The cloud is live: the address list submitted as "free" (bootstrap config
or POST /api/v1/admin/ips) can drift by the time the orchestrator claims
it, or an operator can queue an already-occupied address by mistake.
Neutron's floating-IP association is a blind "last write wins" PUT with
no conflict error to catch, so associateFIP now checks the FIP's PortID
(already fetched via GetFloatingIPByAddress) before associating, guarded
against the false-positive of the FIP already belonging to this same
validator's own port.
A match routes the address straight to a new terminal ip_queue.state
("occupied", distinct from failed/fail) via db.MarkFIPOccupied — no
retries, since Neutron won't free it on its own and requeuing would let
it be reclaimed again next tick, starving the rest of the queue — plus a
dedicated fip_occupied audit event. Resubmitting the address later (once
the conflict is resolved) resets it to queued via the existing
POST /api/v1/admin/ips resubmit path (CancelIP/ListExpiredLeases updated
to treat occupied as terminal too). admin-dashboard gets its own "занят"
badge, distinct from fail/partial/cancelled.
Rebuilt bin/{control-api,admin-dashboard,prober,validator-agent} and
bin/SHA256SUMS per docs/SETUP.md's documented build recipe, since
control-api and admin-dashboard source changed.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NeVbMVEiE7XQAkBd7HQgj6
195 lines
4.6 KiB
Go
195 lines
4.6 KiB
Go
package db
|
|
|
|
import "time"
|
|
|
|
// Validator and IP lifecycle states. Kept as typed string constants rather
|
|
// than a Go enum type so they round-trip through SQLite TEXT columns and
|
|
// JSON without conversion.
|
|
const (
|
|
ValidatorUnregistered = "unregistered"
|
|
ValidatorIdle = "idle"
|
|
ValidatorAssigned = "assigned"
|
|
ValidatorChecking = "checking"
|
|
ValidatorUnreachable = "unreachable"
|
|
|
|
// Site (prober) availability states — no assigned/checking equivalent,
|
|
// since a prober isn't bound to one IP at a time.
|
|
SiteUnregistered = "unregistered"
|
|
SiteIdle = "idle"
|
|
SiteUnreachable = "unreachable"
|
|
|
|
IPQueued = "queued"
|
|
IPAssigningFIP = "assigning_fip"
|
|
IPAwaitingSelfCheck = "awaiting_self_check"
|
|
IPChecking = "checking"
|
|
IPAggregating = "aggregating"
|
|
IPDone = "done"
|
|
IPFailed = "failed"
|
|
// IPOccupied is a terminal state distinct from IPFailed: the floating IP
|
|
// was found already associated to a different port at claim time, so the
|
|
// check cycle never started for this attempt. See
|
|
// Orchestrator.associateFIP and db.MarkFIPOccupied.
|
|
IPOccupied = "occupied"
|
|
|
|
ResultPass = "pass"
|
|
ResultPartial = "partial"
|
|
ResultFail = "fail"
|
|
ResultCancelled = "cancelled"
|
|
|
|
SourceEgress = "egress"
|
|
)
|
|
|
|
// InboundSource returns the checks.source value for the given prober site
|
|
// index (1-based), e.g. InboundSource(1) == "inbound-site-1".
