Problem: the hexagon's Phase 2 (plans/2026-08-15-hexagonal-architecture.md) must give the use-cases-to-be their contract surface: driven-port interfaces, test fakes, the secrets interface moved into core, and the postgres package inside the adapters tree — before the first vertical slice (Phase 3) can wire a composition root. Change: - internal/core/ports: full driven-port catalog per plan §3.3 — repositories as transaction-scoped aggregates whose inputs carry derived checks, audit, and events (§3.6), plus CommandExecutor, TargetResolver, Checker, Secrets, EventPublisher, Provisioner. Port-local payload types (Event, AuditEntry, CheckDef, KnowledgeEntry, ExecResult) keep signatures off infrastructure; TypeTree aliases internal/ontology (pure over domain) until checkdefaults is absorbed. ReadModels intentionally not declared yet — it materializes with the Phase 3 slice and grows as report handlers rewire. - secrets.Backend is now an alias of ports.Secrets; implementations (Infisical, SOPS, Manager) unchanged. mcp's local secretBackend subset is deleted; tool constructors take ports.Secrets. - internal/db → internal/adapters/postgres (mechanical import rewrite; package identifier stays db until the Phase 3 repository split). sqlc.yaml, Makefile, golangci exclusions, and docs follow the move; make generate-check verified. - internal/adapters/ssh: Executor implements ports.CommandExecutor over the actuator dial pool + RunStreaming (10-min default timeout carried over from the httpapi path). - internal/adapters/remote: Resolver implements ports.TargetResolver delegating to internal/remote (still pool-based; drops onto ports.EntityRepository when repositories land in Phase 3 — documented transitional import). - internal/core/ports/portstest: importable fakes — in-memory EntityRepo (with check-then-act SetState, side-effect recording), RecordingExecutor, FakeChecker, SpyPublisher; port-satisfaction guards; tests. Risk: ports are declared ahead of implementations — signatures firm up per phase as slices land (documented in the package doc); the remote→postgres transitional import is explicit and dissolves in Phase 3. Verification: go vet, make test (race, 19 packages), generate-check, golangci on core+adapters — 0 issues; full-repo baseline down 365→344.
90 lines
3.4 KiB
YAML
90 lines
3.4 KiB
YAML
# golangci-lint v2 configuration for Oikos
|
|
# Docs: https://golangci-lint.run/usage/configuration/
|
|
# Default-enabled linters (errcheck, govet, ineffassign, staticcheck, unused)
|
|
# are not listed below. gosimple/typecheck were absorbed into staticcheck in v2.
|
|
version: "2"
|
|
run:
|
|
tests: true
|
|
linters:
|
|
enable:
|
|
- depguard
|
|
- misspell
|
|
- revive
|
|
settings:
|
|
depguard:
|
|
# ADR 0016 dependency rules. Rules only constrain files that exist:
|
|
# internal/core is live since Phase 0 (domain moved); internal/nomos
|
|
# and its bans activate in Phase 8; full audit at Phase 9.
|
|
rules:
|
|
core-no-agent-tech:
|
|
files:
|
|
- "**/internal/core/**"
|
|
deny:
|
|
- pkg: github.com/dtoro/oikos/internal/nomos
|
|
desc: core never links agent-client packages (ADR 0016 §3.1 rule 3)
|
|
- pkg: github.com/dtoro/oikos/internal/nomos/**
|
|
desc: core never links agent-client packages (ADR 0016 §3.1 rule 3)
|
|
- pkg: github.com/openai/openai-go
|
|
desc: core never links the LLM SDK — nomos is an external client
|
|
- pkg: github.com/openai/openai-go/**
|
|
desc: core never links the LLM SDK — nomos is an external client
|
|
- pkg: github.com/modelcontextprotocol/go-sdk
|
|
desc: core never links MCP packages — mcpserver is a driving adapter
|
|
- pkg: github.com/modelcontextprotocol/go-sdk/**
|
|
desc: core never links MCP packages — mcpserver is a driving adapter
|
|
core-purity:
|
|
files:
|
|
- "**/internal/core/**"
|
|
deny:
|
|
- pkg: github.com/dtoro/oikos/internal/adapters
|
|
desc: core must not import adapters — depend on core/ports instead
|
|
- pkg: github.com/dtoro/oikos/internal/adapters/**
|
|
desc: core must not import adapters — depend on core/ports instead
|
|
- pkg: github.com/dtoro/oikos/cmd
|
|
desc: core must not import composition roots
|
|
- pkg: github.com/dtoro/oikos/cmd/**
|
|
desc: core must not import composition roots
|
|
nomos-isolation:
|
|
files:
|
|
- "**/internal/nomos/**"
|
|
deny:
|
|
- pkg: github.com/dtoro/oikos/internal/core
|
|
desc: nomos must not import core — consume oikos via MCP/REST
|
|
- pkg: github.com/dtoro/oikos/internal/core/**
|
|
desc: nomos must not import core — consume oikos via MCP/REST
|
|
- pkg: github.com/dtoro/oikos/internal/adapters
|
|
desc: nomos must not import adapters — consume oikos via MCP/REST
|
|
- pkg: github.com/dtoro/oikos/internal/adapters/**
|
|
desc: nomos must not import adapters — consume oikos via MCP/REST
|
|
errcheck:
|
|
# Allow unchecked errors on common Close/Flush patterns (deferred cleanup)
|
|
exclude-functions:
|
|
- (io.Closer).Close
|
|
- (*os.File).Close
|
|
exclusions:
|
|
generated: lax
|
|
rules:
|
|
- linters:
|
|
- errcheck
|
|
path: _test\.go
|
|
- linters:
|
|
- all
|
|
path: internal/httpapi/gen/
|
|
- linters:
|
|
- all
|
|
path: internal/adapters/postgres/sqlcgen/
|
|
paths:
|
|
- third_party$
|
|
- builtin$
|
|
- examples$
|
|
issues:
|
|
max-issues-per-linter: 0
|
|
max-same-issues: 0
|
|
formatters:
|
|
exclusions:
|
|
generated: lax
|
|
paths:
|
|
- third_party$
|
|
- builtin$
|
|
- examples$
|