Files
mesh-controller/internal/inventory/migrations/0072-a-module-declares-the-data-it-holds.sql
T
jochen abf9125689 Measure each item its own way; never compare a partial size (hq ADR 0233)
A walk over a large library every hour loads the array that protects it. An item now says how it
is measured — a bounded daily walk, a dataset's counters, or its top level only — and a size that
is a lower bound is kept as such and never read as a shrink.
2026-10-06 17:00:22 +02:00

69 lines
3.4 KiB
SQL

-- The data a module declares, as the mesh found it on each machine (novox/hq ADR 0233).
--
-- A module's manifest says what data it keeps and of which class. The self-check asks each machine's
-- backup holder what it measured of every declared item — its size, its last write, its last good
-- backup — and keeps that here: so a shrink is read against what the item held before, an item a
-- machine no longer declares is still known to be there, and an empty copy of an item is told from a
-- full one somewhere else.
--
-- **Keyed by the machine's name, not a reference.** The data outlives the machine record, as a
-- binding's provider does (migration 0071): a machine leaving the mesh must not turn the record of
-- what it holds into nothing.
--
-- **Retired, never removed.** An irreplaceable or valuable item in a module's own directory that its
-- machine no longer declares — its module unassigned — is marked retired, with when and why, and stays
-- until a person deletes it through `cleanup delete` (ADR 0230); the deletion is recorded here too,
-- never by dropping the row. An item on an operator's path (an access) is never the mesh's to retire.
--
-- Numbered 0072, past 0071, the highest on main or any open branch when this was written.
create table data_item (
machine text not null,
module text not null,
item text not null,
class text not null,
-- Whether it is in the module's own directory (the mesh's to retire) or an operator's path, and
-- how it is protected: backup, redundancy, both, or none.
owned boolean not null default true,
protection text not null default '',
-- Where it is on the machine, as the backup holder last said; empty until one has.
path text not null default '',
first_seen timestamptz not null default now(),
-- When a composition of the machine last declared it.
declared_at timestamptz not null default now(),
-- The newest measurement: size in bytes, the newest write inside it, and when it was measured.
size_bytes bigint,
last_write timestamptz,
measured_at timestamptz,
-- The newest good backup that covers it.
last_backup timestamptz,
-- What the holder could not measure, when it could not: the path gone, a walk refused.
measure_error text,
-- What the newest size is: exact, a dataset's whole size, partial (a lower bound) or none.
precision text,
-- The redundant storage it is on, as the holder read it: zfs, md or btrfs, which pool or device,
-- whether it is healthy, and what it said.
redundancy_kind text,
redundancy_where text,
redundancy_healthy boolean,
redundancy_said text,
retired_at timestamptz,
retired_why text,
deleted_at timestamptz,
deleted_by text,
deleted_why text,
primary key (machine, module, item)
);
-- One row per measurement kept, at most one an hour per item, for ninety days: what a shrink is
-- read against. Only a comparable size is kept: exact, or a dataset's own counters — never a partial
-- walk's lower bound.
create table data_reading (
machine text not null,
module text not null,
item text not null,
at timestamptz not null,
size_bytes bigint not null,
last_write timestamptz,
primary key (machine, module, item, at)
);