The gate judged a module by what the mesh saw from outside, so a container that crash-looped after it applied passed it. Each machine's node-engine now states the health of every long-running resource it runs; the controller keeps the newest statement per machine, raises module.<module>.<machine>.unhealthy on the second statement in a row, clears it on the first that does not say it, and the gate passes a module only when every long-running resource of it is stated healthy since the send. An engine that states nothing is judged as before.
27 lines
1.7 KiB
SQL
27 lines
1.7 KiB
SQL
-- A module says how it is healthy, and the node-engine judges it (novox/hq ADR 0240, to-be 48 Phase A).
|
|
--
|
|
-- Every machine's node-engine states the health of every long-running resource it runs for a module — a
|
|
-- container that stays up, a process that stays up, a service stated running — in every report and as an
|
|
-- event between reports. The controller keeps the newest statement per machine, here, so the release
|
|
-- gate, `node show` and a controller started again all read the same word; and with it, per module, how
|
|
-- many statements in a row said a resource of it was unhealthy — `module.<module>.<machine>.unhealthy` is
|
|
-- raised on the second (ADR 0240 §4).
|
|
--
|
|
-- One row per machine, replaced, as node_report is: the question is the machine's state now. A machine
|
|
-- whose node-engine is older than the judging has no row, and its health is not known — never healthy,
|
|
-- never unhealthy.
|
|
create table node_health (
|
|
node uuid primary key references node(id) on delete cascade,
|
|
-- The statement's version (the engine's liveness contract).
|
|
contract int not null,
|
|
-- When the node-engine looked, on the machine's clock: the order of its statements. An older one
|
|
-- than this is refused.
|
|
said_at timestamptz not null,
|
|
-- When this controller heard it, on its own: what "since the send" is judged by.
|
|
heard_at timestamptz not null default now(),
|
|
-- [{module, resource, kind, target, state, reason, since, streak, restarts}], as the engine said them.
|
|
resources jsonb not null default '[]',
|
|
-- {module: statements in a row saying a resource of it is unhealthy}.
|
|
streaks jsonb not null default '{}'
|
|
);
|