Retire a consumer the mesh stops asking for, and delete only on a person's word (hq ADR 0230)
The hourly release of ADR 0229's brake still ended in the mesh acting alone on a mistake. A consumer now stays active until the same unasked set holds for five passes, waits for a person past three or half of those held, is disabled and marked rather than withdrawn, comes back as it was when asked again, and is deleted only through the provider's delete tool. The backend keeps the mark, so a restart forgets nothing and finds what was withdrawn before.
This commit is contained in:
@@ -32,10 +32,11 @@ func main() {
|
||||
}
|
||||
return
|
||||
}
|
||||
var h *Harness
|
||||
if receives := os.Getenv("MESH_RECEIVES"); receives == "" {
|
||||
say("MESH_RECEIVES is not set — the provisioner cannot run without it")
|
||||
} else {
|
||||
h := &Harness{
|
||||
h = &Harness{
|
||||
Resource: "postgres-database",
|
||||
Receives: receives,
|
||||
Adapter: provisioner{pg: pg, announce: announce},
|
||||
@@ -52,7 +53,9 @@ func main() {
|
||||
go h.Run(context.Background())
|
||||
}
|
||||
go audit()
|
||||
if err := stdio.Serve("", Tools(pg)); err != nil {
|
||||
// The retirement tools beside postgres's own: what is retired here, approving or rejecting what waits
|
||||
// for a person, and deleting a retired consumer (novox/hq ADR 0230).
|
||||
if err := stdio.Serve("", append(Tools(pg), RetirementTools(h)...)); err != nil {
|
||||
say("%v", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
@@ -79,7 +82,7 @@ func audit() {
|
||||
case "postgres.database.provisioned":
|
||||
say("database provisioned for %s (db %s)", body.Consumer, body.Database)
|
||||
case "postgres.database.deprovisioned":
|
||||
say("database withdrawn, kept (db %s)", body.Database)
|
||||
say("database retired, kept (db %s)", body.Database)
|
||||
}
|
||||
return nil
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user