Files
mesh-controller/internal/inventory/migrations/0073-a-build-rolls-out-gated-and-rolls-back.sql
T
jochen 2bfa6ae4a0 No build reaches a machine without a gate; a release plan walks what waits (hq ADR 0236)
A send carries the machine's whole declaration, so at the switch to roll the next send of
anything would have carried the old default's backlog, unjudged, to every machine. A gated
send now carries and judges everything waiting on its machine; every other send is refused
or leaves the machine; a release plan walks what waits one machine at a time, the control
node last, and one that fails holds the next until a person releases it.
2026-10-06 19:14:25 +02:00

73 lines
4.7 KiB
SQL

-- A module's build rolls out one machine first, judged at a gate, and rolls back there when the gate
-- fails (novox/hq ADR 0236, to-be 45 §8, Phase 4).
--
-- 1. The upgrade policy becomes a person's choice over the module's own word. Until now every module
-- held a policy here, 'record' unless a person had said 'roll-out', and nothing distinguished a
-- 'record' somebody chose from the default it always was. From here a null policy is no choice: the
-- module's manifest decides (its `upgrade`, its data, whether it is the bus), and its default is to
-- roll out. A 'roll-out' a person chose is kept as their choice. A 'record' is the old default and
-- becomes no choice — ADR 0236 decides it, and lists every module's resulting policy; a person who
-- wants one held again says so with `upgrade <module> record --why`, which is kept with its why.
alter table module alter column upgrade drop not null;
alter table module alter column upgrade drop default;
alter table module drop constraint if exists module_upgrade_check;
alter table module add constraint module_upgrade_chosen check (upgrade is null or upgrade in ('record', 'roll-out'));
update module set upgrade = null where upgrade = 'record';
-- Why the person chose it, and who: said back by `upgrade`, so a held module says why it is held.
alter table module add column upgrade_why text not null default '';
alter table module add column upgrade_by text not null default '';
-- 2. The gate's verdict on each build a plan rolled out, one row per build: passed on its first machine,
-- or failed there and rolled back. **A build that failed its gate is marked, and is never sent again
-- automatically**: registration refuses it, and the rollback is attempted once per build — the row is
-- written before the rollback's send, so a controller replaced in between does not send it twice.
create table build_gate (
build text primary key,
module text not null,
-- The commit the build was made from, and the one the module was put back to.
commit_hash text not null default '',
previous text not null default '',
plan text not null default '',
-- The machines it was judged on: the first machine, and the bus holder when it went with it.
machines text[] not null default '{}',
-- 'passed', or 'failed'; and for a failed one how the rollback went: 'rolling-back', 'rolled-back',
-- or 'not-rolled-back' (no previous build to put back, or the send refused), said in `why`.
verdict text not null check (verdict in ('passed', 'failed')),
rollback text not null default '' check (rollback in ('', 'rolling-back', 'rolled-back', 'not-rolled-back')),
why text not null default '',
-- The core component it is, when it is one: mesh-controller, mesh-host, node-tools.
component text not null default '',
judging_from timestamptz,
judged_at timestamptz not null default now(),
epoch bigint
);
create index build_gate_module on build_gate (module, judged_at desc);
-- 3. The bus's planned step (to-be 45 §8): a bus upgrade is never rolled out; a person starts it, with
-- why, after its streams are snapshotted, and it is checked after. One row per step; the open one is
-- the step running, which the self-check says as `bus-maintenance` until the bus is healthy again or
-- the step's bound passes and it is said failed, with its snapshot as the way back.
create table bus_step (
id bigserial primary key,
module text not null,
machines text[] not null default '{}',
from_build text not null default '',
to_build text not null default '',
-- Where the streams' snapshot is: taken by the mesh, or one a person says they took.
snapshot text not null,
-- Whether the new version can be reverted by putting the old one back, as the person said it.
reversible boolean not null,
by_whom text not null default '',
why text not null,
started timestamptz not null default now(),
ended timestamptz,
-- '', then 'done' or 'failed', with what was found.
outcome text not null default '' check (outcome in ('', 'done', 'failed')),
found text not null default ''
);
-- 4. A release plan (ADR 0236): the builds that wait for a gate — the backlog the old default left, and
-- whatever a plan built and did not send — walked through the machines one at a time, each judged
-- before the next. Its walk is kept with the plan.
alter table release_plan add column release jsonb;