Documentation
¶
Overview ¶
Package platform holds the process-local platform store: a single-slot, concurrency-safe holder of the platform module generated and built from the cluster-singleton Platform CR and the set of active transformer claims. It is written by the PlatformReconciler and read by the render path. It also owns Layout, the on-disk lifecycle of the generated module directories the store records (per-identity directories, staging swaps, retention, boot reset); the module content itself comes from the library's opm/helper/platformmodule generator.
The store records one Generated platform module per PackageIdentity: the module directory on the operator's own disk, the platform value the kernel built from it and the resolved catalog-skew policy (0019:D6, D7). A render leases the record for its duration (Store.Lease) so the PlatformReconciler never prunes a module directory a render build is still reading from.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type ClaimCoordinate ¶
ClaimCoordinate is one active claim's catalog coordinate: the provider catalog's major-suffixed CUE module path and the released version the claim pins. It is the unit a PackageIdentity is built from, and the same pair the generated module's #registry entry carries.
func (ClaimCoordinate) String ¶
func (c ClaimCoordinate) String() string
String returns the coordinate's canonical "<catalog>@<version>" form.
type Generated ¶
type Generated struct {
// Identity is what the package is a function of: the Platform CR
// generation plus the active claims' catalog coordinates (0015:D13). It
// is the store's key and the name of Dir's last path element.
Identity PackageIdentity
Dir string
Platform *platform.Platform
// Skew is the resolved Platform.spec.skewPolicy (Warn when unset), passed
// verbatim as RenderInput.Skew by every render of this package
// (0019:D7/D18).
Skew kernel.SkewPolicy
}
Generated is the process-local record of the platform module the reconciler generated and built for one PackageIdentity: the identity, the module directory on the operator's own disk (a per-identity directory under the manager's --platform-dir), the source-carrying platform the kernel's shape-gated loader built from it and the skew policy the CR resolved to. The render path consumes it through Store.Lease; the module is never published, written to the cluster or served elsewhere (0019:D6).
type Layout ¶
type Layout struct {
Root string
}
Layout owns the on-disk lifecycle of generated platform modules under Root (the manager's --platform-dir): one directory per PackageIdentity, written by staging plus rename so a module directory is either absent or complete, pruned to the current and every leased identity after each successful build, and emptied at manager start. The module content itself comes from the library's generator (opm/helper/platformmodule); the lifecycle is operator process policy, which is why it lives here beside the store that records the directories.
func (Layout) Dir ¶
func (l Layout) Dir(id PackageIdentity) string
Dir returns the directory an identity's module lives in, whether or not it exists. The identity's string form is the directory name, so two packages generated for the same CR generation from different active-claim sets get different directories and neither overwrites the other.
func (Layout) Packages ¶
Packages lists the complete package directories under Root by name — each name the string form of the PackageIdentity it was written for — in lexical order. Staging and moved-aside entries are ignored. The identity is not recoverable from the name (its claim list is digested), so callers compare against an identity's String rather than parsing.
func (Layout) Prune ¶
func (l Layout) Prune(keep ...PackageIdentity) error
Prune removes every entry under Root except the package directories the identities in keep name: superseded packages, staging leftovers and moved-aside copies. A missing Root is not an error.
func (Layout) Reset ¶
Reset empties Root entirely (the boot path: disk is ephemeral, the CR is the source of truth, and the initial reconcile regenerates) and makes sure Root exists afterwards.
func (Layout) Write ¶
func (l Layout) Write(id PackageIdentity, files platformmodule.Files) (string, error)
Write materialises files as the identity's module directory and returns its path. The files are written into a staging directory first and renamed into place, so no reader observes a partially written module: a failure at any point leaves the staging directory (cleaned by the next Prune or Reset) and never a package directory. An existing directory for the same identity (a re-reconcile after a build failure, or a container restart on the same volume) is moved aside before the swap and removed after it.
type PackageIdentity ¶
type PackageIdentity struct {
// contains filtered or unexported fields
}
PackageIdentity identifies one generated platform package by the two inputs the package is a function of (0015:D13): the Platform CR's .metadata.generation and the sorted set of active claims' catalog coordinates. Enhancement 0015:D17 makes it the unit the operator holds, because a claim activating changes the package while leaving the generation untouched: keying on the generation alone would leave a render consuming a platform that does not contain the provider just accepted.
