store

package
v0.2.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: Apache-2.0 Imports: 13 Imported by: 0

Documentation

Overview

Package store is Deploy's durable control-plane state.

The package owns the embedded migrations that define the control schema and the append-only activity receipts that make operator work auditable. It does not own a connection pool: the binary opens one through candace/ipc/db/csfpg, hands it to NewControlStore as the database capability and closes it after the store's users stop. The SQL files under migrations/ are the only source of schema; no Go code here or anywhere else in Core declares DDL.

Callers may rely on NewControlStore returning only after the database answers and every embedded migration has been applied exactly once under an advisory lock, on WithTx running its function inside a single transaction, and on IsTransactionCommitError marking the one outcome that must not be reported as a failure without a durable read-back, because PostgreSQL may have committed after all.

The generated query layer these migrations produce lives behind services/deploy/internal/storedb and is deliberately not part of this repository's public API: those relational shapes change whenever a migration does. Embedders reach durable state through Store.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func AppendReceipt

func AppendReceipt(
	ctx context.Context,
	queries *storedb.Queries,
	entityType string,
	entityID string,
	kind string,
	summary string,
	payloadSHA256 string,
	at time.Time,
) (int64, error)

AppendReceipt appends through either the root query set or a transaction.

func IsTransactionCommitError

func IsTransactionCommitError(err error) bool

IsTransactionCommitError reports whether a write needs durable read-back before its outcome can safely be called failed.

Types

type StartupRecovery

type StartupRecovery struct {
	InterruptedRuns           int
	InterruptedDeploymentRuns int
	ExpiredApprovals          int
	ReceiptIDs                []int64
}

StartupRecovery summarizes durable work terminalized before a new operator controller starts. ReceiptIDs contains one append-only receipt per recovered run or approval.

type Store

type Store struct {
	Queries *storedb.Queries
	// contains filtered or unexported fields
}

Store is the durable control-plane store. Queries is the root query set, outside any transaction; use WithTx for writes that must be atomic.

func NewControlStore

func NewControlStore(ctx context.Context, database csfpg.IDB) (*Store, error)

NewControlStore verifies PostgreSQL readiness through the database capability, applies embedded migrations, and returns the durable control-plane store. The store never closes the database it was given.

func (*Store) AppendReceipt

func (s *Store) AppendReceipt(
	ctx context.Context,
	entityType string,
	entityID string,
	kind string,
	summary string,
	payloadSHA256 string,
	at time.Time,
) (int64, error)

AppendReceipt appends one activity receipt outside a transaction. Use the package-level AppendReceipt to append inside one.

func (*Store) Ping

func (s *Store) Ping(ctx context.Context) error

Ping verifies that the durable control-plane store is reachable.

func (*Store) RecoverInterruptedOperatorWork

func (s *Store) RecoverInterruptedOperatorWork(ctx context.Context, interruptedAt time.Time) (StartupRecovery, error)

RecoverInterruptedOperatorWork atomically terminalizes nonterminal work left by an earlier Core process. It must run before a new controller can create work, making every open record at this boundary stale by definition.

func (*Store) WithTx

func (s *Store) WithTx(ctx context.Context, fn func(queries *storedb.Queries) error) error

WithTx runs one SQLC-only transaction. Keeping the callback typed prevents callers from embedding ad-hoc SQL in handwritten Go.

type TransactionCommitError

type TransactionCommitError struct {
	Cause error
}

TransactionCommitError means PostgreSQL may have committed even though the client did not receive a successful commit acknowledgement.

func (*TransactionCommitError) Error

func (e *TransactionCommitError) Error() string

Error implements error.

func (*TransactionCommitError) Unwrap

func (e *TransactionCommitError) Unwrap() error

Unwrap returns the underlying commit failure.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL