The launcher trusted a counter only a by-hand reconcile ever cleared and a known-good nothing in the daemon wrote, so no machine could roll its host back; the controller and the node tools were replaced in place with nothing kept. - The launcher runs a delivered host that is not known-good on trial: one that crashes, stops for nothing, or does not report within ten minutes goes back to known-good, once per version, recorded in rolled-back. The host proves itself when the mesh takes a report under its own build, says every standing verdict on its reports, never stands aside for a rolled-back version, and restarts its service once when its launcher was replaced on disk. - The engine keeps the controller's and the node tools' previous build beside the new one and judges the new one: the lease taken by the controller it started (read-only direct get of mesh-controller_lease/holder), or this machine's runtime answering $SRV.PING.node-tools.<node>, within sixty seconds of time it could ask. Not healthy: the previous restored, once, said. Proved: the previous deleted. A build declared not-reversible is never rolled back. - Retire never removes a version newer than the running one.
30 lines
1.3 KiB
Plaintext
30 lines
1.3 KiB
Plaintext
# A bus with the grants a witness needs (novox/hq to-be 45 §8), for witnessing_nats_test.go:
|
|
#
|
|
# docker run -d --rm --name w -p 14224:4222 -v $PWD/internal/link/testdata:/c:ro nats:2.11-alpine -js -c /c/witness-grants.conf
|
|
# MESH_TEST_NATS_GRANTS=nats://127.0.0.1:14224 go test ./internal/link/ -run TestNatsWitness
|
|
#
|
|
# `node.anchor` is a machine's host with exactly the two subjects the witness asks added to what a
|
|
# host already has (its inbox); `node.bare` is a host without them. `runtime` stands in for the tool
|
|
# runtime, `admin` for the controller writing the lease.
|
|
jetstream: enabled
|
|
accounts {
|
|
MESH {
|
|
jetstream: enabled
|
|
users = [
|
|
{ user: "node.anchor", password: "a", permissions: {
|
|
publish: { allow: ["$JS.API.DIRECT.GET.KV_mesh-controller_lease.$KV.mesh-controller_lease.holder", "$SRV.PING.node-tools.anchor"] }
|
|
subscribe: { allow: ["_INBOX.node.anchor.>"] }
|
|
} }
|
|
{ user: "node.bare", password: "b", permissions: {
|
|
publish: { allow: ["mesh.control.bare.>"] }
|
|
subscribe: { allow: ["_INBOX.node.bare.>"] }
|
|
} }
|
|
{ user: "runtime", password: "r", permissions: {
|
|
subscribe: { allow: ["$SRV.PING.node-tools.>"] }
|
|
allow_responses: { max: 1, ttl: "1m" }
|
|
} }
|
|
{ user: "admin", password: "x" }
|
|
]
|
|
}
|
|
}
|