Documentation
¶
Overview ¶
Package achrix supplies instance-owned composition, authorization and lifecycle for trusted, compiled modules. It owns no product data or authentication scheme.
Index ¶
- Variables
- func Version() string
- type Application
- func (a *Application) Authorize(ctx context.Context, p Principal, capability, resource string) error
- func (a *Application) Components() []Descriptor
- func (a *Application) Ready(ctx context.Context) error
- func (a *Application) Shutdown(parent context.Context) error
- func (a *Application) Start(parent context.Context) error
- type Capability
- type Config
- type Descriptor
- type Module
- type Policy
- type PolicyFunc
- type Principal
Constants ¶
This section is empty.
Variables ¶
Functions ¶
Types ¶
type Application ¶
type Application struct {
// contains filtered or unexported fields
}
Application is immutable after composition except for lifecycle/admission state. Domain methods remain typed consumer-owned methods, not an untyped dispatcher.
func New ¶
func New(config Config, policy Policy, modules ...Module) (*Application, error)
New rejects duplicate, missing, incompatible or cyclic composed contracts before any module starts. Module descriptors are snapshotted to prevent mutable registry state leaking between instances. No process-global registration exists.
func (*Application) Authorize ¶
func (a *Application) Authorize(ctx context.Context, p Principal, capability, resource string) error
Authorize fails closed for empty principals, unknown capabilities, stopped applications or policy errors. Call it inside the owning Application operation before authorization-sensitive reads/writes; transport discovery grants no rights. resource is a product-owned opaque scope/reference, not trusted client claims. Callers must supply a deadline. Shutdown cancels/drains admitted policy work; calls outside ready return ErrNotReady without invoking policy. Policy errors never expose raw provider text: only explicit ErrDenied is a permission denial. Core emits safe DEBUG detail; the product owns bounded denial/failure visibility.
func (*Application) Components ¶
func (a *Application) Components() []Descriptor
Components returns a defensive snapshot for compatible build/recovery identity.
func (*Application) Ready ¶
func (a *Application) Ready(ctx context.Context) error
Ready checks only composed local dependencies, under the caller's deadline. It never waits behind lifecycle callbacks and is canceled/drained by Shutdown. Repeated probe detail is DEBUG; the product owns bounded operational signals.
func (*Application) Shutdown ¶
func (a *Application) Shutdown(parent context.Context) error
Shutdown closes admission immediately, cancels admitted Ready/Authorize work, drains it, then stops Modules in reverse order. Its deadline covers lifecycle waiting, drain and Stop together. If waiting/drain expires, the instance remains stopping and a later Shutdown may finish cleanup; Stop never races callbacks. Completed cleanup is not repeated and its result is retained. Modules must terminate their owned domain work in Stop; Core tracks only its own callbacks.
func (*Application) Start ¶
func (a *Application) Start(parent context.Context) error
Start is a one-shot operation. A failed start cleans the failing module and all earlier modules in reverse order using a fresh bounded cleanup context. Lifecycle failures are diagnosed by component and phase without logging extension errors.
type Capability ¶
Capability identifies an owned public contract. Version is its positive ABI revision, not the implementation's release version. Compatible additive changes retain the revision; incompatible contracts increment it. Composition matches exact revisions and admits only one provider/revision for each capability ID.
type Descriptor ¶
type Descriptor struct {
ID string
// Version identifies the Module implementation's packaged source dependency.
// Official packages in this Go module use Version(); capability ABI is separate.
Version string
Provides []Capability
Requires []Capability
Optional []Capability
}
Descriptor is deterministic, side-effect-free, cheap composition metadata. Describing a Module must not read environment/secrets, acquire resources, call networks/databases or mutate registration. Optional providers may be absent; when present they must match the exact revision and precede their consumers.
type Module ¶
type Module interface {
Descriptor() Descriptor
Start(context.Context) error
Ready(context.Context) error
Stop(context.Context) error
}
Module owns its resources. Start, Ready and Stop must honor context cancellation. Stop must clean resources acquired by a partially failed Start and be safe when Start acquired none. In-process code is trusted; contexts are not a sandbox.
type Policy ¶
Policy is the consumer-owned authorization decision: nil allows, ErrDenied (possibly wrapped) explicitly denies, and other errors fail closed as evaluation unavailable. It must honor cancellation and must not mutate domain state. Implementations must be safe for concurrent calls.
type PolicyFunc ¶
Directories
¶
| Path | Synopsis |
|---|---|
|
SPDX-License-Identifier: MPL-2.0 Package admin composes trusted, compiled Module-owned administration screens.
|
SPDX-License-Identifier: MPL-2.0 Package admin composes trusted, compiled Module-owned administration screens. |
|
SPDX-License-Identifier: MPL-2.0 Package audit owns retained accountability records.
|
SPDX-License-Identifier: MPL-2.0 Package audit owns retained accountability records. |
|
SPDX-License-Identifier: MPL-2.0
|
SPDX-License-Identifier: MPL-2.0 |
|
admin
SPDX-License-Identifier: MPL-2.0 Package admin owns Identity's account-management presentation.
|
SPDX-License-Identifier: MPL-2.0 Package admin owns Identity's account-management presentation. |
|
SPDX-License-Identifier: MPL-2.0
|
SPDX-License-Identifier: MPL-2.0 |
|
admin
SPDX-License-Identifier: MPL-2.0 Package admin owns Media's private file-library presentation.
|
SPDX-License-Identifier: MPL-2.0 Package admin owns Media's private file-library presentation. |
|
Package multisite resolves an authorized exact authority to a stable site ID.
|
Package multisite resolves an authorized exact authority to a stable site ID. |