Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ReportStaleAssociationVariables ¶ added in v0.14.0
func ReportStaleAssociationVariables( ctx context.Context, log *slog.Logger, ec *entityserver.Client, eac *entityserver_v1alpha.EntityAccessClient, ) (stale int, checked int, err error)
ReportStaleAssociationVariables warns about associations whose recorded variables disagree with the copy in the app's active version.
Rotation used to write the new credential into a new app version and leave the association holding the provision-time value. The runtime now resolves through the association, so one left stale by a rotation on v0.12.x names a password that no longer works.
This only reports; it never writes. There is no reliable way to tell which record is fresher: before this design the version was, after it the association is. A sweep that guessed wrong would take a working app offline, and it would guess wrong on every coordinator restart that followed a rotation. Running `miren addon rotate` again reconciles both records.
Delete this once v0.12.x and v0.13.x are out of upgrade range. It writes nothing, so there is no data to unwind.
Types ¶
type Controller ¶
type Controller struct {
// contains filtered or unexported fields
}
Controller reconciles AddonAssociation entities, driving provisioning and deprovisioning of addons through their providers.
Implements controller.ReconcileControllerI[*addon_v1alpha.AddonAssociation]
func NewController ¶
func NewController( log *slog.Logger, ec *entityserver.Client, eac *entityserver_v1alpha.EntityAccessClient, registry *addon.Registry, sagaStorage saga.Storage, ) *Controller
NewController creates a new addon controller.
func (*Controller) Reconcile ¶
func (c *Controller) Reconcile(ctx context.Context, assoc *addon_v1alpha.AddonAssociation, meta *entity.Meta) error
type RotationController ¶ added in v0.12.1
type RotationController struct {
// contains filtered or unexported fields
}
RotationController reconciles RotationRequest entities, driving in-place rotation of an addon server credential through the provider's optional CredentialRotator capability.
Rotation is modeled as its own reactive entity rather than an association status because it is server-scoped: one request rotates the credential on the backing server, then redeploys whichever consumers actually embed the rotated secret. Implements controller.ReconcileControllerI[*addon_v1alpha.RotationRequest].
func NewRotationController ¶ added in v0.12.1
func NewRotationController( log *slog.Logger, ec *entityserver.Client, eac *entityserver_v1alpha.EntityAccessClient, registry *addon.Registry, ) *RotationController
NewRotationController creates a new rotation controller.
func (*RotationController) Init ¶ added in v0.12.1
func (c *RotationController) Init(ctx context.Context) error
func (*RotationController) Reconcile ¶ added in v0.12.1
func (c *RotationController) Reconcile(ctx context.Context, req *addon_v1alpha.RotationRequest, meta *entity.Meta) error