The identity is computed from the inputs at generation time and stamped on the result. It is never read back as an input and nothing reconstructs the active set from it, which keeps generation a pure function: the same tuple yields the same identity, and an identity mismatch is the signal that the tuple moved.
The value is comparable, so it keys the store's maps directly, and its fields are unexported so an identity can only be built through NewPackageIdentity and therefore always carries canonically ordered claims.
func NewPackageIdentity ¶
func NewPackageIdentity(generation int64, claims []ClaimCoordinate) PackageIdentity
NewPackageIdentity returns the identity of a package generated for the given Platform CR generation from the given active claims. The claims are canonically ordered, so callers may pass them in any order; repeated coordinates collapse, since one coordinate contributes one #registry entry however many times it is listed.
func (PackageIdentity) Claims ¶
func (id PackageIdentity) Claims() []string
Claims returns the active claims' coordinates in canonical order, as "<catalog>@<version>" strings. The slice is freshly built, so a caller may keep or sort it without disturbing the identity.
func (PackageIdentity) Generation ¶
func (id PackageIdentity) Generation() int64
Generation returns the Platform CR generation the identity was built for.
func (PackageIdentity) IsZero ¶
func (id PackageIdentity) IsZero() bool
IsZero reports whether id is the zero identity, which no generated package carries: a stored Platform's .metadata.generation is at least 1.
func (PackageIdentity) String ¶
func (id PackageIdentity) String() string
String returns the identity's stable, bounded, filesystem-safe form: "gen-<generation>" when no claim is active, and "gen-<generation>-<digest>" otherwise, where digest is the first 8 bytes of the SHA-256 of the canonical claim list. Bounded rather than the claim list verbatim because the string is both a directory name and a status field; the enumerable form of the active set is Platform status's resolved registry union, not this.
The same inputs always produce the same string and any change to either input produces a different one. A platform with no active claims keeps the plain "gen-<generation>" form the operator used before claims existed.
type Store ¶
type Store struct {
// contains filtered or unexported fields
}
Store holds at most one current generated platform, keyed on the PackageIdentity it was built for. One Platform per cluster needs one slot and nothing more.
The key is the identity rather than the CR generation (0015:D17) because a claim activating produces a different package while leaving the generation untouched: keyed on the generation alone, a render would keep consuming a platform that does not contain the provider just accepted.
The Store carries no kernel gate. The single process-wide library Kernel is safe for concurrent use across its method calls (library ADR-007): every verb (module acquisition, instance synthesis, on-disk acquisition, the platform build, the render) builds in a cue.Context of its own and retains nothing, so acquisitions, syntheses and renders of different objects overlap with no mutex.
func (*Store) Clear ¶
func (s *Store) Clear()
Clear drops the held record so the store reports no platform held. Called when the Platform CR is deleted. Leases outstanding on the dropped identity are kept: the renders holding them still read its directory.
func (*Store) Generated ¶
Generated returns the current generated-module record and true, or the zero record and false when none is held. Safe for concurrent callers. A render that will read the module directory takes Lease instead.
func (*Store) Identity ¶
func (s *Store) Identity() PackageIdentity
Identity returns the PackageIdentity of the held platform, or the zero identity when no platform is held.
func (*Store) Lease ¶
Lease returns the current record and a release function, holding the record's identity leased until release is called; it returns ok false (a zero record and a no-op release) when no platform is held. The caller defers release immediately: a leased identity's module directory survives the PlatformReconciler's prune until every lease on it is released. Release is idempotent.
func (*Store) Leased ¶
func (s *Store) Leased() []PackageIdentity
Leased returns the identities at least one render currently holds a lease on, ordered by their string form so the result is deterministic. The PlatformReconciler adds them to the prune keep set.
func (*Store) SetGenerated ¶
SetGenerated records g as the current generated platform module, replacing any earlier record, and reports g.Identity from Identity. Leases on the replaced identity are unaffected: the render holding one finishes against the directory it started with.