Every module named its events the way the old bus spelled a routing key — `module.<module>.<verb>`. Design 29 says a module names an event locally and the mesh works out where it lands, so all 37 were stale against a rule already decided. On the new bus that derives into a namespace belonging to a module called "module", so no cross-module subscription in the mesh matched anything: nothing failed, nothing reacted (novox/hq 04-ISSUES/127). 36 manifests converted, and 43 files of module code with them. The code mattered as much as the manifests: the runtime builds the subject from what `emit()` is handed, so a converted manifest with unconverted code would have had the permission and the subject disagree. Three things the new check found on the way: - `photos` emitted an event its manifest never declared, which the new bus refuses outright. Declared. - `showcase` waited for an event nothing emits, so its demo could never be triggered — only `showcase` may publish under its own name. It emits both halves now. - `distribution` declared an event named after a different module. It emits `image.pushed` under its own name. An event about a *role* belongs on the seat, where the name outlives whoever holds it, but the sdk has no way to publish on a seat yet, so that stays recorded rather than declared. The audit logger's "everything" pattern is `**` rather than the old bus's `#`.
46 lines
1.8 KiB
TypeScript
46 lines
1.8 KiB
TypeScript
// verdaccio's events. The tool runtime imports this once the broker is bound.
|
|
//
|
|
// Emits (novox/hq ADR 0041/0042):
|
|
// module.verdaccio.package.published — a new package version was published to the registry
|
|
//
|
|
// A genuinely useful signal: a package was just published, so anything on the mesh that pins,
|
|
// mirrors or announces dependency releases can react without polling the registry. Verdaccio has
|
|
// no publish webhook, so the module discovers it by diffing the package list's latest versions.
|
|
//
|
|
// The polling is deliberately unhurried: a publish a minute late is still the event, whereas
|
|
// hammering the registry for immediacy nobody asked for is not.
|
|
|
|
import { emit } from "@novox/mesh-sdk/events";
|
|
import { VerdaccioClient } from "./client.js";
|
|
|
|
const verdaccio = VerdaccioClient.fromEnv();
|
|
|
|
// The latest version we have seen per package name. Primed silently on the first look so a registry
|
|
// that was already populated when this started does not announce its whole catalog as freshly
|
|
// published.
|
|
const latest = new Map<string, string>();
|
|
let primed = false;
|
|
|
|
async function pollPackages(): Promise<void> {
|
|
const packages = await verdaccio.listPackages();
|
|
for (const pkg of packages) {
|
|
if (!pkg.version) continue;
|
|
const known = latest.get(pkg.name);
|
|
if (known !== pkg.version) {
|
|
// A name we have not seen, or a name whose latest version moved — both are a publish.
|
|
if (primed) await emit("package.published", { name: pkg.name, version: pkg.version });
|
|
latest.set(pkg.name, pkg.version);
|
|
}
|
|
}
|
|
primed = true;
|
|
}
|
|
|
|
const tick = (fn: () => Promise<void>, everyMs: number): void => {
|
|
const run = (): void => void fn().catch((err) => console.error(`[verdaccio] ${err}`));
|
|
setInterval(run, everyMs);
|
|
run();
|
|
};
|
|
tick(pollPackages, 60_000);
|
|
|
|
console.log("[verdaccio] watching the registry for newly published packages");
|