compute

package
v0.15.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 11, 2026 License: Apache-2.0 Imports: 9 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// SourceConfig marks a variable declared in .miren/app.toml. It belongs to
	// the version built from that app.toml.
	SourceConfig = "config"

	// SourceManual marks a variable an operator set.
	SourceManual = "manual"

	// SourceAddon marks a variable an addon contributed. Deprovision strips only
	// keys whose source is exactly this, so the value must never be rewritten to
	// anything else.
	SourceAddon = "addon"
)

Variable sources: who owns a variable. The schema documents this field as "config or manual", but the addon controller writes a third value and the deprovision path matches on it exactly, so name them here.

This is the ownership axis, not RFD-55's storage-backend axis. Storage lives on the `backend` field. See RFD-90, which settled that split.

Variables

This section is empty.

Functions

func ConfigSpecFromConfig

func ConfigSpecFromConfig(cfg *core_v1alpha.Config) core_v1alpha.ConfigSpec

ConfigSpecFromConfig converts the existing inline Config into a ConfigSpec suitable for a ConfigVersion entity. This is used during dual-write to create ConfigVersion entities alongside inline Config.

func GetServiceConcurrency

func GetServiceConcurrency(spec *core_v1alpha.ConfigSpec, serviceName string) (core_v1alpha.ConfigSpecServicesConcurrency, error)

GetServiceConcurrency returns the concurrency configuration for a named service from a ConfigSpec.

func PinSecrets added in v0.14.0

func PinSecrets(ctx context.Context, resolver secret.Resolver, spec *core_v1alpha.ConfigSpec) error

PinSecrets resolves every backend-sourced variable in a config and rewrites each one's value to the fully-qualified reference it resolved to.

Call it immediately before a ConfigVersion is created. An authored reference usually floats ("payments/stripe-key"); what the ConfigVersion records is what it resolved to at that moment ("payments/stripe-key@x1A"). That is what makes "which secret did this version actually ship with?" answerable, and what makes a rollback come back on the value the old version ran with rather than today's.

It is idempotent, because resolving an already-pinned reference returns the same reference. A redeploy therefore re-pins a floating app.toml reference to whatever is current — picking up a rotation — while leaving a hand-set reference at the version it was set to.

A config with no backend-sourced variables never touches the resolver, so a cluster with no secrets in play pays nothing and cannot fail here.

func ResolveConfig

ResolveConfig loads the configuration for an AppVersion. If the version has a ConfigVersion, it loads the ConfigVersion entity and returns its spec directly. Otherwise, it falls back to the inline Config field and converts it.

func ResolveRuntimeConfig added in v0.14.0

ResolveRuntimeConfig returns the config an AppVersion runs with: the version's stored config, plus the addon bindings the app's associations currently supply.

This reads the app's addon associations, so it costs one indexed List per call and fails if that read fails. Callers that write a ConfigVersion must use ResolveConfig instead. Storing the result of this function would put addon bindings back into a version, which is what this removes.

Addon variables stored on the version are dropped, and the live bindings are used instead. This keeps the invariant in one place: an AppVersion records user config, and addon state resolves at runtime. A version that stores a copy never serves it, whether the copy predates this design or a later change writes one.

Precedence:

  • A binding replaces an app.toml declaration of the same key. Declaring DATABASE_URL in app.toml and then attaching a database addon means the addon supplies the value. Required and Description carry from the declaration onto the binding, because `miren env list` shows them and the next build validates against them.
  • A binding never replaces a variable an operator set. See RFD-59.

Before this, an addon contributed its variables by minting a successor version. A version built before the addon existed therefore never contained DATABASE_URL, and activating one left the app without its credentials permanently (MIR-1579).

func SecretReferences added in v0.14.0

func SecretReferences(spec *core_v1alpha.ConfigSpec) []secret.Reference

SecretReferences collects every backend-sourced variable in a config, both the shared ones and the per-service ones.

Types

This section is empty.

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL