-- A module's build rolls out one machine first, judged at a gate, and rolls back there when the gate -- fails (novox/hq ADR 0236, to-be 45 §8, Phase 4). -- -- 1. The upgrade policy becomes a person's choice over the module's own word. Until now every module -- held a policy here, 'record' unless a person had said 'roll-out', and nothing distinguished a -- 'record' somebody chose from the default it always was. From here a null policy is no choice: the -- module's manifest decides (its `upgrade`, its data, whether it is the bus), and its default is to -- roll out. A 'roll-out' a person chose is kept as their choice. A 'record' is the old default and -- becomes no choice — ADR 0236 decides it, and lists every module's resulting policy; a person who -- wants one held again says so with `upgrade record --why`, which is kept with its why. alter table module alter column upgrade drop not null; alter table module alter column upgrade drop default; alter table module drop constraint if exists module_upgrade_check; alter table module add constraint module_upgrade_chosen check (upgrade is null or upgrade in ('record', 'roll-out')); update module set upgrade = null where upgrade = 'record'; -- Why the person chose it, and who: said back by `upgrade`, so a held module says why it is held. alter table module add column upgrade_why text not null default ''; alter table module add column upgrade_by text not null default ''; -- 2. The gate's verdict on each build a plan rolled out, one row per build: passed on its first machine, -- or failed there and rolled back. **A build that failed its gate is marked, and is never sent again -- automatically**: registration refuses it, and the rollback is attempted once per build — the row is -- written before the rollback's send, so a controller replaced in between does not send it twice. create table build_gate ( build text primary key, module text not null, -- The commit the build was made from, and the one the module was put back to. commit_hash text not null default '', previous text not null default '', plan text not null default '', -- The machines it was judged on: the first machine, and the bus holder when it went with it. machines text[] not null default '{}', -- 'passed', or 'failed'; and for a failed one how the rollback went: 'rolling-back', 'rolled-back', -- or 'not-rolled-back' (no previous build to put back, or the send refused), said in `why`. verdict text not null check (verdict in ('passed', 'failed')), rollback text not null default '' check (rollback in ('', 'rolling-back', 'rolled-back', 'not-rolled-back')), why text not null default '', -- The core component it is, when it is one: mesh-controller, mesh-host, node-tools. component text not null default '', judging_from timestamptz, judged_at timestamptz not null default now(), epoch bigint ); create index build_gate_module on build_gate (module, judged_at desc); -- 3. The bus's planned step (to-be 45 §8): a bus upgrade is never rolled out; a person starts it, with -- why, after its streams are snapshotted, and it is checked after. One row per step; the open one is -- the step running, which the self-check says as `bus-maintenance` until the bus is healthy again or -- the step's bound passes and it is said failed, with its snapshot as the way back. create table bus_step ( id bigserial primary key, module text not null, machines text[] not null default '{}', from_build text not null default '', to_build text not null default '', -- Where the streams' snapshot is: taken by the mesh, or one a person says they took. snapshot text not null, -- Whether the new version can be reverted by putting the old one back, as the person said it. reversible boolean not null, by_whom text not null default '', why text not null, started timestamptz not null default now(), ended timestamptz, -- '', then 'done' or 'failed', with what was found. outcome text not null default '' check (outcome in ('', 'done', 'failed')), found text not null default '' ); -- 4. A release plan (ADR 0236): the builds that wait for a gate — the backlog the old default left, and -- whatever a plan built and did not send — walked through the machines one at a time, each judged -- before the next. Its walk is kept with the plan. alter table release_plan add column release jsonb;