Somebody editing a managed file is now visible instead of mysterious
Asked how the mesh would know if somebody edited their hosts file. It would not. The file was rewritten within five minutes and the outcome said "updated" -- which is exactly what the mesh changing its own mind looks like. So the change vanished, nothing anywhere said why, and the obvious thing to do is edit it again. The host now records a digest of what it wrote, which is enough to tell the two apart on the next pass: the file matches the declaration unchanged it matches what was last written updated -- the mesh changed its mind it matches neither corrected -- somebody changed it here The machine is put back either way, because holding it to what it was told is the point. What changes is that it says so. A digest rather than the content: the store is read on every reconcile and sits beside the state on disk, and keeping every managed file twice would make it grow with the size of the machine rather than with the number of resources.
This commit is contained in:
@@ -47,6 +47,16 @@ type Applied struct {
|
||||
// re-reading a declaration that may no longer exist.
|
||||
Target string `json:"target"`
|
||||
AppliedAt time.Time `json:"applied_at"`
|
||||
|
||||
// Wrote is a digest of what this host last put there, for resources where that is a
|
||||
// meaningful question.
|
||||
//
|
||||
// Without it, a file that does not match the declaration has two possible explanations and
|
||||
// the host cannot tell them apart: the mesh changed what it wants, or somebody edited the
|
||||
// machine. Both end with the file being rewritten, so the outcome is identical — and a
|
||||
// person who edits a managed file watches their change vanish every few minutes with nothing
|
||||
// anywhere saying why.
|
||||
Wrote string `json:"wrote,omitempty"`
|
||||
}
|
||||
|
||||
// State is the whole of what a node knows about what it has done.
|
||||
|
||||
Reference in New Issue
Block a user