A command opens each store once, not once per machine
Working out what a machine should be reaches the identity context for its certificate and the licence context for its model access. Both were opened — and waited on — inside functions called for every node in a push. Two machines hid it. Fifty would be fifty connect-and-wait cycles for data that does not change while the push runs. So a command holds what it has open, and passes it. Each context is opened on first use rather than up front, because most commands need one and paying to reach three would be the same waste from the other side. The contexts stay separate, which is the point: this is one struct holding three connections to three databases, not one connection to a shared one. No context reaches another's store, and each still holds only its own credential (novox/hq ADR 0008). A pure move again — the gate is green before and after, and no test changed.
This commit is contained in:
+26
-25
@@ -21,7 +21,8 @@ import (
|
||||
// nothing in it was wrong, and no one edit was the one that should have been a new file.
|
||||
|
||||
// planFor works out everything a node should run, from what was assigned to it.
|
||||
func planFor(ctx context.Context, inv *inventory.Inventory, nodeName string) (catalogue.Resolution, catalogue.SettingsBy, error) {
|
||||
func planFor(ctx context.Context, open *stores, nodeName string) (catalogue.Resolution, catalogue.SettingsBy, error) {
|
||||
inv := open.inventory
|
||||
shelf, err := inv.Catalogue(ctx)
|
||||
if err != nil {
|
||||
return catalogue.Resolution{}, nil, err
|
||||
@@ -63,7 +64,7 @@ func planFor(ctx context.Context, inv *inventory.Inventory, nodeName string) (ca
|
||||
// What this mesh can answer with a record rather than a machine, and which record each of
|
||||
// this node's modules was put on. Read across a context boundary by name, which is what
|
||||
// crossing one is allowed to carry (novox/hq ADR 0008).
|
||||
world.Licences, world.Using, err = licencesFor(ctx, nodeName)
|
||||
world.Licences, world.Using, err = licencesFor(ctx, open, nodeName)
|
||||
if err != nil {
|
||||
return catalogue.Resolution{}, nil, err
|
||||
}
|
||||
@@ -83,7 +84,7 @@ func planFor(ctx context.Context, inv *inventory.Inventory, nodeName string) (ca
|
||||
// Answered by something the mesh holds, so there is no pair-wise secret between two
|
||||
// machines. Its key was supplied by a person and sealed to this node then; the mesh
|
||||
// discarded the plaintext and cannot make another.
|
||||
sealed, err := keyFor(ctx, n.From, nodeName, n.For)
|
||||
sealed, err := keyFor(ctx, open, n.From, nodeName, n.For)
|
||||
if err != nil {
|
||||
return catalogue.Resolution{}, nil, err
|
||||
}
|
||||
@@ -233,21 +234,22 @@ func theRestOfTheMesh(ctx context.Context, inv *inventory.Inventory,
|
||||
// One place, because there were three and one of them was written before credentials existed and
|
||||
// silently produced a declaration missing them — a difference between what `plan` showed and what
|
||||
// `plan --json` handed to anything reading it.
|
||||
func declarationFor(ctx context.Context, inv *inventory.Inventory, node string,
|
||||
func declarationFor(ctx context.Context, open *stores, node string,
|
||||
plan catalogue.Resolution, settings catalogue.SettingsBy) ([]map[string]any, error) {
|
||||
gens, err := generators(ctx, inv)
|
||||
gens, err := generators(ctx, open)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return declarationWith(ctx, inv, node, plan, settings, gens)
|
||||
return declarationWith(ctx, open, node, plan, settings, gens)
|
||||
}
|
||||
|
||||
// declarationWith is the same, for a caller that has already worked out the generators once and
|
||||
// is about to use them for every node.
|
||||
func declarationWith(ctx context.Context, inv *inventory.Inventory, node string,
|
||||
func declarationWith(ctx context.Context, open *stores, node string,
|
||||
plan catalogue.Resolution, settings catalogue.SettingsBy,
|
||||
gens map[string]catalogue.Generator) ([]map[string]any, error) {
|
||||
grants, err := grantsFor(ctx, inv, node)
|
||||
inv := open.inventory
|
||||
grants, err := grantsFor(ctx, open, node)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -274,7 +276,7 @@ func declarationWith(ctx context.Context, inv *inventory.Inventory, node string,
|
||||
if m.Certificate == nil {
|
||||
continue
|
||||
}
|
||||
issued, meshCA, err := certificateFor(ctx, inv, node)
|
||||
issued, meshCA, err := certificateFor(ctx, open, node)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -310,12 +312,12 @@ func declarationWith(ctx context.Context, inv *inventory.Inventory, node string,
|
||||
// the machine and whether it is on the private network, `identity` holds the authority and the
|
||||
// key that machine reported. The process holding both grants asks each for its part
|
||||
// (novox/hq ADR 0008).
