Hserver Failure Notes: Production Acceptance · advanced

A VoIP Change Window Should Prove the Media Path Still Exists

Checking only the SIP proxy is not enough when a healthy call depends on signaling and media components staying aligned.

Current. Current engineering note based on recent hserver deployment, debugging, recovery, and production-hardening work in September 2026.

The hserver change-window preflight treats FreeSWITCH, Drachtio, OpenSIPS and RTPengine as production sentinels. A maintenance change outside the VoIP stack can still affect networking, ports or Docker state that those services depend on.

Telephony availability is a dependency chain rather than one process. Signaling can stay up while media breaks, or a proxy can be reachable while backends are unavailable. Preflight checks enumerate the current signaling and media containers before unrelated production changes proceed, and the RTPengine sentinel was corrected when its runtime name drifted.

This is blast-radius control and change-window validation. Critical unaffected services should be checked before and after a change so collateral damage is detected immediately. Add protocol-level synthetic calls over time, but keep lightweight component sentinels as a fast first gate. The strongest acceptance combines process, endpoint and actual call-path evidence. The concrete hserver evidence is commit dfe9992, so this note is tied to an actual production change rather than a hypothetical failure.

Quick navigationEsc