Every source behind this page, graded. All of it is repository content:
this session's network reached only GitHub, which for this topic happens to be where the
primary record lives. Filter by kind.
Postmortem
Rust project2026-07
rust-lang/rust CI outage, 2026-07-02
A committed, full-format postmortem: kernel.org mirror outage, eighteen affected jobs
(one direct fetch, seventeen transitive via crosstool-ng), four mitigation attempts, a
mitigation-induced secondary failure, and an availability model for external
dependencies.
Carry forwardYour queue's availability is the product of every URL your gate jobs fetch. Mirror or delete them.
raw.githubusercontent.com/rust-lang/infra-team/.../20260702-rust-outage
Postmortem
bors.tech2017-08
"Downtime from 5:47 PM to 2:00 AM UTC the next day"
The hosted merge bot deployed a broken PR through its own queue; unit and integration
tests both missed it for different reasons. Honest to the point of tagging itself
"pants-on-head-stupid".
Carry forwardThe queue is a single point of failure for the entire write path; stage and canary it like one.
raw.githubusercontent.com/bors-ng/bors-ng.github.io/.../we-were-down
ADR
bors.tech2023-05
TMIB 76: the deprecation decision
The maintainer's reasoned surrender to the platform, with the specific unfixable
bugs enumerated: squash merges that cannot be marked merged, status checks that break
when copied across branches, a merge button users should not see.
Carry forwardThird-party queues die on integration seams, not algorithms. List the seams before building on one.
raw.githubusercontent.com/bors-ng/bors-ng.github.io/.../tmib-76
ADR
Rust project2026
New bors design document
The 2026 rewrite's architecture: one auto build at a time, two staging branches per
build flavour because the API cannot merge atomically, post-merge unrolled builds for
rollup blame, and a documented rejected design (check-suite polling) with the race that
killed it.
Carry forwardWebhooks are hints; completion is a derived state you compute, re-check and reconcile.
raw.githubusercontent.com/rust-lang/bors/main/docs/design.md
ADR
OpenStack≤2019
Zuul: Project Gating
The clearest statement of the invariant and of speculative execution's bargain,
including the degenerate case. Preserved on the retired GitHub mirror; the project
itself moved to OpenDev.
Carry forwardSpeculation's worst case is serial testing plus the cost of every discarded build; size it by failure rate.
raw.githubusercontent.com/openstack-infra/zuul/.../gating.rst
ADR
Rust project2026-09
Rollup Procedure (rust-forge)
The operating manual for human-curated batching: the four risk grades, who may
assemble a rollup, how to bisect a failed one by hand, and the queue-fairness etiquette.
Contains the sentence that reframes the whole topic: the queue's job is to test PRs,
not to land them.
Carry forwardIf reviewers can see risk, batching by judgement beats batching by scheduler.
raw.githubusercontent.com/rust-lang/rust-forge/main/src/release/rollups.md
ADR
Kubernetes2026-06
Tide documentation and history
Created 2017 to replace mungegithub's Submit Queue; the design brief was API-token
economics: identify mergeable PRs via GraphQL search so a single instance covers dozens
of orgs. Batches "whenever possible".
Carry forwardRate limits are an architectural force; they decided state placement in three of the six systems here.
raw.githubusercontent.com/kubernetes-sigs/prow/.../tide/_index.md
Source
Kubernetes2026
Maintainer's Guide to Tide
Operational truths: human merges invalidate the whole pool's tests, batches outrank
singles, and GitHub's search index can corrupt and hide mergeable PRs until any update
triggers reindexing.
Carry forwardDisable the humans: one manual merge resets every running test in the pool.
raw.githubusercontent.com/kubernetes-sigs/prow/.../tide/maintainers.md
Source
Rust project / barosl2014–2025
Homu: README and eleven years of history
Why statelessness lost (rate limits), why webhooks beat polling, and the argument
that build badges prove the problem exists. Its git history records its own retirement:
"Disable try builds", 2025-07-22, as the replacement took over.
Carry forwardIf the default branch could never break, the status badge would be pointless; the badge is the confession.
raw.githubusercontent.com/rust-lang/homu/master/README.md
Source
Mozilla / Graydon Hoare2013
The original bors
A stateless cron loop: load everything, advance the ripest PR one state, exit. The
state machine in the README is the whole pattern in nine lines, ending with the
fast-forward and its failure case ("someone moved master on us").
