platform

package
v1.0.0-alpha.22 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: Apache-2.0 Imports: 14 Imported by: 0

Documentation

Overview

Package platform holds the process-local platform store: a single-slot, concurrency-safe holder of the platform module generated and built from the cluster-singleton Platform CR and the set of active transformer claims. It is written by the PlatformReconciler and read by the render path. It also owns Layout, the on-disk lifecycle of the generated module directories the store records (per-identity directories, staging swaps, retention, boot reset); the module content itself comes from the library's opm/helper/platformmodule generator.

The store records one Generated platform module per PackageIdentity: the module directory on the operator's own disk, the platform value the kernel built from it and the resolved catalog-skew policy (0019:D6, D7). A render leases the record for its duration (Store.Lease) so the PlatformReconciler never prunes a module directory a render build is still reading from.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type ClaimCoordinate

type ClaimCoordinate struct {
	Catalog string
	Version string
}

ClaimCoordinate is one active claim's catalog coordinate: the provider catalog's major-suffixed CUE module path and the released version the claim pins. It is the unit a PackageIdentity is built from, and the same pair the generated module's #registry entry carries.

func (ClaimCoordinate) String

func (c ClaimCoordinate) String() string

String returns the coordinate's canonical "<catalog>@<version>" form.

type Generated

type Generated struct {
	// Identity is what the package is a function of: the Platform CR
	// generation plus the active claims' catalog coordinates (0015:D13). It
	// is the store's key and the name of Dir's last path element.
	Identity PackageIdentity

	Dir      string
	Platform *platform.Platform

	// Skew is the resolved Platform.spec.skewPolicy (Warn when unset), passed
	// verbatim as RenderInput.Skew by every render of this package
	// (0019:D7/D18).
	Skew kernel.SkewPolicy
}

Generated is the process-local record of the platform module the reconciler generated and built for one PackageIdentity: the identity, the module directory on the operator's own disk (a per-identity directory under the manager's --platform-dir), the source-carrying platform the kernel's shape-gated loader built from it and the skew policy the CR resolved to. The render path consumes it through Store.Lease; the module is never published, written to the cluster or served elsewhere (0019:D6).

type Layout

type Layout struct {
	Root string
}

Layout owns the on-disk lifecycle of generated platform modules under Root (the manager's --platform-dir): one directory per PackageIdentity, written by staging plus rename so a module directory is either absent or complete, pruned to the current and every leased identity after each successful build, and emptied at manager start. The module content itself comes from the library's generator (opm/helper/platformmodule); the lifecycle is operator process policy, which is why it lives here beside the store that records the directories.

func (Layout) Dir

func (l Layout) Dir(id PackageIdentity) string

Dir returns the directory an identity's module lives in, whether or not it exists. The identity's string form is the directory name, so two packages generated for the same CR generation from different active-claim sets get different directories and neither overwrites the other.

func (Layout) Packages

func (l Layout) Packages() ([]string, error)

Packages lists the complete package directories under Root by name — each name the string form of the PackageIdentity it was written for — in lexical order. Staging and moved-aside entries are ignored. The identity is not recoverable from the name (its claim list is digested), so callers compare against an identity's String rather than parsing.

func (Layout) Prune

func (l Layout) Prune(keep ...PackageIdentity) error

Prune removes every entry under Root except the package directories the identities in keep name: superseded packages, staging leftovers and moved-aside copies. A missing Root is not an error.

func (Layout) Reset

func (l Layout) Reset() error

Reset empties Root entirely (the boot path: disk is ephemeral, the CR is the source of truth, and the initial reconcile regenerates) and makes sure Root exists afterwards.

func (Layout) Write

func (l Layout) Write(id PackageIdentity, files platformmodule.Files) (string, error)

Write materialises files as the identity's module directory and returns its path. The files are written into a staging directory first and renamed into place, so no reader observes a partially written module: a failure at any point leaves the staging directory (cleaned by the next Prune or Reset) and never a package directory. An existing directory for the same identity (a re-reconcile after a build failure, or a container restart on the same volume) is moved aside before the swap and removed after it.

type PackageIdentity

type PackageIdentity struct {
	// contains filtered or unexported fields
}

PackageIdentity identifies one generated platform package by the two inputs the package is a function of (0015:D13): the Platform CR's .metadata.generation and the sorted set of active claims' catalog coordinates. Enhancement 0015:D17 makes it the unit the operator holds, because a claim activating changes the package while leaving the generation untouched: keying on the generation alone would leave a render consuming a platform that does not contain the provider just accepted.

