A take is a comparison: the host's facts, former targets, and strays (hq ADR 0163)
Every held thing carries what a take compares: for a found container its image and the image's date, the networks it is on and the other containers on each, its mounts and published ports, beside the declared image (and its date once pulled), ports and volumes, with the downgrade decided when both dates are known; for a found file whether the declared content differs and how, as lines lost and lines new. A resource whose target moved keeps the former target on record as an orphan, so the next apply removes the container or file the host wrote under the old name (issue 097). Every apply reports the strays: containers the mesh neither wrote nor holds.
This commit is contained in:
+125
-4
@@ -8,6 +8,7 @@ import (
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"sort"
|
||||
"strings"
|
||||
"syscall"
|
||||
"time"
|
||||
@@ -433,6 +434,32 @@ type foundContainer struct {
|
||||
id string
|
||||
running bool
|
||||
spec string
|
||||
// What a take compares (novox/hq ADR 0163): the image and its id, the networks the container
|
||||
// is on, its mounts and its published ports — empty from a runtime (or a test's fake) that
|
||||
// answers the short form.
|
||||
image string
|
||||
imageID string
|
||||
networks []string
|
||||
mounts []string
|
||||
ports []string
|
||||
}
|
||||
|
||||
// foundFormat is what inspectFound asks the runtime for, tab-separated: the three a hold has
|
||||
// always needed, then the facts a take compares.
|
||||
const foundFormat = "{{.Id}}\t{{.State.Running}}\t{{index .Config.Labels \"" + specLabel + "\"}}" +
|
||||
"\t{{.Config.Image}}\t{{.Image}}" +
|
||||
"\t{{range $k, $v := .NetworkSettings.Networks}}{{$k}},{{end}}" +
|
||||
"\t{{range .Mounts}}{{.Source}}:{{.Destination}},{{end}}" +
|
||||
"\t{{range $p, $b := .NetworkSettings.Ports}}{{$p}}{{range $b}}>{{.HostIp}}:{{.HostPort}}{{end}},{{end}}"
|
||||
|
||||
func splitList(s string) []string {
|
||||
var out []string
|
||||
for _, part := range strings.Split(s, ",") {
|
||||
if part = strings.TrimSpace(part); part != "" {
|
||||
out = append(out, part)
|
||||
}
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// inspectFound reads a container by name the way a hold needs it: its id, whether it runs, and
|
||||
@@ -451,8 +478,7 @@ func inspectFound(ctx context.Context, name string, run Runner) (foundContainer,
|
||||
if err != nil {
|
||||
return foundContainer{}, false, fmt.Errorf("%w, so nothing can be said about %q", err, name)
|
||||
}
|
||||
out, err := run(ctx, cri, "container", "inspect", "--format",
|
||||
"{{.Id}}\t{{.State.Running}}\t{{index .Config.Labels \""+specLabel+"\"}}", name)
|
||||
out, err := run(ctx, cri, "container", "inspect", "--format", foundFormat, name)
|
||||
if err != nil {
|
||||
if absent(err) {
|
||||
return foundContainer{}, false, nil
|
||||
@@ -466,14 +492,100 @@ func inspectFound(ctx context.Context, name string, run Runner) (foundContainer,
|
||||
name, err)
|
||||
}
|
||||
parts := strings.Split(strings.TrimSpace(out), "\t")
|
||||
for len(parts) < 3 {
|
||||
for len(parts) < 8 {
|
||||
parts = append(parts, "")
|
||||
}
|
||||
spec := strings.TrimSpace(parts[2])
|
||||
if spec == "<no value>" {
|
||||
spec = ""
|
||||
}
|
||||
return foundContainer{id: strings.TrimSpace(parts[0]), running: parts[1] == "true", spec: spec}, true, nil
|
||||
return foundContainer{id: strings.TrimSpace(parts[0]), running: parts[1] == "true", spec: spec,
|
||||
image: strings.TrimSpace(parts[3]), imageID: strings.TrimSpace(parts[4]),
|
||||
networks: splitList(parts[5]), mounts: splitList(parts[6]), ports: splitList(parts[7])}, true, nil
|
||||
}
|
||||
|
||||
// factsOf is what a take would compare for a found container (novox/hq ADR 0163): the found
|
||||
// image and when it was made, the networks and who else is on them, mounts and ports — beside
|
||||
// what the module declares, and the declared image's date when that image is on the machine.
|
||||
// Every question the runtime cannot answer leaves its fact empty; a preview says so rather than
|
||||
// guesses.
