Compare commits
8
Commits
b24b85c31f
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
dae546e58e | ||
|
|
2270e013f0
|
||
|
|
a84c37d842 | ||
|
|
0c66760628
|
||
|
|
da22b6b266 | ||
|
|
e1c6eec91a
|
||
|
|
fdd43f32d1 | ||
|
|
87ec7896b5
|
@@ -13,7 +13,7 @@ jobs:
|
|||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
name: Run on Ubuntu
|
name: Run on Ubuntu
|
||||||
runs-on: self-hosted
|
runs-on: [self-hosted, pod]
|
||||||
steps:
|
steps:
|
||||||
- name: Clone the code
|
- name: Clone the code
|
||||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ jobs:
|
|||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
name: Run on Ubuntu
|
name: Run on Ubuntu
|
||||||
runs-on: self-hosted
|
runs-on: [self-hosted, vm]
|
||||||
steps:
|
steps:
|
||||||
- name: Clone the code
|
- name: Clone the code
|
||||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ jobs:
|
|||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
name: Run on Ubuntu
|
name: Run on Ubuntu
|
||||||
runs-on: self-hosted
|
runs-on: [self-hosted, pod]
|
||||||
steps:
|
steps:
|
||||||
- name: Clone the code
|
- name: Clone the code
|
||||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||||
|
|||||||
@@ -0,0 +1,84 @@
|
|||||||
|
/*
|
||||||
|
Copyright 2026.
|
||||||
|
|
||||||
|
Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
|
you may not use this file except in compliance with the License.
|
||||||
|
You may obtain a copy of the License at
|
||||||
|
|
||||||
|
http://www.apache.org/licenses/LICENSE-2.0
|
||||||
|
|
||||||
|
Unless required by applicable law or agreed to in writing, software
|
||||||
|
distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
|
See the License for the specific language governing permissions and
|
||||||
|
limitations under the License.
|
||||||
|
*/
|
||||||
|
|
||||||
|
package instance
|
||||||
|
|
||||||
|
import "slices"
|
||||||
|
|
||||||
|
// ExtensionSet is an immutable set of exact names. Zero represents the empty set.
|
||||||
|
// It does not impose identifier syntax or claim that a server supports any name.
|
||||||
|
type ExtensionSet struct {
|
||||||
|
names []string
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewExtensionSet(names []string) ExtensionSet {
|
||||||
|
copied := slices.Clone(names)
|
||||||
|
slices.Sort(copied)
|
||||||
|
return ExtensionSet{names: slices.Compact(copied)}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Names returns a sorted, deduplicated copy.
|
||||||
|
func (s ExtensionSet) Names() []string { return slices.Clone(s.names) }
|
||||||
|
|
||||||
|
type ExtensionDecision string
|
||||||
|
|
||||||
|
const (
|
||||||
|
ExtensionsAccepted ExtensionDecision = "Accepted"
|
||||||
|
ExtensionsUnsupported ExtensionDecision = "ExtensionsUnsupported"
|
||||||
|
ExtensionSupportUnobserved ExtensionDecision = "ExtensionSupportUnobserved"
|
||||||
|
)
|
||||||
|
|
||||||
|
// ExtensionCheck reports support only, not readiness or permission to install.
|
||||||
|
// Unsupported is a detached, sorted list and is populated only for known support.
|
||||||
|
type ExtensionCheck struct {
|
||||||
|
Decision ExtensionDecision
|
||||||
|
Unsupported []string
|
||||||
|
}
|
||||||
|
|
||||||
|
// ExtensionSupport is the extension-list component of an Instance observation.
|
||||||
|
// Zero means unobserved, not an observed empty list. Target/revision binding and
|
||||||
|
// invalidation belong to the containing Instance observation, not this set value.
|
||||||
|
type ExtensionSupport struct {
|
||||||
|
observed bool
|
||||||
|
available ExtensionSet
|
||||||
|
}
|
||||||
|
|
||||||
|
// ObserveExtensionSupport records a successfully read list, including an empty one.
|
||||||
|
// A failed query must not call this constructor with an empty list: the application
|
||||||
|
// must propagate the dependency failure and leave support unobserved.
|
||||||
|
func ObserveExtensionSupport(available []string) ExtensionSupport {
|
||||||
|
return ExtensionSupport{observed: true, available: NewExtensionSet(available)}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check performs no IO and cannot install or remove extensions.
