Make agent creation swarm-only and refuse a name placed on another hive
swarm-controller's POST /api/agents now refuses (409) a name the swarm
has already placed on a different hive: a non-Destroyed declaration in
that hive's wanted state, or a SetAgentWanted node still queued for it.
The same name on the same hive is that agent being re-created and goes
through. A wanted state that cannot be read refuses (503/500) instead of
reading as "placed nowhere". Creations are serialised from that read to
the graph insert so two concurrent creations of one name cannot both
pass.
Hive-level creation is removed: hivectl `agent create` / `request-create`,
HostRequest::Spawn / RequestSpawn, the dashboard POST /api/request-spawn
route, and ApprovalKind::Spawn with its approve/resolve arms and the
approval-carrying `templates::spawn`. The swarm path (deploy request or
wanted-state sweep -> queue_first_deploy -> templates::first_deploy) used
none of them. Old `spawn` approval rows are skipped by collect_lenient,
as `init_config` rows were in a3b672d1.
policy.rs's comment on agent_object_name stated swarm-wide name
uniqueness as a fact; it now says where it is enforced and what that
check cannot see.
Refs #4396
This commit is contained in:
parent
1d8ec00ddc
commit
5785c0024c
35 changed files with 376 additions and 434 deletions
|
|
@ -370,10 +370,9 @@ async fn handle_deploy_request(
|
|||
/// (`power::Store::get_or_seed`), and at that point the container is freshly
|
||||
/// created but not started — so an unseeded row locks the agent to `Offline`
|
||||
/// on its very first reconcile and `Reconcile` never emits the `Start` node.
|
||||
/// Setting the row up front closes that window, the same way
|
||||
/// `actions::approve`'s `ApprovalKind::Spawn` arm does for the
|
||||
/// operator-approved path. A second caller open-coding the insert would lose
|
||||
/// exactly that, and the agent would come up stopped for no visible reason.
|
||||
/// Setting the row up front closes that window. A second caller open-coding
|
||||
/// the insert would lose exactly that, and the agent would come up stopped for
|
||||
/// no visible reason.
|
||||
pub(crate) fn queue_first_deploy(
|
||||
coord: &std::sync::Arc<crate::coordinator::Coordinator>,
|
||||
agent: &str,
|
||||
|
|
|
|||
Loading…
Reference in a new issue