Carry forwardThe minimal correct queue is a weekend project; everything after that is throughput and platform seams.
raw.githubusercontent.com/graydon/bors/master/README.md
Source
bors-ng2017–2023
Bors-NG README
The bifurcate/bifurcateCrab semantic-conflict example, the batch-then-bisect
algorithm walked through on a three-PR failure, and the complexity claim O(N) vs
O(E log N). Now opens with its own deprecation notice.
Carry forwardBisection makes batch cost scale with failures, not batch size; it is the right default when risk is illegible.
raw.githubusercontent.com/bors-ng/bors-ng/master/README.md
Source
Rust project2026-09 (measured 2026-10-04)
rust-lang/rust git history, measured
130 successful queue builds landing 737 PRs in September 2026; 70 rollup builds
carried 677 of them. First-parent commit messages make the queue's whole output
auditable by anyone with a clone.
Carry forwardA queue's merge commits are a free, honest dataset; measure yours before redesigning anything.
github.com/rust-lang/rust
Source
Kubernetes2026-09 (measured 2026-10-04)
kubernetes/kubernetes git history, measured
379 first-parent merge commits in September 2026, all authored by
kubernetes-prow[bot]: a fully automated write path at 12.6 merges/day, batched
opportunistically by Tide.
Carry forwardAt k8s scale the bot owns the merge button outright; humans express intent through labels only.
github.com/kubernetes/kubernetes
Source
Kubernetes2019 (title only)
test-infra #13551: batch failure starves merges
Cited by title, flagged accordingly: "tide: serial merges should occur when batches
fail". The thread body was unreachable under this session's network policy; the failure
mode it names is corroborated by Tide's documented batch-priority rule.
Carry forwardEvery batch-first policy needs a documented starvation exit.
github.com/kubernetes/test-infra/issues/13551
Blog
Rust project2025-10 → 2026-07
Infrastructure team quarterly recaps
The migration diary: try builds on the new bors from July 2025; rust-lang/rust merges
by Q4 2025, "completing the migration off Homu"; the GraphQL mergeability win
(30 min to 1 min); and the admission that satellite repos on GitHub's queue
lost reviewer delegation and got it rebuilt in triagebot.
Carry forwardMigrating a queue is done in slices, lowest-stakes flavour first; try builds were the canary for a year.
raw.githubusercontent.com/rust-lang/blog.rust-lang.org/.../infrastructure-team-2026-q2-recap-and-q3-plan
Blog
bors.tech2017
"About semantic conflicts" and the Whirlwind lineage guide
The pitch essay demonstrates isolation-testing's blind spot in three slides; the
lineage guide records why each generation exists, including "Homu tests pull requests
one at a time" as Bors-NG's founding complaint.
Carry forwardEach rewrite in this lineage was motivated by one named deficiency, not by rot; name yours before rewriting.
raw.githubusercontent.com/bors-ng/bors-ng.github.io/.../whirlwind
Blog
Smarkets2017–
marge-bot README
The Not Rocket Science Rule quoted with attribution, the argument that manual
rebase-and-retry collapses at 5–10 minute CI with a busy team, and a third blame
policy: on batch failure, land the first MR and retry the rest.
Carry forwardAt GitLab shops the same pattern re-evolved independently; the rule is platform-agnostic even when the bots are not.
raw.githubusercontent.com/smarkets/marge-bot/master/README.md
Vendor
GitHub2026
Managing a merge queue (docs source)
The platform queue's mechanics from the docs repository: merge groups on temporary
branches, 1–100 build concurrency, min/max group sizes with a wait timer for
deploy-coupled branches, queue-jumping that rebuilds everything behind, and the
flake-tolerance checkbox.
Carry forwardThe platform queue is Zuul's algorithm productised; what it lacks is everything around the algorithm.
raw.githubusercontent.com/github/docs/.../managing-a-merge-queue.md
Vendor
GitLab2026
Merge trains (docs source)
Parallel merged-results pipelines, the restart cascade on failure, the
20-pipeline default limit, and "merge immediately" documented as an escape hatch that
aborts the train and may leave the target branch needing "additional work".
Carry forwardEvery queue grows an admin bypass; the vendor documenting its blast radius is a gift, read it.
raw.githubusercontent.com/gitlabhq/gitlabhq/.../merge_trains.md
Vendor
Google / Chromium2026
Chromium commit queue docs
A Gerrit-world data point: dry runs separated from submitting runs, automatic retry
of failed shards to absorb flake, and an opt-in "Mega-CQ" that trades much longer wall
time for broader coverage on risky changes.
Carry forwardRisk-tiered verification (normal vs mega) is the machine version of Rust's human risk grades.
raw.githubusercontent.com/chromium/chromium/main/docs/infra/cq.md