|
|
func InboundSource(siteIndex int) string {
|
|
return "inbound-site-" + itoa(siteIndex)
|
|
}
|
|
|
|
func itoa(n int) string {
|
|
if n == 0 {
|
|
return "0"
|
|
}
|
|
neg := n < 0
|
|
if neg {
|
|
n = -n
|
|
}
|
|
var buf [20]byte
|
|
i := len(buf)
|
|
for n > 0 {
|
|
i--
|
|
buf[i] = byte('0' + n%10)
|
|
n /= 10
|
|
}
|
|
if neg {
|
|
i--
|
|
buf[i] = '-'
|
|
}
|
|
return string(buf[i:])
|
|
}
|
|
|
|
type Validator struct {
|
|
ValidatorID string
|
|
Hostname string
|
|
OSPortID string
|
|
State string
|
|
CurrentIPID *int64
|
|
AgentVersion string
|
|
LastHeartbeatAt *time.Time
|
|
CreatedAt time.Time
|
|
UpdatedAt time.Time
|
|
}
|
|
|
|
type IPQueueItem struct {
|
|
ID int64
|
|
IPAddress string
|
|
Sequence int
|
|
State string
|
|
OwnerValidatorID *string
|
|
FIPID string
|
|
AttemptNumber int
|
|
RetryCount int
|
|
LeaseExpiresAt *time.Time
|
|
EgressComplete bool
|
|
OverallResult string
|
|
AssignedAt *time.Time
|
|
FIPAssociatedAt *time.Time
|
|
AggregatedAt *time.Time
|
|
FIPReleasedAt *time.Time
|
|
CreatedAt time.Time
|
|
UpdatedAt time.Time
|
|
}
|
|
|
|
type Check struct {
|
|
ID int64
|
|
IPID int64
|
|
IPAddress string
|
|
AttemptNumber int
|
|
ValidatorID string
|
|
Source string
|
|
CheckType string
|
|
Target string
|
|
Success bool
|
|
LatencyMS int64
|
|
Detail string
|
|
CheckedAt time.Time
|
|
CreatedAt time.Time
|
|
}
|
|
|
|
type Event struct {
|
|
ID int64
|
|
SourceType string
|
|
SourceID string
|
|
IPID *int64
|
|
EventType string
|
|
Payload string
|
|
OccurredAt time.Time
|
|
CreatedAt time.Time
|
|
}
|
|
|
|
type Site struct {
|
|
Index int
|
|
SiteID string
|
|
Hostname string
|
|
State string
|
|
LastHeartbeatAt *time.Time
|
|
CreatedAt time.Time
|
|
UpdatedAt time.Time
|
|
}
|
|
|
|
type TargetGroup struct {
|
|
Name string
|
|
Targets []string
|
|
CreatedAt time.Time
|
|
UpdatedAt time.Time
|
|
}
|
|
|
|
type CheckType struct {
|
|
Name string
|
|
Enabled bool
|
|
TargetGroups []string
|
|
CreatedAt time.Time
|
|
UpdatedAt time.Time
|
|
}
|
|
|
|
// ResolvedCheckType is a check type with its target groups already expanded
|
|
// into a flat target list — what AssignmentForValidator hands to an agent.
|
|
type ResolvedCheckType struct {
|
|
Type string
|
|
Targets []string
|
|
}
|
|
|
|
// SubmitIPsResult categorizes how each address in a SubmitIPs call was
|
|
// handled.
|
|
type SubmitIPsResult struct {
|
|
Added []string
|
|
Requeued []string
|
|
Reordered []string
|
|
SkippedInProgress []string
|
|
}
|
|
|
|
// DeleteIPsResult categorizes how each address in a DeleteIPs call (or a
|
|
// ClearQueue call, which is DeleteIPs given every currently queued address)
|
|
// was handled.
|
|
type DeleteIPsResult struct {
|
|
Deleted []string
|
|
NotFound []string
|
|
}
|
|
|
|
// Settings is the singleton row of orchestrator-wide scalar knobs that are
|
|
// admin-configurable at runtime (see queries_settings.go).
|
|
type Settings struct {
|
|
FIPSettleSeconds int
|
|
CreatedAt time.Time
|
|
UpdatedAt time.Time
|
|
}
|
|
|
|
// InboundChecksSettings is the singleton row describing what the prober
|
|
// checks on every site for every in-flight IP (TCP ports + optional ICMP).
|
|
// Admin-configurable at runtime (see queries_inbound.go).
|
|
type InboundChecksSettings struct {
|
|
Ports []int
|
|
ICMP bool
|
|
CreatedAt time.Time
|
|
UpdatedAt time.Time
|
|
}
|