Files
oikos/internal/httpapi/impl.go
dtoro 64f7d54011
Some checks failed
ci / build-test (push) Has been cancelled
ci / docker-build (push) Has been cancelled
feat: Phase 2 — ports package, secrets port move, postgres adapter move
Problem: the hexagon's Phase 2 (plans/2026-08-15-hexagonal-architecture.md)
must give the use-cases-to-be their contract surface: driven-port
interfaces, test fakes, the secrets interface moved into core, and the
postgres package inside the adapters tree — before the first vertical
slice (Phase 3) can wire a composition root.

Change:
- internal/core/ports: full driven-port catalog per plan §3.3 —
  repositories as transaction-scoped aggregates whose inputs carry
  derived checks, audit, and events (§3.6), plus CommandExecutor,
  TargetResolver, Checker, Secrets, EventPublisher, Provisioner.
  Port-local payload types (Event, AuditEntry, CheckDef, KnowledgeEntry,
  ExecResult) keep signatures off infrastructure; TypeTree aliases
  internal/ontology (pure over domain) until checkdefaults is absorbed.
  ReadModels intentionally not declared yet — it materializes with the
  Phase 3 slice and grows as report handlers rewire.
- secrets.Backend is now an alias of ports.Secrets; implementations
  (Infisical, SOPS, Manager) unchanged. mcp's local secretBackend
  subset is deleted; tool constructors take ports.Secrets.
- internal/db → internal/adapters/postgres (mechanical import rewrite;
  package identifier stays db until the Phase 3 repository split).
  sqlc.yaml, Makefile, golangci exclusions, and docs follow the move;
  make generate-check verified.
- internal/adapters/ssh: Executor implements ports.CommandExecutor over
  the actuator dial pool + RunStreaming (10-min default timeout carried
  over from the httpapi path).
- internal/adapters/remote: Resolver implements ports.TargetResolver
  delegating to internal/remote (still pool-based; drops onto
  ports.EntityRepository when repositories land in Phase 3 — documented
  transitional import).
- internal/core/ports/portstest: importable fakes — in-memory
  EntityRepo (with check-then-act SetState, side-effect recording),
  RecordingExecutor, FakeChecker, SpyPublisher; port-satisfaction
  guards; tests.

Risk: ports are declared ahead of implementations — signatures firm up
per phase as slices land (documented in the package doc); the
remote→postgres transitional import is explicit and dissolves in
Phase 3.

Verification: go vet, make test (race, 19 packages), generate-check,
golangci on core+adapters — 0 issues; full-repo baseline down
365→344.
2026-08-15 22:56:56 +02:00

115 lines
3.1 KiB
Go

package httpapi
import (
"context"
"encoding/json"
"fmt"
"time"
"github.com/dtoro/oikos/internal/adapters/postgres/sqlcgen"
"github.com/dtoro/oikos/internal/core/domain"
"github.com/dtoro/oikos/internal/httpapi/gen"
"github.com/google/uuid"
"github.com/jackc/pgx/v5"
)
const (
defaultLimit = 50
maxLimit = 200
// graphNodeCap bounds the whole-graph view. The cognition transactional
// types (execution, task) are audit records, not topology, and previously
// crowded out every host/lxc/service; the default whole-graph view below
// excludes them so the cap is spent on the actual fleet graph. Operators
// still reach executions/tasks via list_entities.
graphNodeCap = 2000
)
// actorInfo returns the caller's (type, label) from the request context,
// falling back to operator/unknown when unset.
func actorInfo(ctx context.Context) (string, string) {
if a := GetActor(ctx); a != nil {
typ := a.Type
if typ == "" {
typ = "operator"
}
label := a.Label
if label == "" {
label = a.ID
}
return typ, label
}
return "operator", "unknown"
}
func clampLimit(l *int) int {
if l == nil {
return defaultLimit
}
if *l < 1 {
return 1
}
if *l > maxLimit {
return maxLimit
}
return *l
}
// resolveEntityID resolves a UUID-or-slug path/query value to the entity UUID.
func (s *Server) resolveEntityID(ctx context.Context, idOrSlug string) (uuid.UUID, error) {
if id, err := uuid.Parse(idOrSlug); err == nil {
if _, ok := s.entityCache.GetSlug(id.String()); ok {
return id, nil
}
entity, err := sqlcgen.New(s.pool).GetEntityByID(ctx, id)
if err != nil {
return uuid.Nil, fmt.Errorf("%w: %s", domain.ErrNotFound, idOrSlug)
}
s.entityCache.Set(entity.Slug, entity.ID.String(), "")
return entity.ID, nil
}
if cachedID, ok := s.entityCache.GetID(idOrSlug); ok {
id, parseErr := uuid.Parse(cachedID)
if parseErr == nil {
return id, nil
}
}
entity, err := sqlcgen.New(s.pool).GetEntityBySlug(ctx, idOrSlug)
if err != nil {
return uuid.Nil, fmt.Errorf("%w: %s", domain.ErrNotFound, idOrSlug)
}
s.entityCache.Set(entity.Slug, entity.ID.String(), "")
return entity.ID, nil
}
// entityCols requires the entities table to be aliased as `e`, with
// entity_status left-joined and aliased as `st` (see withEntityStatus).
const entityCols = `e.id, e.slug, e.type, e.name, e.state, e.attributes,
e.maintenance_until, e.version, e.created_at, e.updated_at,
st.health, st.last_check_at`
func scanEntity(row pgx.Row) (gen.Entity, error) {
var e gen.Entity
var state *string
var attrsJSON []byte
var maint *time.Time
var health *string
var lastCheckAt *time.Time
err := row.Scan(&e.Id, &e.Slug, &e.Type, &e.Name, &state, &attrsJSON,
&maint, &e.Version, &e.CreatedAt, &e.UpdatedAt, &health, &lastCheckAt)
if err != nil {
return e, err
}
e.State = state
e.MaintenanceUntil = maint
if health != nil {
h := gen.EntityHealth(*health)
e.Health = &h
}
e.LastCheckAt = lastCheckAt
var attrs map[string]any
if len(attrsJSON) > 0 && json.Unmarshal(attrsJSON, &attrs) == nil && len(attrs) > 0 {
e.Attributes = &attrs
}
return e, nil
}