Resync hq ADR references 0044-0054 -> 0039-0049 after the hq record reconciliation
This commit is contained in:
@@ -61,7 +61,7 @@ type Grant struct {
|
||||
Values map[string]any
|
||||
// Slug is the consumer module's identity slug, if it declared one — carried on the grant so the
|
||||
// provider side derives the same login the consumer does, even across nodes where the consumer's
|
||||
// manifest is not in view (novox/hq ADR 0054). Empty means "use the module name".
|
||||
// manifest is not in view (novox/hq ADR 0049). Empty means "use the module name".
|
||||
Slug string
|
||||
// At is where the consuming machine is on the private network, empty if it is not on one.
|
||||
//
|
||||
@@ -143,7 +143,7 @@ func (r Resolution) Declaration(with Rendering) ([]map[string]any, error) {
|
||||
|
||||
// Once, from every module's listens -- not per module. A module receiving only its own ports
|
||||
// would write a rule set that closed every other module on the machine. Each module's per-node
|
||||
// exposure settings override its listens' source first (novox/hq ADR 0051).
|
||||
// exposure settings override its listens' source first (novox/hq ADR 0046).
|
||||
exposure := map[string]map[int]string{}
|
||||
for _, m := range r.Modules {
|
||||
e, err := Exposure(m, with.Settings[m.Module])
|
||||
|
||||
@@ -73,7 +73,7 @@ func (r Resolution) Filtering(computed map[string]Generator, ports map[string]ma
|
||||
}
|
||||
// The source, with any per-node exposure setting applied. The override names the port
|
||||
// the module declares, so it travels with that port to wherever the machine publishes
|
||||
// it (novox/hq ADR 0051): the same module is internal on one node and public on another.
|
||||
// it (novox/hq ADR 0046): the same module is internal on one node and public on another.
|
||||
from := l.From
|
||||
if override, set := exposure[m.Module][l.Port]; set {
|
||||
from = override
|
||||
@@ -108,7 +108,7 @@ func (r Resolution) Filtering(computed map[string]Generator, ports map[string]ma
|
||||
return widest(out), nil
|
||||
}
|
||||
|
||||
// ExposeSetting is the settings key that overrides a listen's source per node (novox/hq ADR 0051):
|
||||
// ExposeSetting is the settings key that overrides a listen's source per node (novox/hq ADR 0046):
|
||||
//
|
||||
// {"expose": {"5432": "anywhere"}}
|
||||
//
|
||||
@@ -122,7 +122,7 @@ const ExposeSetting = "expose"
|
||||
// It refuses an override for a port the module does not listen on, or to a source that is not a
|
||||
// real one — an exposure setting that reaches no port, or names a source nothing enforces, is the
|
||||
// "reads as a restriction and is none" fault this whole mechanism exists to prevent (novox/hq
|
||||
// ADR 0048/0050). A module with no `expose` setting yields nothing and keeps its manifest defaults.
|
||||
// ADR 0043/0045). A module with no `expose` setting yields nothing and keeps its manifest defaults.
|
||||
func Exposure(m Manifest, layers []Layer) (map[int]string, error) {
|
||||
listened := make(map[int]bool, len(m.Listens))
|
||||
for _, l := range m.Listens {
|
||||
|
||||
@@ -580,7 +580,7 @@ func named(r Resolution) []string {
|
||||
}
|
||||
|
||||
// A port's source is a per-node setting, not a manifest constant: the same module is internal on
|
||||
// one machine and public on another (novox/hq ADR 0051). postgres listens from the mesh by default;
|
||||
// one machine and public on another (novox/hq ADR 0046). postgres listens from the mesh by default;
|
||||
// a setting on one node exposes it to anywhere, and the rule set follows.
|
||||
func TestExposureSettingOverridesAListensSource(t *testing.T) {
|
||||
postgres := Manifest{Module: "postgres", Version: "1",
|
||||
@@ -605,7 +605,7 @@ func TestExposureSettingOverridesAListensSource(t *testing.T) {
|
||||
}
|
||||
|
||||
// Exposure refuses a setting that names a port the module does not listen on, or a source that is
|
||||
// not a real one — a setting reaching nothing is worse than none (novox/hq ADR 0048/0051).
|
||||
// not a real one — a setting reaching nothing is worse than none (novox/hq ADR 0043/0046).
|
||||
func TestExposureRefusesAPortNotListenedOnAndABadSource(t *testing.T) {
|
||||
postgres := Manifest{Module: "postgres", Listens: []Listening{{Port: 5432, From: FromMesh}}}
|
||||
layer := func(port, source string) []Layer {
|
||||
|
||||
@@ -35,7 +35,7 @@ var identityUnusable = regexp.MustCompile(`[^a-z0-9_]+`)
|
||||
const IdentityPrefix = "mesh_"
|
||||
|
||||
// IdentitySource is the name the mesh derives a consumer's identity from: the module's slug when it
|
||||
// has declared one, otherwise its name (novox/hq ADR 0054). A module with a name short enough to fit
|
||||
// has declared one, otherwise its name (novox/hq ADR 0049). A module with a name short enough to fit
|
||||
// the tightest backend needs no slug; one whose name would overflow declares a short legible one.
