- Domain: add ModelState, ModelStateEvent, ModelNotReady, ManageModelLifecycle
(in-port), ModelLoader and ModelStateEventBus (out-ports)
- Application: InMemoryModelStateEventBus; ModelLifecycleService — state
machine (ReentrantLock), lazy load on first request, idle-timeout auto-unload
(configurable via trueref.embedding.idle-timeout-seconds, default 300 s),
job-guard (skips unload while ingestion running), platform-thread CUDA executor
- Adapters: OnnxModelLoader wires embedder + reranker start/stop; remove
@PostConstruct/@PreDestroy from OnnxEmbeddingService and OnnxRerankerService;
requireStarted() now throws ModelNotReady instead of IllegalStateException
- REST: GET /api/model/status, POST /api/model/unload (409 when jobs running,
force=true to override), GET /api/model/status/stream (SSE)
- GlobalExceptionHandler: ModelNotReady -> 503 + Retry-After header
- HybridSearchService: calls lifecycle.ensureReady() before every search so
both REST and MCP paths get ModelNotReady (-> 503 / MCP error) when unloaded
- TrueRefMcpTools: catches ModelNotReady, returns retry hint in MCP error text
- Tests: InMemoryModelStateEventBusTest, ModelLifecycleServiceTest (10 cases),
OnnxModelLoaderTest, GlobalExceptionHandlerTest — all 41 tests green
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>