Documentation
¶
Overview ¶
Package achrix supplies instance-owned composition, authorization and lifecycle for trusted, compiled modules. It owns no product data or authentication scheme.
Index ¶
- Variables
- func Version() string
- type Application
- func (a *Application) Authorize(ctx context.Context, p Principal, capability, resource string) error
- func (a *Application) Components() []Descriptor
- func (a *Application) Ready(ctx context.Context) error
- func (a *Application) Shutdown(parent context.Context) error
- func (a *Application) Start(parent context.Context) error
- type Capability
- type Config
- type Descriptor
- type Module
- type Policy
- type PolicyFunc
- type Principal
Constants ¶
This section is empty.
Variables ¶
Functions ¶
Types ¶
type Application ¶
type Application struct {
// contains filtered or unexported fields
}
Application is immutable after composition except for its serialized lifecycle. Domain methods remain typed consumer-owned methods, not an untyped dispatcher.
func New ¶
func New(config Config, policy Policy, modules ...Module) (*Application, error)
New rejects duplicate, missing, incompatible or cyclic required contracts before any module starts. Module descriptors are snapshotted to prevent mutable registry state leaking between instances. No process-global registration exists.
func (*Application) Authorize ¶
func (a *Application) Authorize(ctx context.Context, p Principal, capability, resource string) error
Authorize fails closed for empty principals, unknown capabilities, stopped applications or policy errors. Call it inside the owning Application operation before validation-dependent reads/writes; transport discovery grants no rights. During lifecycle exclusion it returns ErrNotReady without waiting or invoking policy.
func (*Application) Components ¶
func (a *Application) Components() []Descriptor
Components returns a defensive snapshot for compatible build/recovery identity.
func (*Application) Ready ¶
func (a *Application) Ready(ctx context.Context) error
Ready checks only composed local dependencies, under the caller's deadline. During lifecycle exclusion it returns ErrNotReady without waiting or invoking modules.
func (*Application) Shutdown ¶
func (a *Application) Shutdown(parent context.Context) error
Shutdown prevents new authorization and stops started modules in reverse order. Repeated shutdown is safe. Modules must wait for/terminate their owned work in Stop.
func (*Application) Start ¶
func (a *Application) Start(parent context.Context) error
Start is a one-shot operation. A failed start cleans the failing module and all earlier modules in reverse order using a fresh bounded cleanup context. Lifecycle failures are diagnosed by component and phase without logging extension errors.
type Capability ¶
Capability identifies an owned public contract. Version is its positive ABI revision, not the implementation's release version.
type Descriptor ¶
type Descriptor struct {
ID string
Version string
Provides []Capability
Requires []Capability
}
type Module ¶
type Module interface {
Descriptor() Descriptor
Start(context.Context) error
Ready(context.Context) error
Stop(context.Context) error
}
Module owns its resources. Start, Ready and Stop must honor context cancellation. Stop must clean resources acquired by a partially failed Start and be safe when Start acquired none. In-process code is trusted; contexts are not a sandbox.
type Policy ¶
Policy is the consumer-owned authorization decision. Any non-nil result denies. It must honor context cancellation and must not mutate domain state.