Documentation
¶
Overview ¶
Package store is Deploy's durable control-plane state.
The package owns the embedded migrations that define the control schema and the append-only activity receipts that make operator work auditable. It does not own a connection pool: the binary opens one through candace/ipc/db/csfpg, hands it to NewControlStore as the database capability and closes it after the store's users stop. The SQL files under migrations/ are the only source of schema; no Go code here or anywhere else in Core declares DDL.
Callers may rely on NewControlStore returning only after the database answers and every embedded migration has been applied exactly once under an advisory lock, on WithTx running its function inside a single transaction, and on IsTransactionCommitError marking the one outcome that must not be reported as a failure without a durable read-back, because PostgreSQL may have committed after all.
The generated query layer these migrations produce lives behind services/deploy/internal/storedb and is deliberately not part of this repository's public API: those relational shapes change whenever a migration does. Embedders reach durable state through Store.
Index ¶
- func AppendReceipt(ctx context.Context, queries *storedb.Queries, entityType string, ...) (int64, error)
- func IsTransactionCommitError(err error) bool
- type StartupRecovery
- type Store
- func (s *Store) AppendReceipt(ctx context.Context, entityType string, entityID string, kind string, ...) (int64, error)
- func (s *Store) Ping(ctx context.Context) error
- func (s *Store) RecoverInterruptedOperatorWork(ctx context.Context, interruptedAt time.Time) (StartupRecovery, error)
- func (s *Store) WithTx(ctx context.Context, fn func(queries *storedb.Queries) error) error
- type TransactionCommitError
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func AppendReceipt ¶
func AppendReceipt( ctx context.Context, queries *storedb.Queries, entityType string, entityID string, kind string, summary string, payloadSHA256 string, at time.Time, ) (int64, error)
AppendReceipt appends through either the root query set or a transaction.
func IsTransactionCommitError ¶
IsTransactionCommitError reports whether a write needs durable read-back before its outcome can safely be called failed.
Types ¶
type StartupRecovery ¶
type StartupRecovery struct {
InterruptedRuns int
InterruptedDeploymentRuns int
ExpiredApprovals int
ReceiptIDs []int64
}
StartupRecovery summarizes durable work terminalized before a new operator controller starts. ReceiptIDs contains one append-only receipt per recovered run or approval.
type Store ¶
Store is the durable control-plane store. Queries is the root query set, outside any transaction; use WithTx for writes that must be atomic.
func NewControlStore ¶
NewControlStore verifies PostgreSQL readiness through the database capability, applies embedded migrations, and returns the durable control-plane store. The store never closes the database it was given.
func (*Store) AppendReceipt ¶
func (s *Store) AppendReceipt( ctx context.Context, entityType string, entityID string, kind string, summary string, payloadSHA256 string, at time.Time, ) (int64, error)
AppendReceipt appends one activity receipt outside a transaction. Use the package-level AppendReceipt to append inside one.
func (*Store) RecoverInterruptedOperatorWork ¶
func (s *Store) RecoverInterruptedOperatorWork(ctx context.Context, interruptedAt time.Time) (StartupRecovery, error)
RecoverInterruptedOperatorWork atomically terminalizes nonterminal work left by an earlier Core process. It must run before a new controller can create work, making every open record at this boundary stale by definition.
type TransactionCommitError ¶
type TransactionCommitError struct {
Cause error
}
TransactionCommitError means PostgreSQL may have committed even though the client did not receive a successful commit acknowledgement.
func (*TransactionCommitError) Error ¶
func (e *TransactionCommitError) Error() string
Error implements error.
func (*TransactionCommitError) Unwrap ¶
func (e *TransactionCommitError) Unwrap() error
Unwrap returns the underlying commit failure.