Compare commits
9
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
155689672c | ||
|
|
e82789a322 | ||
|
|
99562947f3 | ||
|
|
c171c64d3a | ||
|
|
0dc5515099 | ||
|
|
58c0e715c7 | ||
|
|
c5b229f95d | ||
|
|
a9c49724b5 | ||
|
|
296ec5ece6 |
@@ -152,7 +152,7 @@
|
|||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/var/lib/mesh-bus-conf/accounts.conf",
|
"path": "/var/lib/mesh-bus-conf/accounts.conf",
|
||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "// The first user list, carried by the installer because at genesis there is no mesh to\n// compose one. A bootstrap credential, rotated with the store's and replaced by the\n// controller's own composition from its first start onward.\naccounts {\n MESH {\n jetstream: enabled\n users = [\n { user: \"controller\", password: \"$2a$10$AHqJgOifIVbU41KmATiMhuXFs8xa7Wl2HuN4UVBCXdN2jIQzjqApy\", permissions: {\n publish: { allow: [\"$JS.API.>\", \"$JS.ACK.CONTROL.controller.>\", \"$JS.ACK.EVENTS.controller.>\", \"_INBOX.enrol.>\", \"mesh.control.>\", \"mesh.mod.*.tool.>\", \"mesh.node.>\", \"mesh.seat.mesh-build-machine.accept.>\"] }\n subscribe: { allow: [\"$JS.API.>\", \"_DELIVER.controller\", \"_DELIVER.controller.>\", \"_INBOX.controller.>\", \"mesh.control.>\", \"mesh.mod.mesh-catalog.event.catching-up\", \"mesh.mod.mesh-catalog.event.upgraded\", \"mesh.mod.gitea.event.pull.merged\", \"mesh.seat.mesh-build-machine.event.built\"] }\n allow_responses: { max: 1, ttl: \"1m\" }\n } }\n ]\n }\n}\n"
|
"content": "// The first user list, carried by the installer because at genesis there is no mesh to\n// compose one. A bootstrap credential, rotated with the store's and replaced by the\n// controller's own composition from its first start onward.\naccounts {\n MESH {\n jetstream: enabled\n users = [\n { user: \"controller\", password: \"$2a$10$AHqJgOifIVbU41KmATiMhuXFs8xa7Wl2HuN4UVBCXdN2jIQzjqApy\", permissions: {\n publish: { allow: [\"$JS.API.>\", \"$JS.ACK.CONTROL.controller.>\", \"$JS.ACK.EVENTS.controller.>\", \"_INBOX.enrol.>\", \"mesh.control.>\", \"mesh.mod.*.tool.>\", \"mesh.node.>\", \"mesh.seat.mesh-build-machine.accept.>\", \"mesh.seat.mesh-controller.event.applied\", \"mesh.seat.mesh-controller.event.built-before\", \"mesh.seat.mesh-controller.event.refused\"] }\n subscribe: { allow: [\"$JS.API.>\", \"_DELIVER.controller\", \"_DELIVER.controller.>\", \"_INBOX.controller.>\", \"mesh.control.>\", \"mesh.mod.mesh-catalog.event.catching-up\", \"mesh.mod.mesh-catalog.event.upgraded\", \"mesh.mod.gitea.event.pull.merged\", \"mesh.seat.mesh-build-machine.event.built\"] }\n allow_responses: { max: 1, ttl: \"1m\" }\n } }\n ]\n }\n}\n"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "broker",
|
"id": "broker",
|
||||||
|
|||||||
+68
-1
@@ -320,6 +320,9 @@ func ApplyKeeping(
|
|||||||
// is a different thing — one is "this machine could not do it", the other is "this was never
|
// is a different thing — one is "this machine could not do it", the other is "this was never
|
||||||
// a declaration", and they are fixed in different places.
|
// a declaration", and they are fixed in different places.
|
||||||
var failures []*Error
|
var failures []*Error
|
||||||
|
// Modules whose own step did not complete. What follows *within such a module* is not attempted;
|
||||||
|
// the rest of the machine is (novox/hq ADR 0136).
|
||||||
|
gated := map[string]bool{}
|
||||||
for i, resource := range ordered {
|
for i, resource := range ordered {
|
||||||
if !orphansRemoved && i == guardFirst {
|
if !orphansRemoved && i == guardFirst {
|
||||||
// **Only a guard that is up may let the filter go.** Removing the derived filter's
|
// **Only a guard that is up may let the filter go.** Removing the derived filter's
|
||||||
@@ -337,6 +340,17 @@ func ApplyKeeping(
|
|||||||
return report, known, err
|
return report, known, err
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
// **A module whose step did not complete is skipped from there on** (novox/hq ADR 0136).
