Files
cloud-ip-validator/internal/httpapi/handlers_prober.go
T
ayurishchevandClaude Sonnet 5.5 864208238f Show egress/ingress levels in the registry; freeze checks at the verdict
Registry: the "last result" column now also shows, per level (egress,
ingress), how many of the recorded checks of the latest cycle succeeded, split
by check family (tcp-22 and tcp-443 are both "tcp"). One grouped query per
chunk of addresses; new fields last_cycle_id, egress, ingress in
GET /admin/registry; the dashboard renders them under the verdict.

Verdict integrity (migration 0010):
- the prober is handed an address once per site and attempt, not on every
  poll, so results are no longer overwritten by later probe rounds;
- UpsertCheckIfOpen refuses writes once the address is aggregating or has its
  verdict, or for an older attempt; senders get {"ok":true,"ignored":N} and a
  result_dropped event is recorded;
- the checking window counts from checking_started_at, not from assigned_at;
- checks.recorded_at (server clock) and checks.after_verdict (flag for rows
  written after the verdict in existing data);
- the verdict rule is a pure function (computeVerdict) and the aggregated
  event carries the egress/ingress check counts.

Rebuilt bin/control-api and bin/admin-dashboard to match. Plans and summaries
are in docs/changes; README, API, USAGE, DASHBOARD and DIAGRAMS are updated.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-03 17:59:52 +03:00

152 lines
5.0 KiB
Go

package httpapi
import (
"context"
"fmt"
"net/http"
"time"
"cloudipvalidator/internal/db"
)
func (s *Server) handleProberRegister(w http.ResponseWriter, r *http.Request) {
var req registerProberRequest
if err := readJSON(r, &req); err != nil {
writeError(w, http.StatusBadRequest, "invalid body: "+err.Error())
return
}
idx, err := s.Orch.SiteIndexForID(r.Context(), req.SiteID)
if err != nil {
writeError(w, http.StatusInternalServerError, err.Error())
return
}
if idx == 0 {
writeError(w, http.StatusBadRequest, "unknown site_id: "+req.SiteID)
return
}
if err := s.DB.RegisterSiteProber(r.Context(), req.SiteID, req.Hostname); err != nil {
writeError(w, http.StatusInternalServerError, err.Error())
return
}
s.Orch.RecordEvent(r.Context(), "prober", req.SiteID, nil, "registered", "")
writeJSON(w, http.StatusOK, registerAgentResponse{OK: true, PollIntervalSeconds: s.Orch.Cfg.PollIntervalSeconds})
}
func (s *Server) handleProberHeartbeat(w http.ResponseWriter, r *http.Request) {
siteID := r.PathValue("site_id")
var req heartbeatRequest
_ = readJSON(r, &req) // heartbeat body is informational only; tolerate empty/missing
if err := s.DB.SiteHeartbeat(r.Context(), siteID); err != nil {
writeError(w, http.StatusNotFound, "unknown site_id: "+siteID)
return
}
writeJSON(w, http.StatusOK, okResponse{OK: true})
}
// handleProberAssignments returns every IP currently in the checking state
// that this site has not yet finished probing in the current attempt —
// probers work the whole active set each poll, not one IP at a time, since
// multiple validators run in parallel. An address is handed out until the
// site reports it complete, then no more: one probe round per site per
// attempt, so results are written once and never overwritten.
func (s *Server) handleProberAssignments(w http.ResponseWriter, r *http.Request) {
siteID := r.PathValue("site_id")
idx, err := s.Orch.SiteIndexForID(r.Context(), siteID)
if err != nil {
writeError(w, http.StatusInternalServerError, err.Error())
return
}
if idx == 0 {
writeError(w, http.StatusNotFound, "unknown site_id: "+siteID)
return
}
items, err := s.DB.ListCheckingForSite(r.Context(), idx)
if err != nil {
writeError(w, http.StatusInternalServerError, err.Error())
return
}
inbound, err := s.DB.GetInboundChecks(r.Context())
if err != nil {
writeError(w, http.StatusInternalServerError, err.Error())
return
}
out := make([]proberAssignment, 0, len(items))
for _, item := range items {
out = append(out, proberAssignment{
IPID: item.ID, IPAddress: item.IPAddress,
Ports: inbound.Ports, ICMP: inbound.ICMP,
})
}
writeJSON(w, http.StatusOK, out)
}
func (s *Server) handleProberResults(w http.ResponseWriter, r *http.Request) {
siteID := r.PathValue("site_id")
siteIndex, err := s.Orch.SiteIndexForID(r.Context(), siteID)
if err != nil {
writeError(w, http.StatusInternalServerError, err.Error())
return
}
if siteIndex == 0 {
writeError(w, http.StatusNotFound, "unknown site_id: "+siteID)
return
}
var req proberResultsRequest
if err := readJSON(r, &req); err != nil {
writeError(w, http.StatusBadRequest, "invalid body: "+err.Error())
return
}
completed := map[int64]bool{}
dropped := map[int64]int{}
for _, res := range req.Results {
item, err := s.DB.GetIP(r.Context(), res.IPID)
if err != nil {
writeError(w, http.StatusNotFound, "unknown ip_id")
return
}
checkedAt, err := time.Parse(time.RFC3339Nano, res.CheckedAt)
if err != nil {
checkedAt = db.Now()
}
written, err := s.Orch.RecordCheckIfOpen(r.Context(), db.Check{
IPID: item.ID, IPAddress: item.IPAddress, AttemptNumber: item.AttemptNumber,
Source: db.InboundSource(siteIndex), CheckType: res.CheckType, Target: res.IPAddress,
Success: res.Success, LatencyMS: res.LatencyMS, Detail: res.Detail, CheckedAt: checkedAt,
})
if err != nil {
writeError(w, http.StatusInternalServerError, err.Error())
return
}
if !written {
dropped[item.ID]++
continue
}
if res.Complete {
completed[res.IPID] = true
}
}
for ipID := range completed {
if err := s.Orch.MarkSiteComplete(r.Context(), ipID, siteIndex); err != nil {
writeError(w, http.StatusInternalServerError, err.Error())
return
}
}
writeJSON(w, http.StatusOK, s.reportDropped(r.Context(), "prober", siteID, db.InboundSource(siteIndex), dropped))
}
// reportDropped records one result_dropped event per address whose submitted
// checks were refused (the verdict already exists, or the attempt is old) and
// builds the response. The events are the audit trail of how often senders
// are late; in a healthy run there are none.
func (s *Server) reportDropped(ctx context.Context, sourceType, sourceID, checkSource string, dropped map[int64]int) resultsResponse {
total := 0
for ipID, n := range dropped {
total += n
id := ipID
s.Orch.RecordEvent(ctx, sourceType, sourceID, &id, "result_dropped",
fmt.Sprintf(`{"source":%q,"dropped":%d}`, checkSource, n))
}
return resultsResponse{OK: true, Ignored: total}
}