Move sandbox deployment configuration and nodes into deployment and deploymentpg - #328
Merged
Merged
Conversation
…eploymentpg The deployment package owns the sandbox deployment vocabulary, its rules and use cases: provider configuration and the sealed credential, the specification and retained generations, setup, update and switch, node enrollment, authentication, generation configuration, capacity, presence, status and host history. It is the only package that interprets Sandbox Provider declarations, through the providers.Registry it is given, whose lookups now return typed errors. deploymentpg persists it in Load, Decide and Apply transactions, provider calls run outside them, and the final transaction rechecks the expected generation. Deployment changes run through ExecutionOperations on the execution lease, which the Worker receives as execution.Owner.Deployment. api depends on Deployment, DeploymentChanges and DeploymentReset interfaces typed with the deployment vocabulary; store keeps implementing NodeAllocations and DeploymentReset, together with allocations, placement and reset. Reset completion returns the committed generation and publishes the empty runtime configuration from it before the response reads the current deployment.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #1 (dissolve
store). This is PR 2 of the layering plan: sandbox deployment configuration and nodes move into thedeploymentdomain and its PostgreSQL adapterdeploymentpg.What changes
deploymentowns the sandbox deployment vocabulary, rules and use cases:It is the only package that interprets Sandbox Provider declarations, through the
providers.Registryit is given. Registry lookups now return typed errors.Setupcarries the provider's mode and declared operations, socmd/serverno longer reads declarations.deploymentpgpersists deployment in Load → Decide → Apply transactions.deploymentpg.NewExecution(lease, cipher), which reaches the Worker asexecution.Owner.Deployment.Dispatcher.Deployment.Encryption: the adapter seals and opens the credential with the unchanged binding, so existing ciphertexts still open.
credential_storage_unavailable.api depends on the
Deployment,DeploymentChangesandDeploymentResetinterfaces.writeDeploymentErrormaps the domain errors. The strict fakes are split by area.Still in store for PR 3: allocations, placement and reset. Reset completion returns the committed generation and publishes the empty runtime configuration from it.
Deleted: the store deployment and node files, the deployment copies of
AdminValidationError, and theExecutionOperationsread forwarders.IMPLEMENTATION.md: records the layering conventions and addsdeploymentas an owner.Behavior
sandbox_deployment_conflict, as before.Checks
go build ./...andgo vet ./services/core/...(whole module)deploymentin full: 21 passeddeploymentpgin full: 47 passed, 0 skippedcmd/servertests from themanaged*_test.gofiles: 21 passed-run: 117 passedmake openapi(regenerated) andmake check-namesBlind review found no blocker or major issues. Its four minor findings are fixed: node paths decrypted the credential,
cmd/serverread provider declarations itself, two Service pass-through methods remained, and one decode failure had become 500.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.