The seat set was a Go slice compiled into the controller and referenced by name everywhere, so changing it meant a rebuild and a freeze-prone deploy. It is now a table: catalogue keeps the shipped set as defaultSeats (the seed and the fallback) and a loadable working set; inventory adds the seat table (migration 0034), Seats to read it, and SeedSeats to fill it idempotently without overwriting an operator's edit; migrate seeds it; openInventory loads it, and an empty or unreadable table leaves the compiled defaults in force so it can never brick the control plane's boot. Behaviour-neutral: the seeded table equals the defaults. Phase 2 (reference by a stable id so a rename touches no manifest or code, and the builder reads the set from the mesh) follows.
18 lines
984 B
SQL
18 lines
984 B
SQL
-- The seats are data the control plane owns, not a slice compiled into it (novox/hq ADR 0122).
|
|
--
|
|
-- Until this, the closed set 0110 defines lived only as a Go slice, referenced by name everywhere,
|
|
-- so renaming a seat or adding one meant a controller rebuild and a mesh-wide, freeze-prone deploy.
|
|
-- The set is now a table: one row per seat, seeded from the binary's defaults the first time the
|
|
-- control plane comes up, and thereafter the live copy the control plane reads and an operator can
|
|
-- change. A rename becomes an update here rather than a release.
|
|
--
|
|
-- The name is the key for now, because claims and held records still reference a seat by name; the
|
|
-- move to a stable id that a rename does not touch is the next step (ADR 0122). `delivers` is empty
|
|
-- for a seat that answers for no provision, matching the compiled default.
|
|
create table seat (
|
|
name text primary key,
|
|
scope text not null,
|
|
delivers text not null default '',
|
|
decided text not null
|
|
);
|