The mesh keeps a copy of what each node owns
novox/hq 09-the-node-lifecycle asks for this and it was missing: the host reports what it owns and the mesh keeps the last report. A backup, never a source -- nothing decides anything from it, and a node that disagrees with it wins, because the node is the one that can see the machine. Its point is the orphans. A node that loses its state file currently strands whatever it applied: nothing on the machine knows those resources were the mesh's doing, so nothing removes them. With this, a rebuilt node receives both the declaration and the record of what it previously owned. Never reported and reported nothing are kept apart, and that is the whole care in it. A node that applied nothing holds nothing; a node that has never spoken is unknown -- and handing back an empty list for the second would tell a rebuilding node it owns nothing and have it remove whatever it found. The age comes back with the answer rather than being left for the caller to go and find. An answer about a machine is worth much less without one, and this repository has already been bitten by a cache with no age on it. A refusal or a partial failure moves last_seen and nothing else: neither is an account of what the machine holds, and recording one as though it were would tell a rebuilding node to remove what it still has.
This commit is contained in:
@@ -233,3 +233,53 @@ func (i *Inventory) Seen(ctx context.Context, node string) error {
|
||||
_, err := i.store.Pool().Exec(ctx, `update node set last_seen = now() where id = $1`, node)
|
||||
return err
|
||||
}
|
||||
|
||||
// RecordOwned keeps the last account a node gave of what it holds.
|
||||
//
|
||||
// A copy for recovery and never a source (novox/hq 09-the-node-lifecycle). Nothing here decides
|
||||
// anything from it; it is handed back to a node that has lost its own store, and if that node
|
||||
// then disagrees, the node wins — it is the one that can see the machine.
|
||||
//
|
||||
// Replaced rather than appended. A history of what a node used to own answers a question nobody
|
||||
// asks, and the one question this does answer — what is on that machine now — is only answered by
|
||||
// the latest.
|
||||
func (i *Inventory) RecordOwned(ctx context.Context, node string, owned []string) error {
|
||||
raw, err := json.Marshal(owned)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
_, err = i.store.Pool().Exec(ctx,
|
||||
`update node set owned = $2, owned_reported = now(), last_seen = now() where id = $1`,
|
||||
node, raw)
|
||||
return err
|
||||
}
|
||||
|
||||
// Owned is what a node last said it holds, and when it said so.
|
||||
//
|
||||
// The age is returned with it rather than left to the caller to look up, because an answer about
|
||||
// a machine is worth much less without one — and this repository has already been bitten by a
|
||||
// cache with no age on it.
|
||||
func (i *Inventory) Owned(ctx context.Context, node string) ([]string, time.Time, error) {
|
||||
var raw []byte
|
||||
var reported *time.Time
|
||||
err := i.store.Pool().QueryRow(ctx,
|
||||
`select owned, owned_reported from node where id = $1`, node).Scan(&raw, &reported)
|
||||
if errors.Is(err, pgx.ErrNoRows) {
|
||||
return nil, time.Time{}, fmt.Errorf("%w: %s", ErrNoSuchNode, node)
|
||||
}
|
||||
if err != nil {
|
||||
return nil, time.Time{}, err
|
||||
}
|
||||
if len(raw) == 0 || reported == nil {
|
||||
// Never reported is not the same as reported nothing. A node that has applied nothing
|
||||
// holds nothing; a node that has never spoken is unknown, and handing back an empty list
|
||||
// as though it were a report would tell a rebuilding node it owns nothing and have it
|
||||
// remove whatever it found.
|
||||
return nil, time.Time{}, nil
|
||||
}
|
||||
var owned []string
|
||||
if err := json.Unmarshal(raw, &owned); err != nil {
|
||||
return nil, time.Time{}, err
|
||||
}
|
||||
return owned, *reported, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user