Show egress/ingress levels in the registry; freeze checks at the verdict
Registry: the "last result" column now also shows, per level (egress,
ingress), how many of the recorded checks of the latest cycle succeeded, split
by check family (tcp-22 and tcp-443 are both "tcp"). One grouped query per
chunk of addresses; new fields last_cycle_id, egress, ingress in
GET /admin/registry; the dashboard renders them under the verdict.
Verdict integrity (migration 0010):
- the prober is handed an address once per site and attempt, not on every
poll, so results are no longer overwritten by later probe rounds;
- UpsertCheckIfOpen refuses writes once the address is aggregating or has its
verdict, or for an older attempt; senders get {"ok":true,"ignored":N} and a
result_dropped event is recorded;
- the checking window counts from checking_started_at, not from assigned_at;
- checks.recorded_at (server clock) and checks.after_verdict (flag for rows
written after the verdict in existing data);
- the verdict rule is a pure function (computeVerdict) and the aggregated
event carries the egress/ingress check counts.
Rebuilt bin/control-api and bin/admin-dashboard to match. Plans and summaries
are in docs/changes; README, API, USAGE, DASHBOARD and DIAGRAMS are updated.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
db73409e8f
commit
864208238f
34 files changed
+1570
-72
No files matched your search
@@ -0,0 +1,31 @@
|
||||
-- Verdict integrity (see docs/changes/2026-10-03_17-21_verdict-no-late-results-plan.md).
|
||||
--
|
||||
-- ip_queue.checking_started_at: when the address entered the "checking" state.
|
||||
-- The aggregation window (checking_window_seconds) is counted from here, not
|
||||
-- from assigned_at, which also covers floating-IP association, the settle
|
||||
-- pause and the self-check. NULL on rows that predate this migration; the
|
||||
-- orchestrator falls back to assigned_at for them.
|
||||
--
|
||||
-- checks.recorded_at: when control-api last wrote the row, by its own clock.
|
||||
-- checked_at comes from the probing machine's clock, so it cannot be compared
|
||||
-- reliably with aggregated_at. Existing rows get created_at (their first
|
||||
-- write); a later overwrite is not recoverable.
|
||||
--
|
||||
-- checks.after_verdict: 1 when the row was written after the address's
|
||||
-- verdict (checked_at later than aggregated_at). Set here for existing data
|
||||
-- only; new writes after the verdict are rejected, so it stays 0 afterwards.
|
||||
|
||||
ALTER TABLE ip_queue ADD COLUMN checking_started_at TIMESTAMP;
|
||||
|
||||
ALTER TABLE checks ADD COLUMN recorded_at TIMESTAMP;
|
||||
UPDATE checks SET recorded_at = created_at;
|
||||
|
||||
ALTER TABLE checks ADD COLUMN after_verdict INTEGER NOT NULL DEFAULT 0;
|
||||
UPDATE checks SET after_verdict = 1
|
||||
WHERE EXISTS (
|
||||
SELECT 1 FROM ip_queue q
|
||||
WHERE q.registry_id = checks.registry_id
|
||||
AND q.cycle_id = checks.cycle_id
|
||||
AND q.aggregated_at IS NOT NULL
|
||||
AND julianday(checks.checked_at) > julianday(q.aggregated_at)
|
||||
);
|
||||
Reference in new issue
Block a user