|
||||
func factsOf(ctx context.Context, seen foundContainer, res *declaration.Container, run Runner) *Facts {
|
||||
cri, err := containerRuntime(ctx, run)
|
||||
if err != nil {
|
||||
return nil
|
||||
}
|
||||
f := &store.Facts{Image: seen.image, Mounts: seen.mounts, Ports: seen.ports,
|
||||
DeclaredImage: res.Image, DeclaredPorts: res.Ports, DeclaredVolumes: res.Volumes}
|
||||
if seen.imageID != "" {
|
||||
if out, err := run(ctx, cri, "image", "inspect", "--format", "{{.Created}}", seen.imageID); err == nil {
|
||||
f.ImageCreated = strings.TrimSpace(out)
|
||||
}
|
||||
}
|
||||
if res.Image != "" {
|
||||
if out, err := run(ctx, cri, "image", "inspect", "--format", "{{.Created}}", res.Image); err == nil {
|
||||
f.DeclaredImageCreated = strings.TrimSpace(out)
|
||||
}
|
||||
}
|
||||
if found, err := time.Parse(time.RFC3339Nano, f.ImageCreated); err == nil {
|
||||
if declared, err := time.Parse(time.RFC3339Nano, f.DeclaredImageCreated); err == nil {
|
||||
f.Downgrade = declared.Before(found)
|
||||
}
|
||||
}
|
||||
for _, network := range seen.networks {
|
||||
if f.Networks == nil {
|
||||
f.Networks = map[string][]string{}
|
||||
}
|
||||
var members []string
|
||||
if out, err := run(ctx, cri, "network", "inspect", "--format",
|
||||
"{{range .Containers}}{{.Name}},{{end}}", network); err == nil {
|
||||
for _, m := range splitList(out) {
|
||||
if m != res.Name {
|
||||
members = append(members, m)
|
||||
}
|
||||
}
|
||||
}
|
||||
sort.Strings(members)
|
||||
f.Networks[network] = members
|
||||
}
|
||||
return (*Facts)(f)
|
||||
}
|
||||
|
||||
// Facts is store.Facts, named here so hold's callers read as one vocabulary.
|
||||
type Facts = store.Facts
|
||||
|
||||
// differenceOf is how a found file differs from the declared content: the lines only the found
|
||||
// file has, marked -, then the lines only the declared content has, marked +, in their own order,
|
||||
// bounded so a report stays a report. Not a diff tool's output: the question a take answers is
|
||||
// "what would be lost and what would be new", and that is these two lists.
|
||||
func differenceOf(found, declared string) (bool, []string) {
|
||||
if found == declared {
|
||||
return false, nil
|
||||
}
|
||||
const bound = 40
|
||||
count := func(s string) map[string]int {
|
||||
out := map[string]int{}
|
||||
for _, line := range strings.Split(s, "\n") {
|
||||
out[line]++
|
||||
}
|
||||
return out
|
||||
}
|
||||
inFound, inDeclared := count(found), count(declared)
|
||||
var out []string
|
||||
add := func(mark, s string, other map[string]int) {
|
||||
seen := map[string]int{}
|
||||
for _, line := range strings.Split(s, "\n") {
|
||||
seen[line]++
|
||||
if seen[line] > other[line] && len(out) < bound {
|
||||
out = append(out, mark+" "+line)
|
||||
}
|
||||
}
|
||||
}
|
||||
add("-", found, inDeclared)
|
||||
add("+", declared, inFound)
|
||||
if len(out) >= bound {
|
||||
out = append(out, "… and more")
|
||||
}
|
||||
return true, out
|
||||
}
|
||||
|
||||
// absent is whether a runtime said the thing is not there, rather than failing to answer. Its own
|
||||
@@ -540,6 +652,12 @@ func hold(ctx context.Context, sys system.System, r declaration.Resource, module
|
||||
} else if digestOf(string(content)) != h.Digest {
|
||||
changed = "rewritten"
|
||||
}
|
||||
// What a take would replace it with, and how that differs (novox/hq ADR 0163): a
|
||||
// file declared whole is compared whole; one written into is not replaced at all.
|
||||
if res.Into == "" {
|
||||
differs, lines := differenceOf(string(content), res.Content)
|
||||
h.Facts = &Facts{Differs: differs, Difference: lines}
|
||||
}
|
||||
}
|
||||
case *declaration.Directory:
|
||||
info, err := os.Lstat(res.Path)
|
||||
@@ -628,6 +746,9 @@ func hold(ctx context.Context, sys system.System, r declaration.Resource, module
|
||||
case h.Running && !seen.running:
|
||||
changed = "stopped"
|
||||
}
|
||||
if exists {
|
||||
h.Facts = factsOf(ctx, seen, res, run)
|
||||
}
|
||||
default:
|
||||
return out, h, fmt.Errorf("a %s cannot be held", r.Kind())
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user