ecluse
Safe HaskellNone
LanguageGHC2021

Ecluse.Composition

Description

The wiring half of the boot's effectful tier: turn the ValidatedPlan that Ecluse.Composition.Plan resolves and Ecluse.Composition.Validate clears into the served MountBindings and the worker's publish targets. Every refusal resolveBootWiring reports needs a live environment: a writing role mints each mount's mirror-write credential, and every role runs prepare, which allocates per-rule engine state once at boot. That is why this is IO and why ecluse check-config reaches none of it. WiringPorts carries every capability in, so a unit test runs the assembly without opening a listener.

Synopsis

The environment-dependent wiring

type ResolveAdapter = Ecosystem -> PackumentDeps -> Maybe PublishDeps -> Maybe MountBinding Source #

Resolve an ecosystem's deps to its complete mount, Nothing for an ecosystem this build ships no adapter for. Ecluse.Service holds the one implementation.

data WiringPorts Source #

The capabilities the wiring is built through, injected so a unit test runs the boot-time assembly without opening a listener.

Constructors

WiringPorts 

Fields

data BootWiring Source #

What only a live environment settled: the mounts the front door serves, and the publish targets the worker writes approved artifacts through.

Constructors

BootWiring 

Fields

  • bwBindings :: [MountBinding]

    The resolved mounts. A worker-only role builds them for their rules, and serves none.

  • bwPublishTargets :: [PublishTarget]

    One target per mirrored mount, each holding the provider that mints its write token. A role that writes nothing plans none.

resolveBootWiring :: WiringPorts -> MirrorMintPlan -> Limits -> Maybe PublishBudget -> ValidatedPlan -> IO (Either [BootError] BootWiring) Source #

Build the boot wiring from the cleared plan, or the refusals only a live environment can settle. The credential providers stay internal: a mount reaches one through the wiring it produced.

Boot-time wiring

planMounts :: ResolveAdapter -> IO UTCTime -> (Ecosystem -> RuleDeps) -> MirrorMintPlan -> CredentialProviders -> Limits -> Maybe PublishBudget -> ValidatedPlan -> IO (Either [BootError] [MountBinding]) Source #

Turn the boot's cleared plan into the served MountBindings, or every remaining boot error at once. The caller injects every capability, so this opens no socket, and the Limits arrive resolved.

The first-party privilege

firstPartyName :: FirstParty -> PackageName -> Bool Source #

Whether a name belongs to a namespace this deployment owns. Each arm derives the one predicate every consumer of the privilege reads, so none can disagree about which names are privileged.

Publish-side wiring

data PublishBudget Source #

The publish-side byte discipline: the process-wide aggregate admission and the per-request cap. It exists exactly when a publication target is configured.

Constructors

PublishBudget 

Fields

data PublishTarget Source #

One ecosystem's resolved publish target: the endpoint the worker writes approved artifacts to, and the provider that mints its bearer token. Resolved once, not per request.

Constructors

PublishTarget 

Fields

  • ptEcosystem :: Ecosystem

    The ecosystem this publish target serves.

  • ptMirrorUrl :: RegistryUrl

    The mirror-target endpoint the worker publishes approved artifacts to.

  • ptCredentials :: CredentialProvider

    The provider minting the mirror-target write token.

planPublishTargets :: MirrorMintPlan -> CredentialProviders -> ValidatedPlan -> Either [BootError] [PublishTarget] Source #

Resolve each cleared mount to its publish target, or the aggregated boot errors. A role that mints no write credential plans no target, because nothing in its process writes.