A provider is told who its consumers are, and a reference provisioner
Contributions were node-local, so a mesh-scoped provider — the one case that most needs them — never heard from its consumers. A database was given a password and no idea what to create it for. Cross-node consumers now reach the provider's `receives` file, merged in with the ones on its own machine: from the provider's side they are the same thing, and a provider that had to read two lists would read one of them. Each names the file its credential is in rather than carrying it, because the mesh discarded the value and could not put it there. The readable half therefore stays readable. And examples/postgres-provisioner, which is the last step: it reads what the host wrote and makes PostgreSQL accept it. Explicitly not part of the control plane — the control plane decides and never touches a machine. This runs on the machine and touches it, and a real one ships with the module that ships PostgreSQL. It lives here because this is where the contract is defined, written as something that runs so it can be read. It reconciles rather than applying a change, because it is never told what changed. Three things that follow, and each is a fault somebody has shipped: - the password is set every time, not only on creation, or a rotation reports success and changes nothing - what it made and nobody asks for any more is revoked, or a departed consumer keeps a working login for ever - what it did not make is left alone, or it cannot be run on a database that predates it Proven in the lab against a real PostgreSQL, each assertion confirmed to fail with the behaviour removed. The suite is in mesh-lab, which also records the two ways the test itself was wrong first.
This commit is contained in:
@@ -0,0 +1,12 @@
|
||||
# examples
|
||||
|
||||
Things that run, kept here because a contract is easier to read as working code than as prose.
|
||||
|
||||
**Nothing here is part of the control plane.** The control plane decides and never touches a
|
||||
machine ([README](../README.md)); everything in this directory runs *on* a machine and touches it.
|
||||
These are reference implementations of contracts the control plane defines, and a real one ships
|
||||
with the module that ships the software it configures.
|
||||
|
||||
| | |
|
||||
|---|---|
|
||||
| `postgres-provisioner` | the last step of a credential: reads what the mesh delivered and makes PostgreSQL accept it |
|
||||
Reference in New Issue
Block a user