The mesh keeps a copy of what each node owns
novox/hq 09-the-node-lifecycle asks for this and it was missing: the host reports what it owns and the mesh keeps the last report. A backup, never a source -- nothing decides anything from it, and a node that disagrees with it wins, because the node is the one that can see the machine. Its point is the orphans. A node that loses its state file currently strands whatever it applied: nothing on the machine knows those resources were the mesh's doing, so nothing removes them. With this, a rebuilt node receives both the declaration and the record of what it previously owned. Never reported and reported nothing are kept apart, and that is the whole care in it. A node that applied nothing holds nothing; a node that has never spoken is unknown -- and handing back an empty list for the second would tell a rebuilding node it owns nothing and have it remove whatever it found. The age comes back with the answer rather than being left for the caller to go and find. An answer about a machine is worth much less without one, and this repository has already been bitten by a cache with no age on it. A refusal or a partial failure moves last_seen and nothing else: neither is an account of what the machine holds, and recording one as though it were would tell a rebuilding node to remove what it still has.
This commit is contained in:
@@ -106,3 +106,25 @@ var _ Enroller = Enrolment{}
|
||||
|
||||
// ErrNoBrokerManagement is returned when an account cannot be made because nothing was configured.
|
||||
var ErrNoBrokerManagement = errors.New("no broker management configured")
|
||||
|
||||
// Heard records what a node reported about itself.
|
||||
//
|
||||
// A node states; the owning context writes (novox/hq ADR 0006). What a node says it applied is
|
||||
// its own account of its own machine, kept as a copy for recovery — so this writes it down and
|
||||
// decides nothing from it.
|
||||
func (e Enrolment) Heard(ctx context.Context, report Report) error {
|
||||
if report.Node == "" {
|
||||
return errors.New("a report named no node")
|
||||
}
|
||||
node, err := e.Inventory.NodeByName(ctx, report.Node)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
// A refusal or a failure is not an account of what the machine holds, so it moves last_seen
|
||||
// and nothing else. Recording a partial list as though it were the whole would tell a
|
||||
// rebuilding node to remove what it still has.
|
||||
if report.Refused != "" || len(report.Failed) > 0 {
|
||||
return e.Inventory.Seen(ctx, node.ID)
|
||||
}
|
||||
return e.Inventory.RecordOwned(ctx, node.ID, report.Applied)
|
||||
}
|
||||
|
||||
+17
-2
@@ -28,15 +28,22 @@ type Enroller interface {
|
||||
}
|
||||
|
||||
// Server consumes what nodes say.
|
||||
// Listener is what the control plane does with a report. Separate from Enroller so the two can
|
||||
// be given independently, and so a server that only sends declarations needs neither.
|
||||
type Listener interface {
|
||||
Heard(ctx context.Context, report Report) error
|
||||
}
|
||||
|
||||
type Server struct {
|
||||
conn *amqp.Connection
|
||||
channel *amqp.Channel
|
||||
enroller Enroller
|
||||
listener Listener
|
||||
log *log.Logger
|
||||
}
|
||||
|
||||
// Connect opens the control plane's own connection to the broker.
|
||||
func Connect(enroller Enroller) (*Server, error) {
|
||||
func Connect(enroller Enroller, listener Listener) (*Server, error) {
|
||||
url := strings.TrimSpace(os.Getenv(AMQPVar))
|
||||
if url == "" {
|
||||
return nil, fmt.Errorf(
|
||||
@@ -79,7 +86,7 @@ func Connect(enroller Enroller) (*Server, error) {
|
||||
}
|
||||
}
|
||||
|
||||
return &Server{conn: conn, channel: channel, enroller: enroller,
|
||||
return &Server{conn: conn, channel: channel, enroller: enroller, listener: listener,
|
||||
log: log.New(os.Stdout, "", log.LstdFlags)}, nil
|
||||
}
|
||||
|
||||
@@ -161,6 +168,14 @@ func (s *Server) handleReport(delivery amqp.Delivery) {
|
||||
_ = delivery.Reject(false)
|
||||
return
|
||||
}
|
||||
if s.listener != nil {
|
||||
if err := s.listener.Heard(context.Background(), report); err != nil {
|
||||
// Said rather than swallowed. A report the mesh heard and failed to write down is a
|
||||
// node whose recovery copy is silently older than it looks.
|
||||
s.log.Printf("could not record %s's report: %v", report.Node, err)
|
||||
}
|
||||
}
|
||||
|
||||
switch {
|
||||
case report.Refused != "":
|
||||
s.log.Printf("%s refused a declaration: %s", report.Node, report.Refused)
|
||||
|
||||
Reference in New Issue
Block a user