A send carries the machine's whole declaration, so at the switch to roll the next send of anything would have carried the old default's backlog, unjudged, to every machine. A gated send now carries and judges everything waiting on its machine; every other send is refused or leaves the machine; a release plan walks what waits one machine at a time, the control node last, and one that fails holds the next until a person releases it.
73 lines
4.7 KiB
SQL
73 lines
4.7 KiB
SQL
-- A module's build rolls out one machine first, judged at a gate, and rolls back there when the gate
|
|
-- fails (novox/hq ADR 0236, to-be 45 §8, Phase 4).
|
|
--
|
|
-- 1. The upgrade policy becomes a person's choice over the module's own word. Until now every module
|
|
-- held a policy here, 'record' unless a person had said 'roll-out', and nothing distinguished a
|
|
-- 'record' somebody chose from the default it always was. From here a null policy is no choice: the
|
|
-- module's manifest decides (its `upgrade`, its data, whether it is the bus), and its default is to
|
|
-- roll out. A 'roll-out' a person chose is kept as their choice. A 'record' is the old default and
|
|
-- becomes no choice — ADR 0236 decides it, and lists every module's resulting policy; a person who
|
|
-- wants one held again says so with `upgrade <module> record --why`, which is kept with its why.
|
|
alter table module alter column upgrade drop not null;
|
|
alter table module alter column upgrade drop default;
|
|
alter table module drop constraint if exists module_upgrade_check;
|
|
alter table module add constraint module_upgrade_chosen check (upgrade is null or upgrade in ('record', 'roll-out'));
|
|
update module set upgrade = null where upgrade = 'record';
|
|
-- Why the person chose it, and who: said back by `upgrade`, so a held module says why it is held.
|
|
alter table module add column upgrade_why text not null default '';
|
|
alter table module add column upgrade_by text not null default '';
|
|
|
|
-- 2. The gate's verdict on each build a plan rolled out, one row per build: passed on its first machine,
|
|
-- or failed there and rolled back. **A build that failed its gate is marked, and is never sent again
|
|
-- automatically**: registration refuses it, and the rollback is attempted once per build — the row is
|
|
-- written before the rollback's send, so a controller replaced in between does not send it twice.
|
|
create table build_gate (
|
|
build text primary key,
|
|
module text not null,
|
|
-- The commit the build was made from, and the one the module was put back to.
|
|
commit_hash text not null default '',
|
|
previous text not null default '',
|
|
plan text not null default '',
|
|
-- The machines it was judged on: the first machine, and the bus holder when it went with it.
|
|
machines text[] not null default '{}',
|
|
-- 'passed', or 'failed'; and for a failed one how the rollback went: 'rolling-back', 'rolled-back',
|
|
-- or 'not-rolled-back' (no previous build to put back, or the send refused), said in `why`.
|
|
verdict text not null check (verdict in ('passed', 'failed')),
|
|
rollback text not null default '' check (rollback in ('', 'rolling-back', 'rolled-back', 'not-rolled-back')),
|
|
why text not null default '',
|
|
-- The core component it is, when it is one: mesh-controller, mesh-host, node-tools.
|
|
component text not null default '',
|
|
judging_from timestamptz,
|
|
judged_at timestamptz not null default now(),
|
|
epoch bigint
|
|
);
|
|
create index build_gate_module on build_gate (module, judged_at desc);
|
|
|
|
-- 3. The bus's planned step (to-be 45 §8): a bus upgrade is never rolled out; a person starts it, with
|
|
-- why, after its streams are snapshotted, and it is checked after. One row per step; the open one is
|
|
-- the step running, which the self-check says as `bus-maintenance` until the bus is healthy again or
|
|
-- the step's bound passes and it is said failed, with its snapshot as the way back.
|
|
create table bus_step (
|
|
id bigserial primary key,
|
|
module text not null,
|
|
machines text[] not null default '{}',
|
|
from_build text not null default '',
|
|
to_build text not null default '',
|
|
-- Where the streams' snapshot is: taken by the mesh, or one a person says they took.
|
|
snapshot text not null,
|
|
-- Whether the new version can be reverted by putting the old one back, as the person said it.
|
|
reversible boolean not null,
|
|
by_whom text not null default '',
|
|
why text not null,
|
|
started timestamptz not null default now(),
|
|
ended timestamptz,
|
|
-- '', then 'done' or 'failed', with what was found.
|
|
outcome text not null default '' check (outcome in ('', 'done', 'failed')),
|
|
found text not null default ''
|
|
);
|
|
|
|
-- 4. A release plan (ADR 0236): the builds that wait for a gate — the backlog the old default left, and
|
|
-- whatever a plan built and did not send — walked through the machines one at a time, each judged
|
|
-- before the next. Its walk is kept with the plan.
|
|
alter table release_plan add column release jsonb;
|