| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Composition.Maintenance
Description
Vet store backends, then build the boot role's maintenance or observation capabilities. The preview observes the declared private cache without constructing a deletion handle. No cleared type's constructor is exported, so a value a deletion handle builds from exists only where a pass here issued it.
Synopsis
- data ClearedBackend
- type ResolveMaintenanceAdapter = Ecosystem -> Maybe RegistryAdapter
- vetStoreBackends :: ResolveMaintenanceAdapter -> MountMap -> Vet (Map Ecosystem ClearedBackend)
- vetPrivateCaches :: ResolveMaintenanceAdapter -> Map Ecosystem MountConfig -> MountMap -> Vet (Map Ecosystem (Maybe StoreBackend, ClearedBackend))
- data StorePorts = StorePorts {
- spTracing :: TracingPort
- spCredential :: Maybe CredentialProvider
- spBudget :: BudgetPorts
- data BudgetPorts = BudgetPorts {
- bpGateFor :: QuotaScope -> RequestGate
- bpOverrides :: Map Text QuotaOverride
- bpNominalPace :: Rational
- storeScope :: RegistryUrl -> QuotaScope
- overrideKey :: Text -> Text
- resolvedBudget :: BudgetPorts -> RegistryUrl -> StoreBudget -> StoreBudget
- type BuildUpstreamProbe = Ecosystem -> PrivateEndpoint -> IO UpstreamSafety
- data StoreBuilds = StoreBuilds {
- sbDeleting :: BuildStoreMaintenance
- sbObserving :: BuildStoreObservation
- sbProbing :: BuildUpstreamProbe
- storeBuilds :: StoreBuilds
- buildStoreMaintenance :: BuildStoreMaintenance
- buildStoreObservation :: BuildStoreObservation
- buildUpstreamProbe :: BuildUpstreamProbe
- planStoreMaintenance :: (StorePorts -> Limits -> ClearedBackend -> IO store) -> TracingPort -> BudgetPorts -> CredentialProviders -> Limits -> Map Ecosystem ClearedBackend -> IO (Either [BootError] (Map Ecosystem store))
- planStoreMaintenanceFor :: CredentialTarget -> (StorePorts -> Limits -> ClearedBackend -> IO store) -> TracingPort -> BudgetPorts -> CredentialProviders -> Limits -> Map Ecosystem ClearedBackend -> IO (Either [BootError] (Map Ecosystem store))
- readUpstreamSafety :: [(Ecosystem, IO UpstreamSafety)] -> IO ([Advisory], Either [BootError] ())
- upstreamFindings :: [(Ecosystem, UpstreamSafety)] -> ([Advisory], Either [BootError] ())
The config-decidable half
data ClearedBackend Source #
A store a deleting role's pass cleared, one arm per backend kind. Only vetStoreBackends and
vetPrivateCaches issue one, so no store their passes did not clear gets a handle that can delete.
type ResolveMaintenanceAdapter = Ecosystem -> Maybe RegistryAdapter Source #
How the pass resolves a mount's ecosystem to the adapter this build ships, injected so a spec drives the protocol rule over an adapter that fills no maintenance slice.
vetStoreBackends :: ResolveMaintenanceAdapter -> MountMap -> Vet (Map Ecosystem ClearedBackend) Source #
The rule every declared mirror target meets: its resolved backend offers a control plane this build can sweep. Both store roles refuse a target that fails it, and a writing role ignores it.
vetPrivateCaches :: ResolveMaintenanceAdapter -> Map Ecosystem MountConfig -> MountMap -> Vet (Map Ecosystem (Maybe StoreBackend, ClearedBackend)) Source #
Vet each private cache under its own backend declaration and maintenance authority.
The environment-dependent half
data StorePorts Source #
Per-target tracing and authentication, resolved before the store handles are built.
Constructors
| StorePorts | |
Fields
| |
data BudgetPorts Source #
What the boot knows about request capacity before any store is built: the gate for each capacity pool, and what the operator declared about those pools.
Constructors
| BudgetPorts | |
Fields
| |
storeScope :: RegistryUrl -> QuotaScope Source #
The pool a store falls in when its backend names none of its own: the store's own authority, so two paths on one host share it.
overrideKey :: Text -> Text Source #
The spelling a declared capacity's key and a store URL are compared under, so a trailing slash or a difference of case cannot miss a match.
resolvedBudget :: BudgetPorts -> RegistryUrl -> StoreBudget -> StoreBudget Source #
The store's capacity as this boot resolves it: the backend's own description, the operator's declaration where there is one, else the pace a backend publishing no quota is derived to run at.
type BuildUpstreamProbe = Ecosystem -> PrivateEndpoint -> IO UpstreamSafety Source #
How a boot builds the probe for one mount's private upstream. Injected, as the store builds are, so a spec drives what a boot does with an answer without an AWS identity.
data StoreBuilds Source #
The builds a boot chooses between: one per Dredger authority, and the serving role's probe. The role picks its own, so a preview's boot never runs the build that holds a delete.
Constructors
| StoreBuilds | |
Fields
| |
storeBuilds :: StoreBuilds Source #
The shipped builds.
buildStoreMaintenance :: BuildStoreMaintenance Source #
The live handle for a cleared store. CodeArtifact discovers its credentials the standard AWS way, and both arms read and dial over one manager of the store's own.
buildStoreObservation :: BuildStoreObservation Source #
The observing calls for a cleared store, built from the backend's own read capability rather than from a handle with its writes taken away.
buildUpstreamProbe :: BuildUpstreamProbe Source #
The shipped build. It asks the backend the mount declared, over the role's own ambient identity, so no caller's credential reaches the call.
planStoreMaintenance :: (StorePorts -> Limits -> ClearedBackend -> IO store) -> TracingPort -> BudgetPorts -> CredentialProviders -> Limits -> Map Ecosystem ClearedBackend -> IO (Either [BootError] (Map Ecosystem store)) Source #
Build the booting role's own capabilities for each cleared store, or every refusal the live environment earns. The builds accumulate, so one launch reports every store that cannot be built.
planStoreMaintenanceFor :: CredentialTarget -> (StorePorts -> Limits -> ClearedBackend -> IO store) -> TracingPort -> BudgetPorts -> CredentialProviders -> Limits -> Map Ecosystem ClearedBackend -> IO (Either [BootError] (Map Ecosystem store)) Source #
Plan a target slot with its own credentials and accumulate all backend construction refusals.