|
||||
func certificateFor(ctx context.Context, inv *inventory.Inventory, node string) (string, string, error) {
|
||||
ident, err := openIdentity(ctx)
|
||||
func certificateFor(ctx context.Context, open *stores, node string) (string, string, error) {
|
||||
inv := open.inventory
|
||||
ident, err := open.Identity(ctx)
|
||||
if err != nil {
|
||||
return "", "", err
|
||||
}
|
||||
defer ident.Close()
|
||||
|
||||
record, err := inv.NodeByName(ctx, node)
|
||||
if err != nil {
|
||||
@@ -371,7 +373,8 @@ func certificateFor(ctx context.Context, inv *inventory.Inventory, node string)
|
||||
// The mirror of what a consumer is given, and the half that makes the credential real: a password
|
||||
// nothing was told to create is a password that authenticates nowhere. Sealed to this node, so
|
||||
// the mesh hands over something it cannot itself use.
|
||||
func grantsFor(ctx context.Context, inv *inventory.Inventory, node string) ([]catalogue.Grant, error) {
|
||||
func grantsFor(ctx context.Context, open *stores, node string) ([]catalogue.Grant, error) {
|
||||
inv := open.inventory
|
||||
issued, err := inv.SecretsFrom(ctx, node)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
@@ -393,7 +396,7 @@ func grantsFor(ctx context.Context, inv *inventory.Inventory, node string) ([]ca
|
||||
// can do nothing with it, and the name a consumer wants is the consumer's to say.
|
||||
out := make([]catalogue.Grant, 0, len(issued))
|
||||
for _, s := range issued {
|
||||
plan, settings, err := planFor(ctx, inv, s.Consumer)
|
||||
plan, settings, err := planFor(ctx, open, s.Consumer)
|
||||
if err != nil {
|
||||
// Their set does not resolve. Skipped rather than fatal: this node is not the place
|
||||
// to report another machine's problem, and a grant for something that is not going to
|
||||
@@ -428,13 +431,13 @@ func planCommand(ctx context.Context, args []string) error {
|
||||
return errors.New("plan <node> [--files] [--json]")
|
||||
}
|
||||
args = positionals
|
||||
inv, err := openInventory(ctx)
|
||||
open, err := openStores(ctx)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer inv.Close()
|
||||
defer open.Close()
|
||||
|
||||
plan, settings, err := planFor(ctx, inv, args[0])
|
||||
plan, settings, err := planFor(ctx, open, args[0])
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -443,7 +446,7 @@ func planCommand(ctx context.Context, args []string) error {
|
||||
return nil
|
||||
}
|
||||
if *asJSON {
|
||||
resources, err := declarationFor(ctx, inv, args[0], plan, settings)
|
||||
resources, err := declarationFor(ctx, open, args[0], plan, settings)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -469,7 +472,7 @@ func planCommand(ctx context.Context, args []string) error {
|
||||
for _, n := range plan.Needs {
|
||||
fmt.Printf(" needs %s from %s, for %s\n", n.Name, n.From, n.For)
|
||||
}
|
||||
resources, err := declarationFor(ctx, inv, args[0], plan, settings)
|
||||
resources, err := declarationFor(ctx, open, args[0], plan, settings)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -497,14 +500,13 @@ func planCommand(ctx context.Context, args []string) error {
|
||||
// A mesh with no licences at all is the ordinary case and must not be an error: every existing
|
||||
// mesh is one, and a control plane that refused to plan because nobody had bought an API key
|
||||
// would be unusable for the thing it already does.
|
||||
func licencesFor(ctx context.Context, node string) (
|
||||
func licencesFor(ctx context.Context, open *stores, node string) (
|
||||
map[string][]catalogue.Record, map[string]map[string]catalogue.Record, error) {
|
||||
|
||||
held, err := openLicences(ctx)
|
||||
held, err := open.Licences(ctx)
|
||||
if err != nil {
|
||||
return nil, nil, err
|
||||
}
|
||||
defer held.Close()
|
||||
|
||||
all, err := held.All(ctx)
|
||||
if err != nil {
|
||||
@@ -546,11 +548,10 @@ func licencesFor(ctx context.Context, node string) (
|
||||
// **Empty is not an error here.** The mesh discarded the plaintext when it was supplied, so a
|
||||
// holder recorded afterwards genuinely has no key — and the declaration refuses that by name,
|
||||
// where the module and the path are both in view, rather than here.
|
||||
func keyFor(ctx context.Context, licence, node, module string) (string, error) {
|
||||
held, err := openLicences(ctx)
|
||||
func keyFor(ctx context.Context, open *stores, licence, node, module string) (string, error) {
|
||||
held, err := open.Licences(ctx)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
defer held.Close()
|
||||
return held.KeyFor(ctx, licence, node, module)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user