A taken tunnel's found configuration is retired once the take is proven (hq ADR 0119)

Kept on disk it was the take's fallback; once the mesh's interface is up in its place and a peer
has handshaken with it, it is an unmaintained way back onto the network, held for ever. It is now
removed from where its unit reads it, its kept original verified first and left as it is, and the
hold ends. Until proven — no handshake, or wg not answering — it is kept and the report says why.
The retirement is recorded apart from holds, so later applies, an undeclare, and a reassignment
find it retired rather than missing, and nothing writes it back.
This commit is contained in:
jochen
2026-09-27 00:47:57 +02:00
parent 23a4436499
commit b462f461c6
9 changed files with 628 additions and 14 deletions
+58
View File
@@ -170,6 +170,28 @@ type State struct {
// the bundle carried in the binary is not applied again: what genesis applied was rewritten
// for this machine, and the mesh has said more since (novox/hq issue 104).
Genesis *Genesis `json:"genesis,omitempty"`
// Retired is each found tunnel configuration the mesh removed from where its unit reads it,
// once the private network's take of that tunnel was proven (novox/hq ADR 0119).
//
// **Not a hold, and never released with one.** The hold on the found configuration ends at the
// retirement — what it held for has been replaced, and the node stops reporting it — so without
// this the next apply would find no hold and no file and read the take as one whose
// configuration vanished before it could be kept. It is kept whether or not the private
// network stays declared: undeclaring brings nothing back (ADR 0118), and a private network
// assigned again finds the tunnel's configuration retired rather than missing.
Retired []Retired `json:"retired,omitempty"`
}
// Retired is a found configuration the mesh removed once what replaced it was proven (novox/hq
// ADR 0119): where it was, under which hold it had been kept, and where its original still is.
type Retired struct {
ID string `json:"id"`
Path string `json:"path"`
// Kept is the original as found (novox/hq ADR 0100) — the record of what the predecessor was,
// and a person's way back if one is ever wanted. The mesh never copies it back.
Kept string `json:"kept"`
At time.Time `json:"at"`
}
// Modes a node can be in (novox/hq ADR 0100).
@@ -312,6 +334,42 @@ func (s *State) Release(id string) {
}
}
// RetiredAt returns the retirement of the found configuration at a path, if the mesh retired one.
func (s State) RetiredAt(path string) (Retired, bool) {
for _, r := range s.Retired {
if r.Path == path {
return r, true
}
}
return Retired{}, false
}
// RecordRetired adds or replaces the retirement of the configuration at one path.
func (s *State) RecordRetired(r Retired) {
for i, existing := range s.Retired {
if existing.Path == r.Path {
s.Retired[i] = r
return
}
}
s.Retired = append(s.Retired, r)
}
// Unretire forgets a retirement: the configuration is at its path again, put back by a person, and
// is found — and kept — afresh.
func (s *State) Unretire(path string) {
kept := s.Retired[:0]
for _, r := range s.Retired {
if r.Path != path {
kept = append(kept, r)
}
}
s.Retired = kept
if len(s.Retired) == 0 {
s.Retired = nil
}
}
// Find returns what was applied under an identity.
func (s State) Find(id string) (Applied, bool) {
for _, r := range s.Resources {