Sentinel Set 13E — End-to-End Migration Orchestrator
Set 13E turns the independent node-local migration mechanisms into one crash-resumable transaction. It does not replace the VMM migration engine or Zyvor Fabric's distributed placement/intent.
Transaction
- preflight + exclusive journal lock;
- quiesce new VM flows;
- export conntrack/flow/drop state and optional QUIC CID affinity;
- stop AF_XDP and rollback temporary topology/sched_ext steering on source;
- execute the configured VMM migration argv;
- restore network/QUIC state on destination;
- apply destination topology/sched_ext plans and AF_XDP;
- explicitly resume destination network state;
- seal
EVIDENCE.sha256and mark complete.
Each step is fsync'd to journal.json before the next begins. Re-running run or resume skips completed steps. Changing the plan after a transaction starts is rejected by its plan SHA-256.
Failure semantics
Before the VMM move completes, rollback rebuilds source auxiliaries before reopening source flows. After the VMM move completes, rollback requires explicit vmm.rollback_argv; without it the state becomes manual-intervention rather than guessing where the VM runs.
Security
No plan command uses shell=True; argv is an array; SSH is BatchMode with strict host-key checking by default; transfer paths are generated below /tmp/fluxvm-migrate-*; journals are 0700/0600; known secret flag values are redacted; observer HTTP binds loopback by default.
CLI
fluxvm-migrate validate plan.json
sudo fluxvm-migrate run plan.json
sudo fluxvm-migrate resume plan.json
sudo fluxvm-migrate rollback plan.json
fluxvm-migrate status <migration-id>
fluxvm-migrate reconcile --stale-minutes 15
fluxvm-migrate serve --listen 127.0.0.1:7797
Set 13E intentionally leaves leader election, placement, BGP/ECMP, storage replication and application consistency to their owning layers.