The identity is computed from the inputs at generation time and stamped on the result. It is never read back as an input and nothing reconstructs the active set from it, which keeps generation a pure function: the same tuple yields the same identity, and an identity mismatch is the signal that the tuple moved.

The value is comparable, so it keys the store's maps directly, and its fields are unexported so an identity can only be built through NewPackageIdentity and therefore always carries canonically ordered claims.

func NewPackageIdentity

func NewPackageIdentity(generation int64, claims []ClaimCoordinate) PackageIdentity

NewPackageIdentity returns the identity of a package generated for the given Platform CR generation from the given active claims. The claims are canonically ordered, so callers may pass them in any order; repeated coordinates collapse, since one coordinate contributes one #registry entry however many times it is listed.

func (PackageIdentity) Claims

func (id PackageIdentity) Claims() []string

Claims returns the active claims' coordinates in canonical order, as "<catalog>@<version>" strings. The slice is freshly built, so a caller may keep or sort it without disturbing the identity.

func (PackageIdentity) Generation

func (id PackageIdentity) Generation() int64

Generation returns the Platform CR generation the identity was built for.

func (PackageIdentity) IsZero

func (id PackageIdentity) IsZero() bool

IsZero reports whether id is the zero identity, which no generated package carries: a stored Platform's .metadata.generation is at least 1.

func (PackageIdentity) String

func (id PackageIdentity) String() string

String returns the identity's stable, bounded, filesystem-safe form: "gen-<generation>" when no claim is active, and "gen-<generation>-<digest>" otherwise, where digest is the first 8 bytes of the SHA-256 of the canonical claim list. Bounded rather than the claim list verbatim because the string is both a directory name and a status field; the enumerable form of the active set is Platform status's resolved registry union, not this.

The same inputs always produce the same string and any change to either input produces a different one. A platform with no active claims keeps the plain "gen-<generation>" form the operator used before claims existed.

type Store

type Store struct {
	// contains filtered or unexported fields
}

Store holds at most one current generated platform, keyed on the PackageIdentity it was built for. One Platform per cluster needs one slot and nothing more.

The key is the identity rather than the CR generation (0015:D17) because a claim activating produces a different package while leaving the generation untouched: keyed on the generation alone, a render would keep consuming a platform that does not contain the provider just accepted.

The Store carries no kernel gate. The single process-wide library Kernel is safe for concurrent use across its method calls (library ADR-007): every verb (module acquisition, instance synthesis, on-disk acquisition, the platform build, the render) builds in a cue.Context of its own and retains nothing, so acquisitions, syntheses and renders of different objects overlap with no mutex.

func NewStore

func NewStore() *Store

NewStore returns an empty Store holding no platform.

func (*Store) Clear

func (s *Store) Clear()

Clear drops the held record so the store reports no platform held. Called when the Platform CR is deleted. Leases outstanding on the dropped identity are kept: the renders holding them still read its directory.

func (*Store) Generated

func (s *Store) Generated() (Generated, bool)

Generated returns the current generated-module record and true, or the zero record and false when none is held. Safe for concurrent callers. A render that will read the module directory takes Lease instead.

func (*Store) Identity

func (s *Store) Identity() PackageIdentity

Identity returns the PackageIdentity of the held platform, or the zero identity when no platform is held.

func (*Store) Lease

func (s *Store) Lease() (rec Generated, release func(), ok bool)

Lease returns the current record and a release function, holding the record's identity leased until release is called; it returns ok false (a zero record and a no-op release) when no platform is held. The caller defers release immediately: a leased identity's module directory survives the PlatformReconciler's prune until every lease on it is released. Release is idempotent.

func (*Store) Leased

func (s *Store) Leased() []PackageIdentity

Leased returns the identities at least one render currently holds a lease on, ordered by their string form so the result is deterministic. The PlatformReconciler adds them to the prune keep set.

func (*Store) SetGenerated

func (s *Store) SetGenerated(g Generated)

SetGenerated records g as the current generated platform module, replacing any earlier record, and reports g.Identity from Identity. Leases on the replaced identity are unaffected: the render holding one finishes against the directory it started with.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL