Documentation
¶
Overview ¶
Package shape is the single source of the OPM artifact shape gate shared by the package loaders (opm/helper/loader/file and opm/helper/loader/registry).
The gate is the loader boundary's fast-fail structural check: it confirms an artifact carries the right concrete kind and the identity fields the schema never defaults, but deliberately stops short of full schema validation, which is the Kernel/Binding layer's contract. "Concrete" is judged before default finalization: an identity field authored as a defaulted disjunction is refused, with the default named in the error. Single-sourcing it here guarantees a directory-loaded artifact and a registry-loaded artifact are validated identically and fail with the same sentinel values.
It lives under opm/helper/loader/internal/ so it stays out of the library's public SemVer surface (kernel neutrality) while remaining importable by both loader subpackages. The sentinels are re-exported from loader/file with unchanged identity so existing errors.Is callers are unaffected.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ( // ErrInvalidPackage marks a structurally invalid package: the built root // is not a struct, or load.Instances did not resolve exactly one instance. ErrInvalidPackage = errors.New("invalid OPM package") // ErrWrongKind marks a package whose concrete kind does not match the // artifact the loader was asked for. ErrWrongKind = errors.New("wrong OPM artifact kind") // ErrMissingRequiredField marks a package missing a required identity // field, or carrying it in non-concrete form. ErrMissingRequiredField = errors.New("missing required field") )
Sentinel errors returned by the shape gate. Each Load*Package wraps the relevant sentinel via %w so frontends (CLI, controller, Crossplane function) can branch on the failure class with errors.Is rather than string matching.
var ( ModuleSpec = ArtifactSpec{ ExpectedKind: "Module", RequiredConcreteFields: []string{"metadata.name", "metadata.modulePath", "metadata.version"}, } InstanceSpec = ArtifactSpec{ ExpectedKind: "ModuleInstance", RequiredConcreteFields: []string{"metadata.name", "metadata.namespace"}, ModuleRefs: []ModuleRef{{Path: "#module"}}, } // #Platform.#registry carries path-keyed #Subscription values (enhancement // 0001), not embedded #Module registrations — so there is no per-entry // #module to gate here. Subscription resolution is the materialize layer's // contract; the loader only checks the platform's own identity. PlatformSpec = ArtifactSpec{ ExpectedKind: "Platform", RequiredConcreteFields: []string{"metadata.name", "type"}, } )
ModuleSpec, InstanceSpec, and PlatformSpec are the shape-gate definitions for the three package loaders. The required field lists carry only the identity fields the schema never defaults — fields the schema fills in (or leaves as open `_`) are out of scope here and validated by the Kernel/Binding layer.
Functions ¶
func Gate ¶
func Gate(val cue.Value, spec ArtifactSpec) error
Gate runs the structural validation described by spec against a freshly built artifact value. It is the loader boundary's fast-fail check: it confirms the artifact is the right kind and carries concrete identity, but deliberately stops short of full schema validation, which is the Kernel/Binding layer's contract.
Types ¶
type ArtifactSpec ¶
type ArtifactSpec struct {
ExpectedKind string
RequiredConcreteFields []string
ModuleRefs []ModuleRef
}
ArtifactSpec describes the shape gate for one artifact type. ExpectedKind is the concrete kind literal the package must carry; RequiredConcreteFields are dotted paths to scalar identity fields that must be present and concrete; ModuleRefs point at embedded #Module values whose kind must in turn be "Module".