ecluse
Safe HaskellNone
LanguageGHC2021

Ecluse.Composition.MirrorRole

Description

What each half of the demand-driven mirror pipeline needs of the process running it, the mirror-write credential it mints, and the boot refusal a role earns against the resolved mirror runtime.

Mirroring has a producer half (the serve path enqueues a job for every artifact it admits) and a consumer half (the worker drains the queue and publishes). One process runs both, or a split deployment runs each in its own fleet so the front door and the worker scale apart. The split only works over a durable queue, which is what mirrorRoleRefusal decides.

Synopsis

Documentation

spawnsWorker :: MirrorRole -> MirrorRuntimePlan -> Bool Source #

Whether this process runs the mirror worker: the role wants one and a mount declares a mirror target. Under NoMirroring a spawned loop would poll an inert queue with nothing to pace it.

enqueuesJobs :: MirrorRole -> Bool Source #

Whether this role serves requests, and so enqueues a mirror job for each version it admits. The composition root reads it to decide whether to build the enqueue buffer.

data MirrorMintPlan Source #

Whether a role's boot mints each mirrored mount's write credential. Only a role that writes to the mirror store holds that identity.

Constructors

MintMirrorWrite

ecluse proxy and ecluse mirror: mint at boot, so a bad identity refuses there.

SkipMirrorWrite

ecluse proxy --no-worker: the front door writes nothing, so it needs no write identity.

mirrorMintPlan :: MirrorRole -> MirrorMintPlan Source #

The worker is the only writer, so the roles that run one are the roles that mint.

mirrorRoleRefusal :: MirrorRole -> MirrorRuntimePlan -> Either [BootError] () Source #

Refuse a role the resolved mirror runtime cannot serve. A split role over the bounded in-memory queue would strand every job, because that queue lives inside one process.