Retire a consumer the mesh stops asking for, and delete only on a person's word (hq ADR 0230)
The hourly release of ADR 0229's brake still ended in the mesh acting alone on a mistake. A consumer now stays active until the same unasked set holds for five passes, waits for a person past three or half of those held, is disabled and marked rather than withdrawn, comes back as it was when asked again, and is deleted only through the provider's delete tool. The backend keeps the mark, so a restart forgets nothing and finds what was withdrawn before.
This commit is contained in:
@@ -14,6 +14,7 @@ package main
|
||||
|
||||
import (
|
||||
"context"
|
||||
"time"
|
||||
)
|
||||
|
||||
// provisioner is the adapter over the client; announce emits a lifecycle event.
|
||||
@@ -36,22 +37,36 @@ func (a provisioner) Create(ctx context.Context, p Provision) error {
|
||||
if err := a.pg.EnsureExtensions(ctx, database, extensions); err != nil {
|
||||
return err
|
||||
}
|
||||
// The active mark: a retired consumer asked for again loses its mark to delete here, its LOGIN
|
||||
// already set again by the role statement above (novox/hq ADR 0230).
|
||||
if err := a.pg.MarkActive(ctx, p.As, p.Consumer); err != nil {
|
||||
return err
|
||||
}
|
||||
a.announce("database.provisioned", map[string]string{"consumer": p.Consumer, "database": database, "user": p.As})
|
||||
return nil
|
||||
}
|
||||
|
||||
// Remove withdraws, never drops (novox/hq issue 241). The login is locked and the database kept under
|
||||
// its own name: on 2026-10-04 a misread contributions file withdrew every consumer at once, and
|
||||
// dropping made that a loss of seven databases. Taking a database out of service is a person's act —
|
||||
// postgres_retire_database — and even that renames rather than drops.
|
||||
func (a provisioner) Remove(ctx context.Context, as string, _ map[string]any) error {
|
||||
if err := a.pg.LockRole(ctx, as); err != nil {
|
||||
// Retire locks the login, never drops (novox/hq issue 241, ADR 0230): the database is kept under its
|
||||
// own name, the role marked retired with when and why (retire_pg.go). On 2026-10-04 a misread
|
||||
// contributions file withdrew every consumer at once, and dropping made that a loss of seven databases.
|
||||
// Deleting is `cleanup delete`, a person's act; taking a database out of service by hand is
|
||||
// postgres_retire_database, which renames rather than drops.
|
||||
func (a provisioner) Retire(ctx context.Context, as string, _ map[string]any, why string, at time.Time) error {
|
||||
if err := a.pg.RetireRole(ctx, as, why, at); err != nil {
|
||||
return err
|
||||
}
|
||||
a.announce("database.deprovisioned", map[string]string{"database": as, "kept": "true"})
|
||||
a.announce("database.deprovisioned", map[string]string{"database": as, "kept": "true", "retired": "true"})
|
||||
return nil
|
||||
}
|
||||
|
||||
// Inventory is what this server holds that the mesh made (retire_pg.go).
|
||||
func (a provisioner) Inventory(ctx context.Context) (Inventory, error) { return a.pg.Inventory(ctx) }
|
||||
|
||||
// Delete drops a retired consumer's database and role, or a database set aside — a person's act.
|
||||
func (a provisioner) Delete(ctx context.Context, r Retired) (int64, error) {
|
||||
return a.pg.DeleteRetired(ctx, r)
|
||||
}
|
||||
|
||||
// Holds is asked every minute: whether the consumer can still log in as the mesh gave it, and finds
|
||||
// the extensions it asked for, so a login or extension lost behind the provisioner's back is made
|
||||
// again (novox/hq issue 120).
|
||||
|
||||
Reference in New Issue
Block a user