|
||||
func IdentitySource(slug, name string) string {
|
||||
if slug != "" {
|
||||
@@ -59,7 +59,7 @@ func ConsumerIdentity(node, module string) string {
|
||||
// identityLimit is the shortest identifier limit among the systems these names reach: an S3 access
|
||||
// key's 20 (novox/hq 04-ISSUES/010). PostgreSQL keeps 63 and MinIO 20, so 20 is the one that binds —
|
||||
// the comment used to name PostgreSQL and was wrong. A name over it is refused, with the remedy a
|
||||
// short slug (ADR 0054), not silently cut to fit.
|
||||
// short slug (ADR 0049), not silently cut to fit.
|
||||
const identityLimit = 20
|
||||
|
||||
// CheckIdentity refuses an identity that would not fit the tightest backend a consumer reaches.
|
||||
@@ -68,7 +68,7 @@ const identityLimit = 20
|
||||
// the statement succeeds, so two consumers agreeing for the first N bytes would become one login
|
||||
// (04-ISSUES/022) — and S3 refuses outright. Refused here, at the mesh, because the mesh chose the
|
||||
// name and is the only thing that can choose another. The remedy is a first-class one: give the
|
||||
// module a short `slug` (ADR 0054), or shorten the machine's name.
|
||||
// module a short `slug` (ADR 0049), or shorten the machine's name.
|
||||
func CheckIdentity(node, module string) error {
|
||||
got := ConsumerIdentity(node, module)
|
||||
if len(got) <= identityLimit {
|
||||
|
||||
@@ -6,7 +6,7 @@ import "testing"
|
||||
|
||||
func TestASlugIsPreferredOverTheModuleName(t *testing.T) {
|
||||
// A module that declared a slug is identified by it, so a long name can be made to fit the
|
||||
// tightest backend without a hash (novox/hq ADR 0054).
|
||||
// tightest backend without a hash (novox/hq ADR 0049).
|
||||
if got := IdentitySource("kc", "keycloak"); got != "kc" {
|
||||
t.Errorf("the slug was not preferred: %q", got)
|
||||
}
|
||||
|
||||
@@ -120,7 +120,7 @@ type Manifest struct {
|
||||
Version string `json:"version,omitempty"`
|
||||
|
||||
// Slug is a short identifier the mesh uses in place of the module name when it derives a
|
||||
// consumer's login (novox/hq ADR 0054). Optional: a module with a short name needs none. It
|
||||
// consumer's login (novox/hq ADR 0049). Optional: a module with a short name needs none. It
|
||||
// exists because `mesh_<node>_<module>` must fit the tightest backend a consumer reaches — an S3
|
||||
// access key is 20 characters — and a long module name would overflow it. A person choosing
|
||||
// `kc` for keycloak keeps the identity legible where a hash would not.
|
||||
@@ -135,7 +135,7 @@ type Manifest struct {
|
||||
|
||||
// Emits are the event types this module publishes onto the broker — dotted topic keys, e.g.
|
||||
// "module.umami.site.created". Declared so the mesh knows the event graph; events are
|
||||
// provisioning's lighter sibling — 1:many and broadcast, no credential (novox/hq ADR 0046).
|
||||
// provisioning's lighter sibling — 1:many and broadcast, no credential (novox/hq ADR 0041).
|
||||
Emits []string `json:"emits,omitempty"`
|
||||
|
||||
// Consumes are the event patterns this module subscribes to — topic patterns over module,
|
||||
@@ -474,7 +474,7 @@ func ParseManifest(raw []byte) (Manifest, error) {
|
||||
problems = append(problems, fmt.Sprintf(
|
||||
"%q is not a usable module name: lower-case letters, digits, dashes and dots", m.Module))
|
||||
}
|
||||
// A slug is a short identifier the mesh derives a login from (novox/hq ADR 0054). The same
|
||||
// A slug is a short identifier the mesh derives a login from (novox/hq ADR 0049). The same
|
||||
// charset as a name; its length is checked against a backend's limit at assignment, where the
|
||||
// node it joins is known — a slug that is fine on one machine's short name can overflow another's.
|
||||
if m.Slug != "" && !name.MatchString(m.Slug) {
|
||||
|
||||
@@ -172,7 +172,7 @@ func UnusedSettings(m Manifest, layers []Layer) []string {
|
||||
for _, layer := range layers {
|
||||
for key := range layer.Values {
|
||||
// `expose` is a real destination for a module that listens: it overrides a port's
|
||||
// source (novox/hq ADR 0051), validated in Exposure, so it is not stray here.
|
||||
// source (novox/hq ADR 0046), validated in Exposure, so it is not stray here.
|
||||
if key == ExposeSetting && len(m.Listens) > 0 {
|
||||
continue
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user