|
||||||
|
// Reported rather than passed over in silence: "not attempted" and "nothing to do" are
|
||||||
|
// different answers, and only one of them is somebody's to fix.
|
||||||
|
if module, ours := moduleOf(resource.Identity()); ours && gated[module] {
|
||||||
|
report.Outcomes = append(report.Outcomes, Outcome{
|
||||||
|
ID: resource.Identity(), Type: string(resource.Kind()), Target: resource.Target(),
|
||||||
|
Action: "skipped", Detail: "a step this module declares did not complete",
|
||||||
|
})
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
|
||||||
// **On an adopted node, what is found is kept until its module is taken** (novox/hq ADR
|
// **On an adopted node, what is found is kept until its module is taken** (novox/hq ADR
|
||||||
// 0100, ADR 0103). Before anything is applied: whatever of a module not yet taken is
|
// 0100, ADR 0103). Before anything is applied: whatever of a module not yet taken is
|
||||||
// present with no record of this host making it — or would reach what is — is held as it
|
// present with no record of this host making it — or would reach what is — is held as it
|
||||||
@@ -465,9 +479,26 @@ func ApplyKeeping(
|
|||||||
gates = true
|
gates = true
|
||||||
}
|
}
|
||||||
if gates {
|
if gates {
|
||||||
|
failed.Gated = true
|
||||||
|
// **A module's step gates that module, not the machine** (novox/hq ADR 0136).
|
||||||
|
//
|
||||||
|
// Stopping the whole apply is what this loop's own comment above calls holding a
|
||||||
|
// machine hostage, and it was already rejected for every other shape (04-ISSUES/011).
|
||||||
|
// A step exists to make something true before the next thing in *its module* needs it
|
||||||
|
// — a store seeded before the broker starts, a schema prepared before the version
|
||||||
|
// that needs it runs — so that is exactly how far the gate reaches. Everything else
|
||||||
|
// on the machine is independent state and is attempted.
|
||||||
|
//
|
||||||
|
// An action still gates the machine: the bootstrap is a row of them, each making the
|
||||||
|
// next possible, and they belong to no module.
|
||||||
|
if module, ours := moduleOf(resource.Identity()); ours {
|
||||||
|
gated[module] = true
|
||||||
|
log(fmt.Sprintf(" gated %s.*: a step it declares did not complete, so the rest "+
|
||||||
|
"of it was not attempted", module))
|
||||||
|
continue
|
||||||
|
}
|
||||||
failed.Done = report
|
failed.Done = report
|
||||||
failed.Others = len(failures) - 1
|
failed.Others = len(failures) - 1
|
||||||
failed.Gated = true
|
|
||||||
return report, known, failed
|
return report, known, failed
|
||||||
}
|
}
|
||||||
continue
|
continue
|
||||||
@@ -1470,6 +1501,20 @@ func containerSpecReading(r *declaration.Container, declares, reads map[string]s
|
|||||||
for _, a := range r.Args {
|
for _, a := range r.Args {
|
||||||
b.WriteString("arg " + a + "\n")
|
b.WriteString("arg " + a + "\n")
|
||||||
}
|
}
|
||||||
|
// **The mesh's names are part of what a container is** (novox/hq 04-ISSUES/135). A container
|
||||||
|
// resolves every other machine and every public name through the entries the mesh gives it at
|
||||||
|
// creation, and nothing re-reads them afterwards — so a container left alone when the roster
|
||||||
|
// moved is one that cannot reach anything by name, for ever, while every check reports it
|
||||||
|
// running. That is exactly what happened when this mesh's overlay range changed: one container
|
||||||
|
// whose image and files never changed kept an address five days out of date and restarted
|
||||||
|
// 2286 times against a database it could no longer find.
|
||||||
|
//
|
||||||
|
// Sorted, so the digest does not move for a reordering nobody made.
|
||||||
|
hosts := append([]string(nil), r.Hosts...)
|
||||||
|
sort.Strings(hosts)
|
||||||
|
for _, h := range hosts {
|
||||||
|
b.WriteString("host " + h + "\n")
|
||||||
|
}
|
||||||
// The resolver and address are part of what was declared: a container whose dns or ip moved
|
// The resolver and address are part of what was declared: a container whose dns or ip moved
|
||||||
// is a different container, or the fields could never reach one that already ran — which is
|
// is a different container, or the fields could never reach one that already ran — which is
|
||||||
// exactly how their first deployment silently changed nothing.
|
// exactly how their first deployment silently changed nothing.
