8855766716
The NS-570 epoch stamp clears a drain marker that survives a machine restart — but it assumes every drain-gated action ends in a restart. When a maintenance action completes WITHOUT recreating the container and the writer never cancels the drain, the orphaned marker still carries the current epoch, so the 1s drain watcher honours it forever and the gateway bounces every inbound message with the 'draining for a maintenance action' text (observed in the field: a Hermes Cloud instance refused all Telegram turns for ~3 days). The marker already records requested_at; now the readers check it. A marker older than DRAIN_REQUEST_MAX_AGE_SECONDS (1h) reads as stale in drain_requested() and drain_notification_suppressed(), with a loud warning log. Leniency mirrors the epoch check: a missing or unparseable timestamp still reads as drain-active (fail-safe toward quiescing), and a legitimately long drain keeps a sanctioned keep-alive — re-calling write_drain_request() refreshes requested_at. Fixes #85433