|
||||||
|
func (s ExtensionSupport) Check(requested ExtensionSet) ExtensionCheck {
|
||||||
|
if len(requested.names) == 0 {
|
||||||
|
return ExtensionCheck{Decision: ExtensionsAccepted}
|
||||||
|
}
|
||||||
|
if !s.observed {
|
||||||
|
return ExtensionCheck{Decision: ExtensionSupportUnobserved}
|
||||||
|
}
|
||||||
|
var unsupported []string
|
||||||
|
for _, name := range requested.names {
|
||||||
|
if _, found := slices.BinarySearch(s.available.names, name); !found {
|
||||||
|
unsupported = append(unsupported, name)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if len(unsupported) != 0 {
|
||||||
|
return ExtensionCheck{Decision: ExtensionsUnsupported, Unsupported: unsupported}
|
||||||
|
}
|
||||||
|
return ExtensionCheck{Decision: ExtensionsAccepted}
|
||||||
|
}
|
||||||
@@ -0,0 +1,107 @@
|
|||||||
|
/*
|
||||||
|
Copyright 2026.
|
||||||
|
|
||||||
|
Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
|
you may not use this file except in compliance with the License.
|
||||||
|
You may obtain a copy of the License at
|
||||||
|
|
||||||
|
http://www.apache.org/licenses/LICENSE-2.0
|
||||||
|
|
||||||
|
Unless required by applicable law or agreed to in writing, software
|
||||||
|
distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
|
See the License for the specific language governing permissions and
|
||||||
|
limitations under the License.
|
||||||
|
*/
|
||||||
|
|
||||||
|
package instance_test
|
||||||
|
|
||||||
|
import (
|
||||||
|
"slices"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"git.ddupan.top/panxiao81/postgresql-tenant-operator/internal/domain/instance"
|
||||||
|
)
|
||||||
|
|
||||||
|
const (
|
||||||
|
testUUID = "uuid-ossp"
|
||||||
|
testTrigram = "pg_trgm"
|
||||||
|
testVector = "vector"
|
||||||
|
testChanged = "changed"
|
||||||
|
)
|
||||||
|
|
||||||
|
// Acceptance: docs/domain-instance.md, extension support is based on observations,
|
||||||
|
// not a name regexp or an administrator allowlist.
|
||||||
|
func TestExtensionSupportDecisions(t *testing.T) {
|
||||||
|
available := instance.ObserveExtensionSupport([]string{testTrigram, testUUID})
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
support instance.ExtensionSupport
|
||||||
|
requested []string
|
||||||
|
want instance.ExtensionDecision
|
||||||
|
unsupported []string
|
||||||
|
}{
|
||||||
|
{"unobserved", instance.ExtensionSupport{}, []string{testTrigram}, instance.ExtensionSupportUnobserved, nil},
|
||||||
|
{"observed empty", instance.ObserveExtensionSupport(nil), []string{testTrigram}, instance.ExtensionsUnsupported, []string{testTrigram}},
|
||||||
|
{"empty request", instance.ExtensionSupport{}, nil, instance.ExtensionsAccepted, nil},
|
||||||
|
{"supported", available, []string{testUUID, testTrigram, testTrigram}, instance.ExtensionsAccepted, nil},
|
||||||
|
{"unsupported", available, []string{testVector, "hstore", testVector, testTrigram},
|
||||||
|
instance.ExtensionsUnsupported, []string{"hstore", testVector}},
|
||||||
|
{"exact names", available, []string{"PG_TRGM"}, instance.ExtensionsUnsupported, []string{"PG_TRGM"}},
|
||||||
|
}
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
result := tc.support.Check(instance.NewExtensionSet(tc.requested))
|
||||||
|
if result.Decision != tc.want || !slices.Equal(result.Unsupported, tc.unsupported) {
|
||||||
|
t.Fatalf("Check() = %v, want %v / %v", result, tc.want, tc.unsupported)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestExtensionSetCopiesAndCanonicalizesNames(t *testing.T) {
|
||||||
|
input := []string{testUUID, testTrigram, testUUID}
|
||||||
|
set := instance.NewExtensionSet(input)
|
||||||
|
input[0] = testChanged
|
||||||
|
names := set.Names()
|
||||||
|
want := []string{testTrigram, testUUID}
|
||||||
|
if !slices.Equal(names, want) {
|
||||||
|
t.Fatalf("Names() = %v, want %v", names, want)
|
||||||
|
}
|
||||||
|
names[0] = testChanged
|
||||||
|
if !slices.Equal(set.Names(), want) {
|
||||||
|
t.Fatal("returned slice mutated set")
|
||||||
|
}
|
||||||
|
if len((instance.ExtensionSet{}).Names()) != 0 {
|
||||||
|
t.Fatal("zero set must be empty")
|
||||||
|
}
|
||||||
|
// Names are preserved exactly; actual server support, not a local regexp, is decisive.
