A take is a comparison: the preview, its refusals, the strays, and the policy said at build (hq ADR 0163)
The host now reports, for every held thing, the facts a take compares; the controller keeps them, and take puts them beside what the module declares — the found image and its age against the declared one, the found networks and who else is on them, ports and mounts, a found file's difference from the declared content — and refuses a downgrade without --downgrade and a differing file without --replace <path>. Without --yes the comparison is printed and nothing is taken. node show lists the facts and the strays the machine reports. build and the daemon's take-in say when a module's policy rolls the result out at once. The own-secret refusal points at the provider form for a required secret.
This commit is contained in:
@@ -286,18 +286,22 @@ func (e Enrolment) Heard(ctx context.Context, report Report) (news bool, err err
|
||||
// schedule, when what it holds changes, not only after an apply — and never cleared by a
|
||||
// report that carries none, which is every bare word that the node is there. An adopted node
|
||||
// always names its firewall, so a report from one replaces all three, emptied held included.
|
||||
if len(report.Held) > 0 || report.Firewall != "" || len(report.Reachable) > 0 {
|
||||
if len(report.Held) > 0 || report.Firewall != "" || len(report.Reachable) > 0 || len(report.Strays) > 0 {
|
||||
held := make([]inventory.Held, 0, len(report.Held))
|
||||
for _, h := range report.Held {
|
||||
held = append(held, inventory.Held{ID: h.ID, Module: h.Module, Kind: h.Kind,
|
||||
Target: h.Target, Since: h.Since, Changed: h.Changed, Kept: h.Kept})
|
||||
Target: h.Target, Since: h.Since, Changed: h.Changed, Kept: h.Kept, Facts: h.Facts})
|
||||
}
|
||||
strays := make([]inventory.Stray, 0, len(report.Strays))
|
||||
for _, s := range report.Strays {
|
||||
strays = append(strays, inventory.Stray{Kind: s.Kind, Name: s.Name, Detail: s.Detail})
|
||||
}
|
||||
reachable := make([]inventory.Reach, 0, len(report.Reachable))
|
||||
for _, r := range report.Reachable {
|
||||
reachable = append(reachable, inventory.Reach{Protocol: r.Protocol, Address: r.Address,
|
||||
Port: r.Port, By: r.By, Published: r.Published, ContainerPort: r.ContainerPort})
|
||||
}
|
||||
if err := e.Inventory.RecordAdoption(ctx, node.ID, held, report.Firewall, reachable); err != nil {
|
||||
if err := e.Inventory.RecordAdoptionWithStrays(ctx, node.ID, held, report.Firewall, reachable, strays); err != nil {
|
||||
return false, err
|
||||
}
|
||||
}
|
||||
|
||||
@@ -194,6 +194,9 @@ type Report struct {
|
||||
// not see coming.
|
||||
Host string `json:"host,omitempty"`
|
||||
|
||||
// Strays is what runs on the machine that the mesh neither wrote nor holds (ADR 0163).
|
||||
Strays []Stray `json:"strays,omitempty"`
|
||||
|
||||
// Profile is what the machine can do, detected again by this apply (novox/hq ADR 0161): the
|
||||
// same shape enrolment sends, so a machine that gained or lost a capability — switched its
|
||||
// network manager — is known at its next push and not at its next enrolment. Absent from a host
|
||||
@@ -270,6 +273,16 @@ type Held struct {
|
||||
Changed string `json:"changed,omitempty"`
|
||||
// Kept is where a file's original was kept.
|
||||
Kept string `json:"kept,omitempty"`
|
||||
// Facts is the found thing beside what the module declares — what a take compares (novox/hq
|
||||
// ADR 0163): the host's own shape, carried as data and read by the preview.
|
||||
Facts map[string]any `json:"facts,omitempty"`
|
||||
}
|
||||
|
||||
// A Stray is a container a machine runs that the mesh neither wrote nor holds (ADR 0163).
|
||||
type Stray struct {
|
||||
Kind string `json:"kind"`
|
||||
Name string `json:"name"`
|
||||
Detail string `json:"detail,omitempty"`
|
||||
}
|
||||
|
||||
// Reach is one thing reachable on the machine: a listening socket, or a published container port.
|
||||
|
||||
Reference in New Issue
Block a user