diff --git a/README.md b/README.md index 1eb913e..cd07f10 100644 --- a/README.md +++ b/README.md @@ -444,12 +444,12 @@ The same external-service protocol drill used by CI can be run independently: Run the isolated HTTP/WebSocket/authenticated chat/tracking load profile with resource, PostgreSQL statement, database-connection, and Ecto pool-wait -measurements: +measurements. The lifecycle wrapper is preferred because it removes only its +unique containers, networks, volumes, environment, and image tags on success, +failure, or interruption: ```bash -./scripts/load-stack-up.sh -./scripts/load-run.sh local-load -./scripts/load-stack-stop.sh +./scripts/load-cycle.sh local-load load ``` The profile has its own generated mode-`0600` environment, Compose project, @@ -458,6 +458,24 @@ database. Exact inputs and threshold-free evidence are retained below `output/performance/local-load/`; see [Performance measurement](docs/performance.md) for scope and interpretation. +A separate production probe is limited to a compiled allowlist of public GET +pages and Phoenix heartbeat frames. First inspect a read-only plan with every +experiment input supplied explicitly: + +```bash +WNH_PRODUCTION_LOAD_HTTP_VUS= \ +WNH_PRODUCTION_LOAD_WS_VUS= \ +WNH_PRODUCTION_LOAD_DURATION= \ +WNH_PRODUCTION_LOAD_HTTP_THINK_SECONDS= \ +WNH_PRODUCTION_LOAD_WS_HOLD_MS= \ +WNH_PRODUCTION_LOAD_WS_CONNECT_TIMEOUT_MS= \ + ./scripts/production-readonly-load.sh plan +``` + +It does not start load in `plan` mode. The separately approved `run` mode +requires the exact confirmation printed by that plan and still cannot test +authenticated writes or establish a production capacity limit. + The cursor-pagination database benchmark also creates a one-run Compose project, random database credentials, and a separate PostgreSQL volume: diff --git a/docs/performance.md b/docs/performance.md index 4574a85..58e9bbc 100644 --- a/docs/performance.md +++ b/docs/performance.md @@ -28,7 +28,120 @@ queries. This isolates the limiter on a fast local tmpfs database. It does not include SMTP delivery, account lookup, production storage latency, internet latency, or production contention, and therefore is not a production capacity claim. -It provides no evidence that Redis is currently required. +It verifies the one-statement implementation shape. It provides no evidence +that Redis is currently required or unnecessary on the production host. + +## Two different load profiles + +The repository deliberately separates two experiments: + +1. `scripts/load-cycle.sh` is the full write-capable profile. It creates a + unique Compose project, database, credentials, images, and fixtures. It + exercises login, database writes, private chat, tracking, WebSockets, + multiple web/worker replicas, SQL statements, and connection pools. Use + this profile to find application and query bottlenecks without touching + real users. +2. `scripts/production-readonly-load.sh` is pinned to + `https://whoneedhelp.com`. Its compiled allowlist contains only public GET + pages, readiness, and Phoenix WebSocket heartbeats. It cannot exercise the + authenticated write path and therefore cannot determine write capacity or + whether Redis is warranted. + +The production runner has separate `plan` and `run` modes. Every VU, duration, +think-time, and socket value is mandatory; the script supplies no hidden load +defaults. `plan` verifies the remote checkout identity, exact commit, Compose +project, running application containers, and current host resources without +starting k6. `run` additionally requires the exact confirmation string emitted +by that verified plan. If the production commit or any experiment input +changes, the confirmation no longer matches. + +Example plan only: + +```sh +WNH_PRODUCTION_LOAD_HTTP_VUS= \ +WNH_PRODUCTION_LOAD_WS_VUS= \ +WNH_PRODUCTION_LOAD_DURATION= \ +WNH_PRODUCTION_LOAD_HTTP_THINK_SECONDS= \ +WNH_PRODUCTION_LOAD_WS_HOLD_MS= \ +WNH_PRODUCTION_LOAD_WS_CONNECT_TIMEOUT_MS= \ + ./scripts/production-readonly-load.sh plan +``` + +Do not copy a previous run's values as production limits. Choose and record a +specific experiment, inspect the printed target and scope, then use the printed +confirmation only when that production probe has been explicitly approved. + +When run, evidence is written only on the operator workstation below +`output/performance/