| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Runtime.Cve.Sync
Description
Advisory artifact sync and the write side of Ecluse.Core.Cve.Slot. Each mount retries at boot, then polls for new artifacts. An empty slot denies by default.
Synopsis
- newtype DbEtag = DbEtag Text
- data S3CveSource
- newS3CveSource :: Maybe AwsEndpoint -> IO S3CveSource
- s3CveFetchFor :: S3CveSource -> Text -> Text -> Int -> CveFetch
- data SyncEnv = SyncEnv {
- syncFetch :: CveFetch
- syncEcosystem :: Ecosystem
- syncEpssRequirement :: EpssRequirement
- syncDbPath :: FilePath
- syncSlot :: CveSlot
- syncStoreRef :: Text
- data SyncSchedule = SyncSchedule {
- schedBootBackoff :: [Int]
- schedPollDelay :: Int
- schedAbsentReport :: Int
- data SyncHooks = SyncHooks {
- hookFirstSync :: IO ()
- hookPushAge :: IO ()
- runCveSync :: (MonadUnliftIO m, KatipContext m) => AdvisorySyncMetricsPort -> AdvisorySyncTracingPort -> SyncEnv -> SyncSchedule -> SyncHooks -> m ()
- bootBackoffDelays :: [Int]
- absentReportInterval :: Int
The injected transport
data S3CveSource Source #
An S3-backed advisory-fetch source. newS3CveSource captures one amazonka Env, so
every mount's CveFetch shares one credential discovery. The composition shell never sees it.
newS3CveSource :: Maybe AwsEndpoint -> IO S3CveSource Source #
Build an S3CveSource over one S3 amazonka env, honouring the resolved endpoint override.
s3CveFetchFor :: S3CveSource -> Text -> Text -> Int -> CveFetch Source #
A CveFetch against one bucket, object key, and byte cap, over the captured env.
One sync cycle
Everything one ecosystem's sync task operates on.
Constructors
| SyncEnv | |
Fields
| |
The scheduled task
data SyncSchedule Source #
The task's timing: the boot burst's backoff delays and the steady poll interval, both in
microseconds. The composition root ships bootBackoffDelays and the configured poll interval.
Constructors
| SyncSchedule | |
Fields
| |
What the shell hangs off one sync task. Both run inside the task, so neither may block it, and both must tolerate being called again.
Constructors
| SyncHooks | |
Fields
| |
runCveSync :: (MonadUnliftIO m, KatipContext m) => AdvisorySyncMetricsPort -> AdvisorySyncTracingPort -> SyncEnv -> SyncSchedule -> SyncHooks -> m () Source #
Retry at boot, then poll forever. A refused artifact ends the boot burst.
bootBackoffDelays :: [Int] Source #
The shipped boot-burst backoff: an immediate first attempt, then a retry after each delay, then the burst concedes to the steady poll. The poll interval, not this, is the operator's knob.
absentReportInterval :: Int Source #
The shipped gap, in microseconds, between repeats of the unloaded-database and fetch-failure reports. The rules' outage reminder paces on the same gap.