Problem: the hexagon's Phase 2 (plans/2026-08-15-hexagonal-architecture.md) must give the use-cases-to-be their contract surface: driven-port interfaces, test fakes, the secrets interface moved into core, and the postgres package inside the adapters tree — before the first vertical slice (Phase 3) can wire a composition root. Change: - internal/core/ports: full driven-port catalog per plan §3.3 — repositories as transaction-scoped aggregates whose inputs carry derived checks, audit, and events (§3.6), plus CommandExecutor, TargetResolver, Checker, Secrets, EventPublisher, Provisioner. Port-local payload types (Event, AuditEntry, CheckDef, KnowledgeEntry, ExecResult) keep signatures off infrastructure; TypeTree aliases internal/ontology (pure over domain) until checkdefaults is absorbed. ReadModels intentionally not declared yet — it materializes with the Phase 3 slice and grows as report handlers rewire. - secrets.Backend is now an alias of ports.Secrets; implementations (Infisical, SOPS, Manager) unchanged. mcp's local secretBackend subset is deleted; tool constructors take ports.Secrets. - internal/db → internal/adapters/postgres (mechanical import rewrite; package identifier stays db until the Phase 3 repository split). sqlc.yaml, Makefile, golangci exclusions, and docs follow the move; make generate-check verified. - internal/adapters/ssh: Executor implements ports.CommandExecutor over the actuator dial pool + RunStreaming (10-min default timeout carried over from the httpapi path). - internal/adapters/remote: Resolver implements ports.TargetResolver delegating to internal/remote (still pool-based; drops onto ports.EntityRepository when repositories land in Phase 3 — documented transitional import). - internal/core/ports/portstest: importable fakes — in-memory EntityRepo (with check-then-act SetState, side-effect recording), RecordingExecutor, FakeChecker, SpyPublisher; port-satisfaction guards; tests. Risk: ports are declared ahead of implementations — signatures firm up per phase as slices land (documented in the package doc); the remote→postgres transitional import is explicit and dissolves in Phase 3. Verification: go vet, make test (race, 19 packages), generate-check, golangci on core+adapters — 0 issues; full-repo baseline down 365→344.
115 lines
3.1 KiB
Go
115 lines
3.1 KiB
Go
package httpapi
|
|
|
|
import (
|
|
"context"
|
|
"encoding/json"
|
|
"fmt"
|
|
"time"
|
|
|
|
"github.com/dtoro/oikos/internal/adapters/postgres/sqlcgen"
|
|
"github.com/dtoro/oikos/internal/core/domain"
|
|
"github.com/dtoro/oikos/internal/httpapi/gen"
|
|
"github.com/google/uuid"
|
|
"github.com/jackc/pgx/v5"
|
|
)
|
|
|
|
const (
|
|
defaultLimit = 50
|
|
maxLimit = 200
|
|
// graphNodeCap bounds the whole-graph view. The cognition transactional
|
|
// types (execution, task) are audit records, not topology, and previously
|
|
// crowded out every host/lxc/service; the default whole-graph view below
|
|
// excludes them so the cap is spent on the actual fleet graph. Operators
|
|
// still reach executions/tasks via list_entities.
|
|
graphNodeCap = 2000
|
|
)
|
|
|
|
// actorInfo returns the caller's (type, label) from the request context,
|
|
// falling back to operator/unknown when unset.
|
|
func actorInfo(ctx context.Context) (string, string) {
|
|
if a := GetActor(ctx); a != nil {
|
|
typ := a.Type
|
|
if typ == "" {
|
|
typ = "operator"
|
|
}
|
|
label := a.Label
|
|
if label == "" {
|
|
label = a.ID
|
|
}
|
|
return typ, label
|
|
}
|
|
return "operator", "unknown"
|
|
}
|
|
|
|
func clampLimit(l *int) int {
|
|
if l == nil {
|
|
return defaultLimit
|
|
}
|
|
if *l < 1 {
|
|
return 1
|
|
}
|
|
if *l > maxLimit {
|
|
return maxLimit
|
|
}
|
|
return *l
|
|
}
|
|
|
|
// resolveEntityID resolves a UUID-or-slug path/query value to the entity UUID.
|
|
func (s *Server) resolveEntityID(ctx context.Context, idOrSlug string) (uuid.UUID, error) {
|
|
if id, err := uuid.Parse(idOrSlug); err == nil {
|
|
if _, ok := s.entityCache.GetSlug(id.String()); ok {
|
|
return id, nil
|
|
}
|
|
entity, err := sqlcgen.New(s.pool).GetEntityByID(ctx, id)
|
|
if err != nil {
|
|
return uuid.Nil, fmt.Errorf("%w: %s", domain.ErrNotFound, idOrSlug)
|
|
}
|
|
s.entityCache.Set(entity.Slug, entity.ID.String(), "")
|
|
return entity.ID, nil
|
|
}
|
|
if cachedID, ok := s.entityCache.GetID(idOrSlug); ok {
|
|
id, parseErr := uuid.Parse(cachedID)
|
|
if parseErr == nil {
|
|
return id, nil
|
|
}
|
|
}
|
|
entity, err := sqlcgen.New(s.pool).GetEntityBySlug(ctx, idOrSlug)
|
|
if err != nil {
|
|
return uuid.Nil, fmt.Errorf("%w: %s", domain.ErrNotFound, idOrSlug)
|
|
}
|
|
s.entityCache.Set(entity.Slug, entity.ID.String(), "")
|
|
return entity.ID, nil
|
|
}
|
|
|
|
// entityCols requires the entities table to be aliased as `e`, with
|
|
// entity_status left-joined and aliased as `st` (see withEntityStatus).
|
|
const entityCols = `e.id, e.slug, e.type, e.name, e.state, e.attributes,
|
|
e.maintenance_until, e.version, e.created_at, e.updated_at,
|
|
st.health, st.last_check_at`
|
|
|
|
func scanEntity(row pgx.Row) (gen.Entity, error) {
|
|
var e gen.Entity
|
|
var state *string
|
|
var attrsJSON []byte
|
|
var maint *time.Time
|
|
var health *string
|
|
var lastCheckAt *time.Time
|
|
err := row.Scan(&e.Id, &e.Slug, &e.Type, &e.Name, &state, &attrsJSON,
|
|
&maint, &e.Version, &e.CreatedAt, &e.UpdatedAt, &health, &lastCheckAt)
|
|
if err != nil {
|
|
return e, err
|
|
}
|
|
e.State = state
|
|
e.MaintenanceUntil = maint
|
|
if health != nil {
|
|
h := gen.EntityHealth(*health)
|
|
e.Health = &h
|
|
}
|
|
e.LastCheckAt = lastCheckAt
|
|
var attrs map[string]any
|
|
if len(attrsJSON) > 0 && json.Unmarshal(attrsJSON, &attrs) == nil && len(attrs) > 0 {
|
|
e.Attributes = &attrs
|
|
}
|
|
return e, nil
|
|
}
|