ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Worker.Job

Description

Deciding one mirror job: probe the mirror target, re-run current policy, fetch, verify, and publish. Every step reports its verdict as a JobOutcome value, which Ecluse.Core.Worker.Realise realises at the queue handle.

The receipt is held for the whole job by the lease controller (Ecluse.Core.Worker.Lease), so nothing here touches the queue. Nothing here acks either: a transient failure simply reports Retried, and the un-acked message redelivers.

Synopsis

Documentation

data JobOutcome Source #

The terminal outcome of processing one mirror job. It decides whether the worker acks the message or leaves it to redeliver.

Constructors

Succeeded

The publish succeeded or the mirror already held the version. The worker acknowledges either result, including idempotent redelivery.

Dropped Text

A non-retryable rejection (a tampered artifact, an unformable request URL). Redelivery cannot help, so the job is acked to retire it after alarming.

SourceUnavailable Text

The source's own version object was unavailable, so no mirror write can reflect the package. Retired like Dropped, but reported apart from a policy deny.

DeadLettered Text

A terminal fault handed to deadLetter rather than acked, because a plain delete would silently discard it on a durable queue.

Retried RetryLeg Text

A transient fault: a fetch failure, or a registry rejection worth retrying. The message is left un-acked so it redelivers, carrying the leg it gave up on.

Instances

Instances details
Show JobOutcome Source # 
Instance details

Defined in Ecluse.Core.Worker.Job

Eq JobOutcome Source # 
Instance details

Defined in Ecluse.Core.Worker.Job

data RetryLeg Source #

Which leg a transient failure gave up on. The realisation half reads it to decide whether to reset the message's visibility, so the two legs cannot be conflated at the queue handle.

Constructors

BeforePublish

The job gave up before it published: the inventory probe, the re-evaluation, or the artifact fetch. The message keeps its lease and redelivers when that window lapses.

AfterPublish

The publish itself failed transiently, after the bytes were fetched and verified. The message is released so its redelivery does not wait out the lease.

Instances

Instances details
Show RetryLeg Source # 
Instance details

Defined in Ecluse.Core.Worker.Job

Eq RetryLeg Source # 
Instance details

Defined in Ecluse.Core.Worker.Job

mirrorLatest :: Maybe Version -> [Version] -> Version -> Version Source #

The latest one mirror write declares, over the upstream tag and the post-write inventory. The published version always survives, so the chosen target is always present at the store.

outcomeOfAdmission :: MirrorJob -> ArtifactAdmission -> Either JobOutcome MirrorArtifact Source #

Render the shared ArtifactAdmission as the descriptor to publish, or the outcome the queue realises. admissionTransience alone splits retry from drop, so no path can diverge from the gate.

outcomeOfFetchFault :: RetryLeg -> (FetchFault -> Text) -> FetchFault -> JobOutcome Source #

The worker's terminal-versus-transient split over the shared exchange-fault channel. The artifact fetch and the mirror write read this one table, and each names its own retry leg.

processJob :: MirrorJob -> WorkerM JobOutcome Source #

Decide one job, re-checking current policy before publishing, because the queue wait is unbounded and mirrored bytes bypass every later rule.