Documentation
¶
Overview ¶
Command warden is the candacenet fleet watchdog daemon. Every node runs the same binary: nodes elect a leader (Raft-style, majority quorum), the leader monitors peer liveness and emails the operator when a peer dies. A single bound port per node serves the node-to-node gRPC WardenService and the HTTP surface (SSR dashboard, /api/status, /metrics) multiplexed with cmux.
Concurrency model (CSP) ¶
The wiring below is deliberately channel-first. Each long-running component — the election manager, the watchdog, and the single-port server — owns exactly one goroutine and reports its terminal error on a shared buffered channel. main selects for the first shutdown trigger (an OS signal cancels the context; a component error cancels it too), performs a bounded graceful server drain (which ends in-flight streams cleanly and finishes in-flight unary RPCs), then drains one terminal error from every launched goroutine before returning. There are no mutexes and no shared mutable error slice in the wiring: cancellation flows through context, results flow through channels, and every goroutine is awaited — no abandoned goroutines.