|
||||||
@@ -2247,3 +2292,25 @@ func meshMadeUnits(known store.State) map[string]bool {
|
|||||||
}
|
}
|
||||||
return made
|
return made
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// moduleOf is the module a declared resource belongs to.
|
||||||
|
//
|
||||||
|
// The mesh composes a module's resource ids as `<module>.<its own id>`, and **a module's name may
|
||||||
|
// contain a dot** — `novox.be` is one on this mesh — while a resource's own id never does. So the
|
||||||
|
// owner is everything before the *last* dot; reading to the first one would make `novox.be.server`
|
||||||
|
// belong to a module called "novox", and a gate would then skip whatever else happened to start that
|
||||||
|
// way.
|
||||||
|
//
|
||||||
|
// False for what the mesh declares in its own right: the foundation's resources carry no dot at all,
|
||||||
|
// and the adoption's are named for the mesh rather than for a module. Both belong to no module, and
|
||||||
|
// their gate is therefore the machine's.
|
||||||
|
func moduleOf(identity string) (string, bool) {
|
||||||
|
if strings.HasPrefix(identity, declaration.AdoptionPrefix) {
|
||||||
|
return "", false
|
||||||
|
}
|
||||||
|
at := strings.LastIndex(identity, ".")
|
||||||
|
if at <= 0 {
|
||||||
|
return "", false
|
||||||
|
}
|
||||||
|
return identity[:at], true
|
||||||
|
}
|
||||||
|
|||||||
@@ -0,0 +1,54 @@
|
|||||||
|
package apply
|
||||||
|
|
||||||
|
import (
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/novox/mesh-host/internal/declaration"
|
||||||
|
)
|
||||||
|
|
||||||
|
// **A container's mesh names are part of what it is** (novox/hq 04-ISSUES/135).
|
||||||
|
//
|
||||||
|
// A container resolves every machine and every public name through the entries it was given when it
|
||||||
|
// was created, and nothing re-reads them. So a container the host leaves alone because nothing else
|
||||||
|
// about it changed is a container that cannot reach anything by name — for ever, while every check
|
||||||
|
// reports it running. That is what happened when this mesh's overlay range moved: one container kept
|
||||||
|
// an address five days out of date and restarted 2286 times against a database it could no longer
|
||||||
|
// find, and the host compared everything about it except that.
|
||||||
|
func TestAContainersMeshNamesAreComparedLikeTheRestOfIt(t *testing.T) {
|
||||||
|
was := &declaration.Container{
|
||||||
|
Name: "umami", Image: "ghcr.io/example/umami@sha256:" + zeros(64),
|
||||||
|
Hosts: []string{"novox.internal:10.42.0.1", "umami.novox.be:10.42.0.1"},
|
||||||
|
}
|
||||||
|
moved := &declaration.Container{
|
||||||
|
Name: was.Name, Image: was.Image,
|
||||||
|
Hosts: []string{"novox.internal:10.10.0.1", "umami.novox.be:10.10.0.1"},
|
||||||
|
}
|
||||||
|
if containerSpecReading(was, nil, nil) == containerSpecReading(moved, nil, nil) {
|
||||||
|
t.Fatal("a container whose mesh names moved compares equal, so it is never recreated")
|
||||||
|
}
|
||||||
|
|
||||||
|
// And the order they arrive in is not a change: the digest must not move for a reordering
|
||||||
|
// nobody made.
|
||||||
|
reordered := &declaration.Container{
|
||||||
|
Name: moved.Name, Image: moved.Image,
|
||||||
|
Hosts: []string{moved.Hosts[1], moved.Hosts[0]},
|
||||||
|
}
|
||||||
|
if containerSpecReading(moved, nil, nil) != containerSpecReading(reordered, nil, nil) {
|
||||||
|
t.Fatal("the same names in another order read as a different container")
|
||||||
|
}
|
||||||
|
|
||||||
|
// A container the mesh gives no names is unaffected, so nothing is recreated for a field it
|
||||||
|
// does not set.
|
||||||
|
plain := &declaration.Container{Name: "plex", Image: was.Image}
|
||||||
|
if containerSpecReading(plain, nil, nil) == containerSpecReading(was, nil, nil) {
|
||||||
|
return // different for other reasons, which is fine
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func zeros(n int) string {
|
||||||
|
out := make([]byte, n)
|
||||||
|
for i := range out {
|
||||||
|
out[i] = '0'
|
||||||
|
}
|
||||||
|
return string(out)
|
||||||
|
}
|
||||||
@@ -316,3 +316,85 @@ func TestAContainerNamingARunOnceStepIsRecreatedWhenItRan(t *testing.T) {
|
|||||||
t.Errorf("the recreation did not name the step as its reason: %+v", server)
|
t.Errorf("the recreation did not name the step as its reason: %+v", server)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestAFailedStepGatesItsModuleAndNotTheMachine(t *testing.T) {
|
||||||
|
// **The blast radius of a step is its module** (novox/hq ADR 0136). A step exists to make
|
||||||
|
// something true before the next thing in its own module needs it — a store seeded before the
|
||||||
|
// broker starts, a schema prepared before the version that needs it runs. Stopping the whole
|
||||||
|
// apply is what this host's own loop calls holding a machine hostage, and it was already
|
||||||
|
// rejected for every other shape (04-ISSUES/011): a module whose database is briefly
|
||||||
|
// unreachable must not stop every module declared after it.
|
||||||
|
var startedNames []string
|
||||||
|
run := func(ctx context.Context, name string, args ...string) (string, error) {
|
||||||
|
switch args[0] {
|
||||||
|
case "info":
|
||||||
|
return "27.0\n", nil
|
||||||
|
case "container":
|
||||||
|
return "false\t\n", errors.New("no such container")
|
||||||
|
case "run":
|
||||||
|
startedNames = append(startedNames, nameOf(args))
|
||||||
|
if nameOf(args) == "catalogue-prepare" {
|
||||||
|
return "", errors.New("exit status 1") // the schema could not be reached
|
||||||
|
}
|
||||||
|
return "deadbeef\n", nil
|
||||||
|
case "rm":
|
||||||
|
return "", nil
|
||||||
|
}
|
||||||
|
return "", nil
|
||||||
|
}
|
||||||
|
d := parseTrusted(t, `{"declaration":1,"resources":[
|
||||||
|
{"id":"mesh-catalog.runtime-prepare","type":"container","name":"catalogue-prepare","image":"`+pinned+`","run-once":true},
|
||||||
|
{"id":"mesh-catalog.runtime","type":"container","name":"catalogue","image":"`+pinned+`"},
|
||||||
|
{"id":"gitea.server","type":"container","name":"forge","image":"`+pinned+`"}
|
||||||
|
]}`)
|
||||||
|
|
||||||
|
report, _, err := Apply(context.Background(), archHost(t), d, store.State{}, store.OriginCarried, run, nil, nil)
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("a failed step was not reported as a failure")
|
||||||
|
}
|
||||||
|
started := map[string]bool{}
|
||||||
|
for _, n := range startedNames {
|
||||||
|
started[n] = true
|
||||||
|
}
|
||||||
|
if started["catalogue"] {
|
||||||
|
t.Error("the module's own workload ran although its step did not complete")
|
||||||
|
}
|
||||||
|
if !started["forge"] {
|
||||||
|
t.Error("another module was not attempted, so one module's step held the machine hostage")
|
||||||
|
}
|
||||||
|
// And the machine's own account says which was not attempted, rather than leaving it to be
|
||||||
|
// inferred from silence.
|
||||||
|
var skipped string
|
||||||
|
for _, o := range report.Outcomes {
|
||||||
|
if o.Action == "skipped" {
|
||||||
|
skipped = o.ID
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if skipped != "mesh-catalog.runtime" {
|
||||||
|
t.Errorf("the report does not say what was not attempted: %q", skipped)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAResourcesOwnerIsReadToTheLastDot(t *testing.T) {
|
||||||
|
// **A module's name may contain a dot.** `novox.be` is one on this mesh, so reading a resource's
|
||||||
|
// owner to the first dot would make its resources belong to something called "novox" — and a gate
|
||||||
|
// would skip whatever else happened to start that way. A resource's own id never contains one,
|
||||||
|
// which is what makes the last dot the boundary.
|
||||||
|
for identity, want := range map[string]string{
|
||||||
|
"novox.be.server": "novox.be",
|
||||||
|
"mesh-catalog.runtime-prepare": "mesh-catalog",
|
||||||
|
"gitea.admin-bootstrap": "gitea",
|
||||||
|
} {
|
||||||
|
got, ours := moduleOf(identity)
|
||||||
|
if !ours || got != want {
|
||||||
|
t.Errorf("%q belongs to %q (%v), want %q", identity, got, ours, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// What the mesh declares in its own right belongs to no module: the foundation's resources carry
|
||||||
|
// no dot, and the adoption's are the mesh's.
|
||||||
|
for _, identity := range []string{"container-runtime", "store-ready", "adoption.guard", ".server"} {
|
||||||
|
if _, ours := moduleOf(identity); ours {
|
||||||
|
t.Errorf("%q was read as a module's", identity)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user