ecluse
Safe HaskellNone
LanguageGHC2021

Ecluse.Composition.BootError

Description

Aggregated startup refusals, the advisories a boot logs beside them, and their operator-facing rendering.

Synopsis

Documentation

data BootError Source #

A reason the composition root refuses to start. The root aggregates them, so a single run reports every problem an operator must fix.

Constructors

PolicyBootError PolicyError

A rule policy did not resolve (surfaced by loadConfig).

MissingAdapter Ecosystem

A configured mount's ecosystem has no adapter, so Écluse cannot serve it.

UnresolvedCredential Ecosystem

A mount has no initialised mirror-write provider. Every active mount derives its credential from its mirror target, so this is a safety net, not a reachable state.

QueueProviderUnavailable Text

The queue URL names a backend this binary cannot run.

QueueRegionMissing

An SQS endpoint override (AWS_ENDPOINT_URL_SQS) is set but AWS_REGION is not. An emulator or VPC endpoint carries no region in its host, so the ambient one must scope it.

QueueUrlUnrecognised Text

ECLUSE_QUEUE__URL is set but its shape names no backend this binary knows. Guessing one would send mirror jobs somewhere the operator did not point at. Carries the value.

QueueEndpointMalformed Secret

The configured SQS endpoint override (AWS_ENDPOINT_URL_SQS) is not a parseable endpoint URL. It can carry a credential, so the value stays redacted behind the secret.

AwsEndpointMalformed Secret

The S3 advisory client's endpoint override (AWS_ENDPOINT_URL) is not a parseable endpoint URL. Refused rather than dropped, so a typo never silently dials real AWS.

CodeArtifactMintFailed (NonEmpty Text) Text

The eager mint threw, carrying every configured consumer key and the rendered exception.

MirrorTargetWithoutPublish Ecosystem

A mount declares a mirror target, but this build writes nothing for its ecosystem. The mirror could never publish, so the mount is refused rather than booted half-wired.

PublicationTargetWithoutPublish Ecosystem

A publication target has no adapter that can write its ecosystem's protocol.

FirstPartyMissing Ecosystem

A publication target is set and the mount declares no first-party namespaces, so the anti-shadowing guard has nothing to enforce and any name could be shadowed.

FirstPartyWithoutPrivateUpstream Ecosystem

First-party names have no private authority, so every lookup would return 404.

PublishStaticCredentialNeedsEdge Ecosystem StoreTag

A static publish credential is set without a verifiable inbound edge (ECLUSE_SERVER__AUTH_TOKEN). An unauthenticated request could otherwise publish as Écluse.

PublicationTargetOnPublicUpstream Ecosystem Ecosystem Text

A mount's publication target, at the carried registry, shares a host with the named mount's public upstream. The publisher's relayed credential would reach a public registry.

PublicationTargetOnMountEndpoint Ecosystem Ecosystem Text Text

A mount's publication target is also the named mount's endpoint under the named key, at the carried registry. A publish would be relayed into a role declared for something else.

MirrorTargetOnPublicUpstream Ecosystem Ecosystem Text

A mount's mirror target, at the carried registry, shares a host with the named mount's public upstream. Écluse's own mirror-write credential would reach a public registry.

MirrorTargetOnMountEndpoint Ecosystem Ecosystem Text Text

A mount's mirror target is also the named mount's endpoint under the named key, at the carried registry. A sweep of that store would delete data the other role owns.

PrivateUpstreamOnPublicUpstream Ecosystem Text

One repository receives caller credentials and bypasses the public rules through the private leg.

PrivateUpstreamUnsafe Ecosystem UnsafeReason

The mount's private upstream can serve public content, so every version it holds would be trusted as private. Carries what the backend reported.

PrivateUpstreamProbeFailed Ecosystem Text

Asking the mount's private upstream what it aggregates threw rather than answering, so nothing was settled about it. Carries the rendered exception.

StoreTagConflict Ecosystem Text Ecosystem Text Text

Two endpoints, each carried as its mount and its tagged key path, name the carried registry under different tags, so the two declarations disagree about what serves that store.

MemoryPlanOverrideUnsafe [Text]

An explicit memory override breaks the combined memory-plan invariant even after every tenant shed to its minimum. A computed plan degrades and boots, an operator claim does not.

