A take is a comparison: the preview, its refusals, the strays, and the policy said at build (hq ADR 0163)
The host now reports, for every held thing, the facts a take compares; the controller keeps them, and take puts them beside what the module declares — the found image and its age against the declared one, the found networks and who else is on them, ports and mounts, a found file's difference from the declared content — and refuses a downgrade without --downgrade and a differing file without --replace <path>. Without --yes the comparison is printed and nothing is taken. node show lists the facts and the strays the machine reports. build and the daemon's take-in say when a module's policy rolls the result out at once. The own-secret refusal points at the provider form for a required secret.
This commit is contained in:
@@ -164,6 +164,18 @@ type Held struct {
|
||||
Since time.Time `json:"since"`
|
||||
Changed string `json:"changed,omitempty"`
|
||||
Kept string `json:"kept,omitempty"`
|
||||
// Facts is what a take compares (novox/hq ADR 0163), as the host reported it: for a found
|
||||
// container its image and the image's date, the networks and their other members, mounts and
|
||||
// ports, beside the declared image, ports and volumes, and whether the declared image is the
|
||||
// older; for a found file whether the declared content differs and how.
|
||||
Facts map[string]any `json:"facts,omitempty"`
|
||||
}
|
||||
|
||||
// A Stray is a container a machine runs that the mesh neither wrote nor holds (ADR 0163).
|
||||
type Stray struct {
|
||||
Kind string `json:"kind"`
|
||||
Name string `json:"name"`
|
||||
Detail string `json:"detail,omitempty"`
|
||||
}
|
||||
|
||||
// Reach is one thing reachable on an adopted node: a listening socket or a published port.
|
||||
@@ -181,6 +193,8 @@ type Adoption struct {
|
||||
Held []Held
|
||||
Firewall string
|
||||
Reachable []Reach
|
||||
// Strays is what the machine runs that nobody asked for, as last reported (ADR 0163).
|
||||
Strays []Stray
|
||||
// At is when it said so; zero when it never has.
|
||||
At time.Time
|
||||
}
|
||||
@@ -189,6 +203,16 @@ type Adoption struct {
|
||||
// question is the machine as it is now.
|
||||
func (i *Inventory) RecordAdoption(ctx context.Context, node string, held []Held, firewall string,
|
||||
reachable []Reach) error {
|
||||
return i.RecordAdoptionWithStrays(ctx, node, held, firewall, reachable, nil)
|
||||
}
|
||||
|
||||
// RecordAdoptionWithStrays is RecordAdoption with what the machine says strays on it (ADR 0163).
|
||||
func (i *Inventory) RecordAdoptionWithStrays(ctx context.Context, node string, held []Held, firewall string,
|
||||
reachable []Reach, strays []Stray) error {
|
||||
straysRaw, err := json.Marshal(nonNil(strays))
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
heldRaw, err := json.Marshal(nonNil(held))
|
||||
if err != nil {
|
||||
return err
|
||||
@@ -198,9 +222,9 @@ func (i *Inventory) RecordAdoption(ctx context.Context, node string, held []Held
|
||||
return err
|
||||
}
|
||||
_, err = i.store.Pool().Exec(ctx,
|
||||
`update node set held = $2, firewall = nullif($3, ''), reachable = $4,
|
||||
`update node set held = $2, firewall = nullif($3, ''), reachable = $4, strays = $5,
|
||||
adoption_reported = now(), last_seen = now()
|
||||
where id = $1`, node, heldRaw, firewall, reachRaw)
|
||||
where id = $1`, node, heldRaw, firewall, reachRaw, straysRaw)
|
||||
return err
|
||||
}
|
||||
|
||||
@@ -213,12 +237,12 @@ func nonNil[T any](s []T) []T {
|
||||
|
||||
// AdoptionOf is what a node last reported about adoption.
|
||||
func (i *Inventory) AdoptionOf(ctx context.Context, name string) (Adoption, error) {
|
||||
var heldRaw, reachRaw []byte
|
||||
var heldRaw, reachRaw, straysRaw []byte
|
||||
var firewall *string
|
||||
var at *time.Time
|
||||
err := i.store.Pool().QueryRow(ctx,
|
||||
`select held, firewall, reachable, adoption_reported from node where name = $1`, name).
|
||||
Scan(&heldRaw, &firewall, &reachRaw, &at)
|
||||
`select held, firewall, reachable, adoption_reported, strays from node where name = $1`, name).
|
||||
Scan(&heldRaw, &firewall, &reachRaw, &at, &straysRaw)
|
||||
if errors.Is(err, pgx.ErrNoRows) {
|
||||
return Adoption{}, fmt.Errorf("%w: %s", ErrNoSuchNode, name)
|
||||
}
|
||||
@@ -237,6 +261,11 @@ func (i *Inventory) AdoptionOf(ctx context.Context, name string) (Adoption, erro
|
||||
return Adoption{}, err
|
||||
}
|
||||
}
|
||||
if len(straysRaw) > 0 {
|
||||
if err := json.Unmarshal(straysRaw, &out.Strays); err != nil {
|
||||
return Adoption{}, err
|
||||
}
|
||||
}
|
||||
if len(reachRaw) > 0 {
|
||||
if err := json.Unmarshal(reachRaw, &out.Reachable); err != nil {
|
||||
return Adoption{}, err
|
||||
|
||||
Reference in New Issue
Block a user