diff --git a/internal/cluster/orchestrator_timesync_inventory.go b/internal/cluster/orchestrator_timesync_inventory.go index 911c6bf..d5046f6 100644 --- a/internal/cluster/orchestrator_timesync_inventory.go +++ b/internal/cluster/orchestrator_timesync_inventory.go @@ -135,6 +135,10 @@ func isTimeSynced(raw string) bool { // Signature: (o *Orchestrator) preflightExternalDatastore(ctx context.Context) error. // Why: keeps behavior explicit so startup/shutdown workflows remain maintainable as services evolve. func (o *Orchestrator) preflightExternalDatastore(ctx context.Context) error { + // Cancellation must win even when a local datastore is already reachable. + if err := ctx.Err(); err != nil { + return err + } if len(o.cfg.ControlPlanes) == 0 { return nil } diff --git a/testing/orchestrator/hooks_vault_lifecycle_branch_matrix_test.go b/testing/orchestrator/hooks_vault_lifecycle_branch_matrix_test.go index 40191a4..88aacc1 100644 --- a/testing/orchestrator/hooks_vault_lifecycle_branch_matrix_test.go +++ b/testing/orchestrator/hooks_vault_lifecycle_branch_matrix_test.go @@ -359,6 +359,8 @@ func TestHookVaultLifecycleBranchMatrix(t *testing.T) { cfgFail.Startup.RequireFluxHealth = false cfgFail.Startup.RequireWorkloadConvergence = false cfgFail.Startup.RequireCriticalServiceEndpoints = true + cfgFail.Startup.CriticalServiceEndpointWaitSec = 1 + cfgFail.Startup.CriticalServiceEndpointPollSec = 1 run := func(ctx context.Context, timeout time.Duration, name string, args ...string) (string, error) { command := name + " " + strings.Join(args, " ") if name == "kubectl" && strings.Contains(command, "get endpoints") {