Hserver Failure Notes: Safe Automation · advanced

A Green Badge Needs an Expiration Time

Operational evidence should age out automatically rather than remaining green until someone notices it is old.

Current. Current engineering note based on recent hserver deployment, debugging, recovery, and production-hardening work in September 2026.

Observability evidence has a temporal scope. Freshness budgets are similar to cache TTLs: beyond the accepted age, the consumer must refresh rather than assume validity. The Command Center could display the last successful posture job indefinitely. During a later deployment, the same success badge might refer to evidence collected before several relevant changes.

The UI represented state but not validity duration. A PASS was being treated as a permanent property instead of a time-bounded observation.

Evidence policies now define maximum ages per job and calculate CURRENT, STALE, FAILED, IN_PROGRESS or NOT_RUN states for operator display. Attach max-age policy to every safety signal and let the system decay stale evidence automatically. Do not rely on color without age and timestamp context. The concrete hserver evidence is commit 3387a0e, so this note is tied to an actual production change rather than a hypothetical failure.

Quick navigationEsc