A command opens each store once, not once per machine

Working out what a machine should be reaches the identity context for its
certificate and the licence context for its model access. Both were opened —
and waited on — inside functions called for every node in a push. Two machines
hid it. Fifty would be fifty connect-and-wait cycles for data that does not
change while the push runs.

So a command holds what it has open, and passes it. Each context is opened on
first use rather than up front, because most commands need one and paying to
reach three would be the same waste from the other side.

The contexts stay separate, which is the point: this is one struct holding
three connections to three databases, not one connection to a shared one. No
context reaches another's store, and each still holds only its own credential
(novox/hq ADR 0008).

A pure move again — the gate is green before and after, and no test changed.
This commit is contained in:
2026-08-31 13:35:39 +02:00
parent 8623613704
commit 6eeb10f066
11 changed files with 177 additions and 91 deletions
+15 -11
View File
@@ -39,17 +39,18 @@ func overlayCommand(ctx context.Context, args []string) error {
"what its assignments resolve to — the two are computed from one picture of the " +
"mesh, and sending them separately would let them disagree")
}
inv, err := openInventory(ctx)
open, err := openStores(ctx)
if err != nil {
return err
}
defer inv.Close()
defer open.Close()
inv := open.inventory
switch args[0] {
case "place":
return overlayPlace(ctx, inv, args[1:])
case "show":
return overlayShow(ctx, inv)
return overlayShow(ctx, open)
default:
return fmt.Errorf("overlay has no %q; it has place and show", args[0])
@@ -145,8 +146,9 @@ func network(ctx context.Context, inv *inventory.Inventory, on map[string]bool,
}
// graph is the whole mesh's network, for showing it.
func graph(ctx context.Context, inv *inventory.Inventory) ([]overlay.Node, overlay.Graph, error) {
on, refused, err := whoResolves(ctx, inv, overlay.Requirement)
func graph(ctx context.Context, open *stores) ([]overlay.Node, overlay.Graph, error) {
inv := open.inventory
on, refused, err := whoResolves(ctx, open, overlay.Requirement)
if err != nil {
return nil, nil, err
}
@@ -167,8 +169,9 @@ func graph(ctx context.Context, inv *inventory.Inventory) ([]overlay.Node, overl
// Resolved rather than read from the assignment table, because a module can arrive by being
// required by something else, and a machine that needs the private network to do its job is on it
// for the same reason as one that was handed it directly.
func whoResolves(ctx context.Context, inv *inventory.Inventory, requirement string) (
func whoResolves(ctx context.Context, open *stores, requirement string) (
map[string]bool, map[string]string, error) {
inv := open.inventory
nodes, err := inv.Nodes(ctx)
if err != nil {
return nil, nil, err
@@ -178,7 +181,7 @@ func whoResolves(ctx context.Context, inv *inventory.Inventory, requirement stri
// the rest being described, and whoever is rendering that node will raise it themselves.
refused := map[string]string{}
for _, n := range nodes {
plan, _, err := planFor(ctx, inv, n.Name)
plan, _, err := planFor(ctx, open, n.Name)
if err != nil {
refused[n.Name] = err.Error()
continue
@@ -195,9 +198,10 @@ func whoResolves(ctx context.Context, inv *inventory.Inventory, requirement stri
}
// rendering is everything a declaration needs, computed over the whole mesh.
func generators(ctx context.Context, inv *inventory.Inventory) (
func generators(ctx context.Context, open *stores) (
map[string]catalogue.Generator, error) {
on, refused, err := whoResolves(ctx, inv, overlay.Addressing)
inv := open.inventory
on, refused, err := whoResolves(ctx, open, overlay.Addressing)
if err != nil {
return nil, err
}
@@ -214,8 +218,8 @@ func generators(ctx context.Context, inv *inventory.Inventory) (
}, nil
}
func overlayShow(ctx context.Context, inv *inventory.Inventory) error {
nodes, computed, err := graph(ctx, inv)
func overlayShow(ctx context.Context, open *stores) error {
nodes, computed, err := graph(ctx, open)
if err != nil {
return err
}