A withdrawn consumer keeps its data, in every provider that holds some (hq issue 241)

mssql disables the login, mongodb takes the user's roles, minio revokes the key and keeps the bucket,
mailu disables the mailbox, gitea prohibits the login instead of purging the user and their
repositories, umami keeps the website. Each provider's create already enables what this locks.
This commit is contained in:
2026-10-05 00:34:40 +02:00
parent 190d711a2a
commit 1fb7ca3d72
10 changed files with 51 additions and 18 deletions
+8
View File
@@ -256,6 +256,14 @@ export class MssqlClient {
}
/** Drop a database and its login, idempotently, after evicting live connections. */
/** Withdraw a consumer and keep its database: its login is disabled, which create undoes. */
async disableLogin(login: string): Promise<void> {
const logins = await this.query(
`SELECT 1 AS ok FROM sys.server_principals WHERE name = ${literal(login)}`,
);
if (logins.length > 0) await this.exec(`ALTER LOGIN ${ident(login)} DISABLE`);
}
async dropDatabaseAndLogin(database: string, login: string): Promise<void> {
const dbs = await this.query(
`SELECT 1 AS ok FROM sys.databases WHERE name = ${literal(database)}`,
+3 -2
View File
@@ -41,8 +41,9 @@ runProvisioner("mssql-database", {
},
async remove(p: { as: string }): Promise<void> {
await mssql.dropDatabaseAndLogin(p.as, p.as);
await announce("database.deprovisioned", { database: p.as });
// Disabled, never dropped (novox/hq issue 241: a withdrawal never destroys a consumer's data — on 2026-10-04 a misread grants file withdrew every consumer at once). create enables the login again.
await mssql.disableLogin(p.as);
await announce("database.deprovisioned", { database: p.as, kept: "true" });
},
// Asked every minute by the harness: whether the backend still holds this consumer exactly as
// the mesh gave it, so a login lost behind the provisioner's back is made again (novox/hq issue 120).