One object store, not two

object-store.json and minio.json described the same thing: same image,
same provision at the same scope, same provisioner. Not two
implementations a person could choose between — one module written
twice. Assigning both to a node would have collided on `s3-bucket`.

It exists because it was written first, to pair with photos.json for the
README's worked edge, and minio.json was the fuller version of the same
module written later. Nobody removed the first.

The pair test keeps its point and now reads the surviving one. Checked
across the rest: this was the only duplicate.
This commit is contained in:
2026-09-01 21:06:17 +02:00
parent 0d975a051d
commit 4d6ec5b10c
5 changed files with 67 additions and 89 deletions
+17 -1
View File
@@ -336,7 +336,23 @@ func declarationWith(ctx context.Context, open *stores, node string,
needed := map[string]map[string]string{}
for _, m := range plan.Modules {
for name := range m.OwnSecrets {
sealed, err := inv.SecretForModule(ctx, node, m.Module, name)
// Minted on the send path and only read on every other. Making one is an insert, and
// a question that writes is a question that can block against the machine it is about.
var sealed string
var err error
if choosing == Allocating {
sealed, err = inv.SecretForModule(ctx, node, m.Module, name)
} else {
var held bool
sealed, held, err = inv.ModuleSecretIfIssued(ctx, node, m.Module, name)
if err == nil && !held {
// Never issued, so this machine cannot be running it. Left out rather than
// invented: an empty string here would compose a declaration that differs
// from what would be sent, and the comparison this feeds would then be
// answering about a declaration nothing will ever push.
continue
}
}
if err != nil {
return nil, err
}