A walk over a large library every hour loads the array that protects it. An item now says how it is measured — a bounded daily walk, a dataset's counters, or its top level only — and a size that is a lower bound is kept as such and never read as a shrink.
69 lines
3.4 KiB
SQL
69 lines
3.4 KiB
SQL
-- The data a module declares, as the mesh found it on each machine (novox/hq ADR 0233).
|
|
--
|
|
-- A module's manifest says what data it keeps and of which class. The self-check asks each machine's
|
|
-- backup holder what it measured of every declared item — its size, its last write, its last good
|
|
-- backup — and keeps that here: so a shrink is read against what the item held before, an item a
|
|
-- machine no longer declares is still known to be there, and an empty copy of an item is told from a
|
|
-- full one somewhere else.
|
|
--
|
|
-- **Keyed by the machine's name, not a reference.** The data outlives the machine record, as a
|
|
-- binding's provider does (migration 0071): a machine leaving the mesh must not turn the record of
|
|
-- what it holds into nothing.
|
|
--
|
|
-- **Retired, never removed.** An irreplaceable or valuable item in a module's own directory that its
|
|
-- machine no longer declares — its module unassigned — is marked retired, with when and why, and stays
|
|
-- until a person deletes it through `cleanup delete` (ADR 0230); the deletion is recorded here too,
|
|
-- never by dropping the row. An item on an operator's path (an access) is never the mesh's to retire.
|
|
--
|
|
-- Numbered 0072, past 0071, the highest on main or any open branch when this was written.
|
|
create table data_item (
|
|
machine text not null,
|
|
module text not null,
|
|
item text not null,
|
|
class text not null,
|
|
-- Whether it is in the module's own directory (the mesh's to retire) or an operator's path, and
|
|
-- how it is protected: backup, redundancy, both, or none.
|
|
owned boolean not null default true,
|
|
protection text not null default '',
|
|
-- Where it is on the machine, as the backup holder last said; empty until one has.
|
|
path text not null default '',
|
|
first_seen timestamptz not null default now(),
|
|
-- When a composition of the machine last declared it.
|
|
declared_at timestamptz not null default now(),
|
|
-- The newest measurement: size in bytes, the newest write inside it, and when it was measured.
|
|
size_bytes bigint,
|
|
last_write timestamptz,
|
|
measured_at timestamptz,
|
|
-- The newest good backup that covers it.
|
|
last_backup timestamptz,
|
|
-- What the holder could not measure, when it could not: the path gone, a walk refused.
|
|
measure_error text,
|
|
-- What the newest size is: exact, a dataset's whole size, partial (a lower bound) or none.
|
|
precision text,
|
|
-- The redundant storage it is on, as the holder read it: zfs, md or btrfs, which pool or device,
|
|
-- whether it is healthy, and what it said.
|
|
redundancy_kind text,
|
|
redundancy_where text,
|
|
redundancy_healthy boolean,
|
|
redundancy_said text,
|
|
retired_at timestamptz,
|
|
retired_why text,
|
|
deleted_at timestamptz,
|
|
deleted_by text,
|
|
deleted_why text,
|
|
primary key (machine, module, item)
|
|
);
|
|
|
|
-- One row per measurement kept, at most one an hour per item, for ninety days: what a shrink is
|
|
-- read against. Only a comparable size is kept: exact, or a dataset's own counters — never a partial
|
|
-- walk's lower bound.
|
|
create table data_reading (
|
|
machine text not null,
|
|
module text not null,
|
|
item text not null,
|
|
at timestamptz not null,
|
|
size_bytes bigint not null,
|
|
last_write timestamptz,
|
|
primary key (machine, module, item, at)
|
|
);
|