|
||||||
|
unusual := []string{"Vendor.Extension", testUUID}
|
||||||
|
if result := instance.ObserveExtensionSupport(unusual).Check(instance.NewExtensionSet(unusual)); result.Decision != instance.ExtensionsAccepted {
|
||||||
|
t.Fatal("imposed a local name restriction")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestExtensionSupportCopiesObservationAndResults(t *testing.T) {
|
||||||
|
input := []string{testTrigram}
|
||||||
|
support := instance.ObserveExtensionSupport(input)
|
||||||
|
input[0] = testVector
|
||||||
|
requested := instance.NewExtensionSet([]string{testTrigram, testVector})
|
||||||
|
result := support.Check(requested)
|
||||||
|
if !slices.Equal(result.Unsupported, []string{testVector}) {
|
||||||
|
t.Fatal("input mutation changed observation")
|
||||||
|
}
|
||||||
|
result.Unsupported[0] = testChanged
|
||||||
|
again := support.Check(requested)
|
||||||
|
if !slices.Equal(again.Unsupported, []string{testVector}) {
|
||||||
|
t.Fatal("result mutation changed subsequent decision")
|
||||||
|
}
|
||||||
|
// Replacing an observation does not mutate the old value or produce uninstall actions.
|
||||||
|
empty := instance.ObserveExtensionSupport(nil)
|
||||||
|
if empty.Check(requested).Decision != instance.ExtensionsUnsupported {
|
||||||
|
t.Fatal("empty observation ignored")
|
||||||
|
}
|
||||||
|
if support.Check(instance.NewExtensionSet([]string{testTrigram})).Decision != instance.ExtensionsAccepted {
|
||||||
|
t.Fatal("new observation mutated old value")
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,101 @@
|
|||||||
|
/*
|
||||||
|
Copyright 2026.
|
||||||
|
|
||||||
|
Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
|
you may not use this file except in compliance with the License.
|
||||||
|
You may obtain a copy of the License at
|
||||||
|
|
||||||
|
http://www.apache.org/licenses/LICENSE-2.0
|
||||||
|
|
||||||
|
Unless required by applicable law or agreed to in writing, software
|
||||||
|
distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
|
See the License for the specific language governing permissions and
|
||||||
|
limitations under the License.
|
||||||
|
*/
|
||||||
|
|
||||||
|
package instance
|
||||||
|
|
||||||
|
import "errors"
|
||||||
|
|
||||||
|
// Phase is a workflow checkpoint, never evidence of external resource state.
|
||||||
|
type Phase string
|
||||||
|
|
||||||
|
const (
|
||||||
|
PhasePending Phase = "Pending"
|
||||||
|
PhaseValidating Phase = "Validating"
|
||||||
|
PhaseInitializingRegistry Phase = "InitializingRegistry"
|
||||||
|
PhaseReady Phase = "Ready"
|
||||||
|
PhaseDeleting Phase = "Deleting"
|
||||||
|
)
|
||||||
|
|
||||||
|
type Readiness string
|
||||||
|
|
||||||
|
const (
|
||||||
|
Unknown Readiness = "Unknown"
|
||||||
|
Ready Readiness = "Ready"
|
||||||
|
NotReady Readiness = "NotReady"
|
||||||
|
)
|
||||||
|
|
||||||
|
// Snapshot contains persisted observations only, without credentials or live evidence.
|
||||||
|
// Failure detail mapping will be added with capability assessment, not intent transitions.
|
||||||
|
type Snapshot struct {
|
||||||
|
Phase Phase
|
||||||
|
ObservedRevision int64
|
||||||
|
Readiness Readiness
|
||||||
|
ReportedVersion string
|
||||||
|
}
|
||||||
|
|
||||||
|
// Instance protects registration state and pure lifecycle transitions.
|
||||||
|
// Reconstitution does not establish live capability evidence, even for a Ready snapshot.
|
||||||
|
// This initial slice deliberately exposes no operation that authorizes provisioning.
