (persisted, idempotent, timeouts, compensation, crash recovery); a failing compensation parks the saga for a humanSagaTest (12), CheckoutSagaTest
13Structured logsPARTIALCOMPLETE: JSON, correlation/trace/tenant ids, redaction (heuristic, documented)ObservabilityTest
14MetricsMISSINGCOMPLETE: Prometheus /metrics, token-protected, fails closed; cache-store dependentObservabilityTest, OperationsTest
15TracingMISSINGPARTIAL: W3C propagation through HTTP → events → consumers ✔; OTLP export verified against a fake collector onlyObservabilityTest
16HealthPARTIALCOMPLETE: liveness independent of dependencies, startup, readiness by HEALTH_REQUIRED, degraded /healthOpsEndpointsTest, service OperationsTest
17Gateway horizontal scalingNEEDS TESTINGPARTIAL: breaker/nonce/limiter state proven to live in the shared cache (not process memory); multi-replica behaviour itself not load-testedResilienceTest::test_breaker_state_is_shared_through_the_cache_not_process_memory
18Multi-tenancyPARTIALCOMPLETE for the tested paths (Eloquent, queues, events, logs, strict jobs, audit command); raw DB::table() bypasses scopes by design (documented)TenantPropagationTest, TenantCheckTest
19Secret handlingPARTIALCOMPLETE for service-to-service secret rotation; other secrets are operator-managed (documented)GatewaySignatureTest
20Database reliabilityMISSINGPARTIAL: statement timeout, Transactions::idempotent/once, migration guidance. No test against a real failoverDegradedModeTest, DegradedModeTest
21Redis failure modeUNSAFE (undefined)COMPLETE for the framework's own uses (defined degrade/fail-open/fail-closed per function); Laravel's Redis queue/session/rate-limit are still Redis-dependent unless you configure failover driversDegradedModeTest, GatewaySignatureTest
22DockerPARTIALCOMPLETE: stop_grace_period, structured logs, inbox on; image build in CICI "Docker images build + compose config"
23KubernetesMISSINGPARTIAL: reference manifests, schema-validated in CI; not deployed to a cluster by CICI "Kubernetes manifests are valid"
24CIPARTIALCOMPLETE for the listed suites: unit/feature (PHP 8.3, 8.4), real Kafka, pgsql + mysql concurrency, Linux signals, manifests, security audit, CLI on Node 20/22/24, clean-install E2E.github/workflows/ci.yml
25Disaster recovery docsMISSINGCOMPLETE as documentation (DISASTER-RECOVERY.md); restores can only be rehearsed by the operator–
26Production-readiness CLIPARTIALCOMPLETE as an audit (PASS/WARN/FAIL, fails soft when dependencies are down); it never certifies "production ready"OpsCommandsTest, ops.test.js
27Reference applicationMISSINGCOMPLETE as an in-process demonstration (REFERENCE-APP.md); not a deployable multi-service stackCheckoutSagaTest (7)
28Performance measurementsMISSINGPARTIAL: relative overhead measured on a laptop with SQLite; not capacity numbers (BENCHMARKS.md)OverheadBenchmarkTest (opt-in)

Design decisions taken from this audit are recorded in RELIABILITY.md.

Edit this page on GitHub