Review: module issue's pre-check factored and tested; a pair delivery for a requirement the module keeps no secret for is refused; builder issue's usage says the module comes first
This commit is contained in:
@@ -253,12 +253,8 @@ func moduleCommand(ctx context.Context, args []string) error {
|
||||
if !ok {
|
||||
return fmt.Errorf("this mesh knows no module %q; `module add` it first", module)
|
||||
}
|
||||
// The account is delivered as the module's own secret named broker; a module that declares
|
||||
// none has nothing to read it with, and an account nothing reads is an orphan on the bus
|
||||
// (novox/hq 04-ISSUES/078). Said before the account is made, not after.
|
||||
if _, reads := m.OwnSecrets["broker"]; !reads {
|
||||
return fmt.Errorf("%s declares no own secret named broker, so there is nowhere to deliver "+
|
||||
"an account; a module that speaks on the bus declares \"own-secrets\": {\"broker\": <path>}", module)
|
||||
if err := mayIssue(m); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
management, err := broker.ManagementFromEnvironment()
|
||||
@@ -559,3 +555,15 @@ func brokerReachableAt(ctx context.Context, inv *inventory.Inventory, known brok
|
||||
}
|
||||
return net.JoinHostPort(brokerAt, port), nil
|
||||
}
|
||||
|
||||
// mayIssue says whether a module can be given a broker account. The account is delivered as the
|
||||
// module's own secret named broker; a module that declares none has nothing to read it with, and
|
||||
// an account nothing reads is an orphan on the bus (novox/hq 04-ISSUES/078). Said before the
|
||||
// account is made, not after.
|
||||
func mayIssue(m catalogue.Manifest) error {
|
||||
if _, reads := m.OwnSecrets["broker"]; !reads {
|
||||
return fmt.Errorf("%s declares no own secret named broker, so there is nowhere to deliver "+
|
||||
"an account; a module that speaks on the bus declares \"own-secrets\": {\"broker\": <path>}", m.Module)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user