Problem: the hexagon's Phase 2 (plans/2026-08-15-hexagonal-architecture.md) must give the use-cases-to-be their contract surface: driven-port interfaces, test fakes, the secrets interface moved into core, and the postgres package inside the adapters tree — before the first vertical slice (Phase 3) can wire a composition root. Change: - internal/core/ports: full driven-port catalog per plan §3.3 — repositories as transaction-scoped aggregates whose inputs carry derived checks, audit, and events (§3.6), plus CommandExecutor, TargetResolver, Checker, Secrets, EventPublisher, Provisioner. Port-local payload types (Event, AuditEntry, CheckDef, KnowledgeEntry, ExecResult) keep signatures off infrastructure; TypeTree aliases internal/ontology (pure over domain) until checkdefaults is absorbed. ReadModels intentionally not declared yet — it materializes with the Phase 3 slice and grows as report handlers rewire. - secrets.Backend is now an alias of ports.Secrets; implementations (Infisical, SOPS, Manager) unchanged. mcp's local secretBackend subset is deleted; tool constructors take ports.Secrets. - internal/db → internal/adapters/postgres (mechanical import rewrite; package identifier stays db until the Phase 3 repository split). sqlc.yaml, Makefile, golangci exclusions, and docs follow the move; make generate-check verified. - internal/adapters/ssh: Executor implements ports.CommandExecutor over the actuator dial pool + RunStreaming (10-min default timeout carried over from the httpapi path). - internal/adapters/remote: Resolver implements ports.TargetResolver delegating to internal/remote (still pool-based; drops onto ports.EntityRepository when repositories land in Phase 3 — documented transitional import). - internal/core/ports/portstest: importable fakes — in-memory EntityRepo (with check-then-act SetState, side-effect recording), RecordingExecutor, FakeChecker, SpyPublisher; port-satisfaction guards; tests. Risk: ports are declared ahead of implementations — signatures firm up per phase as slices land (documented in the package doc); the remote→postgres transitional import is explicit and dissolves in Phase 3. Verification: go vet, make test (race, 19 packages), generate-check, golangci on core+adapters — 0 issues; full-repo baseline down 365→344.
84 lines
2.8 KiB
Go
84 lines
2.8 KiB
Go
package ports
|
|
|
|
import (
|
|
"context"
|
|
|
|
"github.com/dtoro/oikos/internal/core/domain"
|
|
"github.com/dtoro/oikos/internal/ontology"
|
|
)
|
|
|
|
// TypeTree aliases the ontology tree: entity types, relationship types,
|
|
// lifecycle definitions. ontology is pure over domain; it moves under
|
|
// core/ when checkdefaults is absorbed (Phase 3).
|
|
type TypeTree = ontology.TypeTree
|
|
|
|
// EntityFilters bounds entity list/search reads.
|
|
type EntityFilters struct {
|
|
Type string
|
|
State string
|
|
Q string
|
|
Limit int
|
|
}
|
|
|
|
// EntityCreateInput is one transaction: the entity, its derived check
|
|
// definitions, and the audit/event side-effects of the creation.
|
|
type EntityCreateInput struct {
|
|
Entity domain.Entity
|
|
DerivedChecks []CheckDef
|
|
Audit []AuditEntry
|
|
Event *Event
|
|
}
|
|
|
|
// EntityUpdateInput mirrors EntityCreateInput for updates.
|
|
type EntityUpdateInput struct {
|
|
Entity domain.Entity
|
|
DerivedChecks []CheckDef
|
|
Audit []AuditEntry
|
|
Event *Event
|
|
}
|
|
|
|
// EntityTransitionInput is a lifecycle state change: the check-then-act
|
|
// precondition (current state) is validated inside the transaction.
|
|
type EntityTransitionInput struct {
|
|
Slug string
|
|
From string
|
|
To string
|
|
Audit []AuditEntry
|
|
Event *Event
|
|
}
|
|
|
|
// EntityRepository is the entity aggregate. Command methods are
|
|
// transaction-scoped: everything in the input commits or nothing does.
|
|
type EntityRepository interface {
|
|
Get(ctx context.Context, id domain.UUID) (domain.Entity, error)
|
|
BySlug(ctx context.Context, slug string) (domain.Entity, error)
|
|
List(ctx context.Context, filters EntityFilters) ([]domain.Entity, error)
|
|
Search(ctx context.Context, q string, limit int) ([]domain.Entity, error)
|
|
|
|
Create(ctx context.Context, input EntityCreateInput) (domain.Entity, error)
|
|
Update(ctx context.Context, input EntityUpdateInput) (domain.Entity, error)
|
|
SetState(ctx context.Context, input EntityTransitionInput) (domain.Entity, error)
|
|
}
|
|
|
|
// RelationshipCreateInput validates endpoints against the ontology in core
|
|
// before this is called; the repository persists the edge (+audit/event).
|
|
type RelationshipCreateInput struct {
|
|
Relationship domain.Relationship
|
|
Audit []AuditEntry
|
|
Event *Event
|
|
}
|
|
|
|
// RelationshipRepository is the relationship aggregate.
|
|
type RelationshipRepository interface {
|
|
Create(ctx context.Context, input RelationshipCreateInput) (domain.Relationship, error)
|
|
End(ctx context.Context, source, target domain.UUID, relType string) error
|
|
ListFor(ctx context.Context, entityID domain.UUID, direction string) ([]domain.Relationship, error)
|
|
}
|
|
|
|
// OntologyStore loads the type tree; implementations cache. Consumers
|
|
// validate entity types, relationship endpoints, and lifecycle transitions
|
|
// against it before issuing repository writes.
|
|
type OntologyStore interface {
|
|
LoadTypeTree(ctx context.Context) (TypeTree, error)
|
|
}
|