Provisioner asks the backend, not memory, whether a consumer is still there (hq issue 120) #7

Merged
jschoubben merged 3 commits from fix/120-a-provisioner-checks-what-is-there into main 2026-09-25 23:30:24 +00:00
3 Commits
Author SHA1 Message Date
jochen 3192491df6 Brake counts only successful re-applies; only a timeout ends a pass
A lost consumer whose re-apply fails is retried at the next check with
its count unchanged, instead of waiting out a backoff meant for adapters
whose create and holds disagree. A check that fails for one consumer no
longer stops checking the consumers after it; only a timeout does.
2026-09-26 01:30:13 +02:00
jochen 3d0165559a Bound holds: a timeout, a brake, and no password in the log
A check that hangs no longer stalls every consumer: it times out after
30s and counts as could-not-ask, and the rest of that pass is not asked.
A consumer still not held after being applied again is checked at
doubling intervals up to an hour, and said loudly, so an adapter whose
create and holds disagree costs one re-apply an hour, not one a minute.
The consumer's password is scrubbed from every error the harness logs.
2026-09-26 01:24:30 +02:00
jochen 7976510028 Provisioner asks the backend, not memory, whether a consumer is still there
An optional holds() on the adapter is asked for every applied consumer
every minute; false applies it again. A backend that forgets what it was
given while the provisioner runs (hq issue 120) is healed within a
minute instead of failing its consumers in silence. Unable to ask is not
treated as loss. Adapters without holds() behave as before.
2026-09-26 00:53:12 +02:00