SplitRoleNeedsDurableQueue Text

A split-deployment role (carried as its invocation) was selected over the bounded in-memory queue, whose jobs never leave the process that enqueued them.

MirrorRoleWithoutMirroring

The dedicated mirror worker was launched with no mount declaring a mirror target, so it has no queue to drain and nothing to publish.

MirrorQueueUnavailable Text

Building the configured mirror-queue backend threw. Carries the rendered exception, which tells a transient fault from a permanent one to fix.

AdvisorySyncUnavailable Text

Preparing the configured advisory sync threw. Carries the rendered exception, which tells a transient fault from a permanent one to fix.

StoreMaintenanceUnavailable Ecosystem StoreMaintenanceReason

A vetted mirror store has no store maintenance backend the Dredger can sweep it with, carrying why.

DredgerQuotaScopeConflict Text Text Text

Two dredger.quotaOverrides entries declare the same capacity pool differently, carried as the pool and the two keys that define it.

DredgerChunkPauseBeneathFloor NominalDiffTime NominalDiffTime

The configured pause between sweep chunks is beneath its floor, carried beside it. Only the deleting role reads the dredger group, so only that role refuses.

AdvisoryDenyWithoutStore Ecosystem (NonEmpty Text)

A mount's rules deny on the advisory database and no advisory store is configured, so those rules could never decide. Carries the mount and the rule names, in policy order.

PilotWithoutEcosystem

An advisory store is configured and no mount is, so ecluse pilot has no ecosystem to compile an artifact for and would publish nothing.

ProgressWindowNotPositive Int

The progress window is zero or negative. Carries the configured seconds.

ProgressWindowNotBelowServeCap Int Int

The progress window is not below the serve-path cap, so the floor could never fire first on a served request. Carries the window and the cap, in seconds.

MinProgressBytesNotPositive Int

The progress floor's byte count is zero or negative. Carries the configured count.

Instances

Instances details
Show BootError Source # 
Instance details

Defined in Ecluse.Composition.BootError

Eq BootError Source # 
Instance details

Defined in Ecluse.Composition.BootError

data StoreMaintenanceReason Source #

Why a mount's mirror target reached no store maintenance handle.

Constructors

NoControlPlane StoreTag

The mount's store tag names no control plane this build implements.

DeletionNotPermitted StoreTag

The mount's store carries no operator consent to delete from it.

NoProtocolMaintenance

The store's only control plane is the ecosystem protocol, which spells no package listing or version delete.

PrivateCacheUnavailable Text

The declared private cache lacks a supported maintenance or authentication operation.

ClientBuildFailed Text

Building the cleared backend's client against the live environment threw.

data Advisory Source #

A finding a role boots on and warns about. The deleting role refuses the collapses below, so no advisory naming one reaches it.

Constructors

MirrorTargetOnPrivateUpstream Ecosystem Ecosystem RegistryUrl

A mount's mirror target is also the named mount's private upstream, at the carried registry. Both mounts are carried, because the two can differ.

MirrorTargetOnOwnPublicationTarget Ecosystem RegistryUrl

A mount's mirror target is also its own publication target, at the carried registry.

DredgerQuotaOverrideUnmatched Text

A dredger.quotaOverrides entry names a store no mount declares, carried as the key it was written under.

PrivateUpstreamUndecided Ecosystem UndecidabilityReason

Whether the mount's private upstream serves public content stayed open, so that topology stays the operator's to verify. Carries why it stayed open.

Instances

Instances details
Show Advisory Source # 
Instance details

Defined in Ecluse.Composition.BootError

Eq Advisory Source # 
Instance details

Defined in Ecluse.Composition.BootError

refuseOnThrow :: (Text -> BootError) -> IO a -> IO (Either [BootError] a) Source #

Fold a thrown fault into the boot error the caller names, so a phase that dials a live environment refuses through the aggregate rather than escaping the boot as an exception.

renderBootError :: BootError -> Text Source #

Render a BootError as a human-facing line for the aggregated failure block.

renderBootErrors :: [BootError] -> Text Source #

Render an aggregated refusal as the one block a failed launch reports, so every problem an operator must fix appears in a single run.

renderAdvisory :: Advisory -> Text Source #

Render an advisory as the warning line a boot logs and ecluse check-config prints. Both entry points render here, so neither can word a warning its own way.