bootgate

package
v1.3.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 10, 2026 License: Apache-2.0 Imports: 3 Imported by: 0

Documentation

Overview

Package bootgate is the fail-closed boot gate for services that must have a working IAM-register delivery path before they accept mutating Creates.

Without it, a service whose register-drainer / IAM-peer is down silently logs a Warn and keeps accepting Creates — every resource created in that window gets no owner-tuple (the exact "ресурс создан, tuple обвалился" failure mode). The gate turns that silent loss into an explicit refusal (fail-closed is safer than a grant-leak).

Canonical mode: when --require-iam (KACHO_<SVC>_REQUIRE_IAM=true) is set and the IAM-connected drainer is not up, BOTH effects hold —

  • GuardMutation() returns a refusal (UNAVAILABLE) so Create<Resource> fails,
  • Ready() reports false so the k8s readiness probe goes NotReady (no mutating traffic is routed to an instance without a working delivery path).

Read RPCs are unaffected — the gate is consulted only on the mutating path.

With --require-iam=false (dev back-compat, local fixtures only) the gate is a no-op: always Ready, Create always allowed.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Config

type Config struct {
	// RequireIAM mirrors the --require-iam flag (KACHO_<SVC>_REQUIRE_IAM). When
	// false the gate is disabled (dev back-compat): Ready()==true, GuardMutation
	// always nil. In production it MUST be true (fail-closed).
	RequireIAM bool
	// Service is the short service name (apps|vpc|compute|nlb|iam) used only for
	// the refusal message; optional.
	Service string
}

Config parameterises a Gate.

type Gate

type Gate struct {
	// contains filtered or unexported fields
}

Gate is the fail-closed boot gate. The composition root creates one Gate from the --require-iam flag, the drainer wiring calls SetConnected(true) once the IAM-connected drainer is up (and false if the peer is lost), and the readiness probe + the mutating-Create handler consult Ready()/GuardMutation().

Gate is safe for concurrent use (the connected flag is atomic).

func New

func New(cfg Config) *Gate

New constructs a Gate. It starts NOT connected — a require-iam service is fail-closed (NotReady, Create refused) until the drainer wiring signals SetConnected(true).

func (*Gate) GuardMutation

func (g *Gate) GuardMutation() error

GuardMutation returns a refusal error if mutating Creates must be rejected (require-iam on AND drainer not connected), else nil. Call it first thing in every mutating Create/Update/Delete handler that records an owner-tuple intent.

The refusal is UNAVAILABLE (the IAM-register dependency is unavailable — a retryable, fail-closed condition for cross-domain dependencies).

func (*Gate) Ready

func (g *Gate) Ready() bool

Ready reports readiness for the k8s readiness probe. When require-iam is off the gate is always ready (dev). When on, ready iff the drainer is connected.

func (*Gate) SetConnected

func (g *Gate) SetConnected(connected bool)

SetConnected records whether the IAM-connected register-drainer/peer is up. Call SetConnected(true) once the drainer has established its IAM connection (or first successful delivery), and SetConnected(false) if it is lost.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL