The mesh names what may go from its own build records — a digest it did not record making is never named, which is what keeps the sweep away from the images genesis pushed. An artifact stays because a definition the mesh holds names it, or because it belongs to one of the five most recent successful builds of its module. internal/artifacts asks the store to let go of one; internal/inventory decides and remembers (migration 0055); the sweep runs after a build the mesh recorded, which is when both the bytes and the keep set moved. Never fatal to a build. And the manifest side of while-stopped, refused from the definition alone: no schedule, run-once, a container the module does not declare, itself.
24 lines
1.4 KiB
SQL
24 lines
1.4 KiB
SQL
-- What the artifact store no longer keeps (novox/hq ADR 0189, issue 108).
|
|
--
|
|
-- The mesh removes from its store only what it put there and can account for: every digest it
|
|
-- could remove is already in a build record, so the sweep reads its own records rather than
|
|
-- enumerating the store. What it does not get from those records is whether it has already
|
|
-- removed something -- `build.made` says what that build published, for ever, which is history
|
|
-- and not an index of what is on disk.
|
|
--
|
|
-- Without this the sweep would reissue a delete for every artifact it has ever collected, every
|
|
-- time it runs, and each one would answer 404 -- a number of requests that grows with the mesh's
|
|
-- whole history and never shrinks.
|
|
--
|
|
-- Keyed by the reference as the mesh records it (`artifact-store://<module>/<artifact>@sha256:…`),
|
|
-- because that is the identity the record uses everywhere else. Not a foreign key to build: two
|
|
-- builds can publish the same digest (the same source built twice produces the same bytes), and
|
|
-- what is collected is the artifact, not the attempt that made it.
|
|
create table artifact_collected (
|
|
reference text primary key,
|
|
|
|
-- When the store answered. Kept so a reader of an old build record can tell "this artifact is
|
|
-- gone" from "this artifact was never there", which are different kinds of surprise.
|
|
at timestamptz not null default now()
|
|
);
|