|
||||||
|
type Instance struct {
|
||||||
|
target ObservationTarget
|
||||||
|
snapshot Snapshot
|
||||||
|
deleting bool
|
||||||
|
}
|
||||||
|
|
||||||
|
func Reconstitute(target ObservationTarget, snapshot Snapshot, deleting bool) (*Instance, error) {
|
||||||
|
if err := target.Validate(); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
switch snapshot.Phase {
|
||||||
|
case PhasePending, PhaseValidating, PhaseInitializingRegistry, PhaseReady, PhaseDeleting:
|
||||||
|
default:
|
||||||
|
snapshot.Phase = PhasePending
|
||||||
|
snapshot.Readiness = Unknown
|
||||||
|
}
|
||||||
|
return &Instance{target: target, snapshot: snapshot, deleting: deleting}, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (i *Instance) Target() ObservationTarget { return i.target }
|
||||||
|
|
||||||
|
// Snapshot returns a detached value. Persisting it remains the application's job.
|
||||||
|
func (i *Instance) Snapshot() Snapshot { return i.snapshot }
|
||||||
|
|
||||||
|
// BeginValidation records intent only; it does not claim a concluded observation.
|
||||||
|
func (i *Instance) BeginValidation() error {
|
||||||
|
if err := i.target.Validate(); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if i.deleting {
|
||||||
|
return errors.New("cannot begin validation after deletion was requested")
|
||||||
|
}
|
||||||
|
i.snapshot.Phase = PhaseValidating
|
||||||
|
i.snapshot.Readiness = Unknown
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// BeginDeletion stops the lifecycle from accepting validation. It does not delete
|
||||||
|
// resources, inspect Tenant references, close connections or modify finalizers.
|
||||||
|
func (i *Instance) BeginDeletion() error {
|
||||||
|
if err := i.target.Validate(); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if !i.deleting {
|
||||||
|
return errors.New("cannot begin deletion without a deletion request")
|
||||||
|
}
|
||||||
|
i.snapshot.Phase = PhaseDeleting
|
||||||
|
i.snapshot.Readiness = Unknown
|
||||||
|
return nil
|
||||||
|
}
|
||||||
@@ -0,0 +1,134 @@
|
|||||||
|
/*
|
||||||
|
Copyright 2026.
|
||||||
|
|
||||||
|
Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
|
you may not use this file except in compliance with the License.
|
||||||
|
You may obtain a copy of the License at
|
||||||
|
|
||||||
|
http://www.apache.org/licenses/LICENSE-2.0
|
||||||
|
|
||||||
|
Unless required by applicable law or agreed to in writing, software
|
||||||
|
distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
|
See the License for the specific language governing permissions and
|
||||||
|
limitations under the License.
|
||||||
|
*/
|
||||||
|
|
||||||
|
package instance_test
|
||||||
|
|
||||||
|
import (
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"git.ddupan.top/panxiao81/postgresql-tenant-operator/internal/domain/instance"
|
||||||
|
)
|
||||||
|
|
||||||
|
func lifecycleInstance(t *testing.T, snapshot instance.Snapshot, deleting bool) *instance.Instance {
|
||||||
|
t.Helper()
|
||||||
|
identity, revision, definition := targetParts(t)
|
||||||
|
target, err := instance.NewObservationTarget(identity, revision, definition)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
value, err := instance.Reconstitute(target, snapshot, deleting)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
return value
|
||||||
|
}
|
||||||
|
|
||||||
|
// Acceptance: docs/domain-instance.md §3, checkpoint reconstruction and intent-only transitions.
|
||||||
|
func TestReconstituteCheckpoints(t *testing.T) {
|
||||||
|
for _, phase := range []instance.Phase{
|
||||||
|
instance.PhasePending, instance.PhaseValidating, instance.PhaseInitializingRegistry,
|
||||||
|
instance.PhaseReady, instance.PhaseDeleting,
|
||||||
|
} {
|
||||||
|
snapshot := instance.Snapshot{Phase: phase, ObservedRevision: 1, Readiness: instance.Ready, ReportedVersion: "17"}
|
||||||
|
value := lifecycleInstance(t, snapshot, false)
|
||||||
|
if value.Snapshot() != snapshot {
|
||||||
|
t.Fatal("known checkpoint was not preserved")
|
||||||
|
}
|
||||||
|
// A snapshot is detached; it is not a setter on the aggregate.
|
||||||
|
copy := value.Snapshot()
|
||||||
|
copy.Phase = instance.PhasePending
|
||||||
|
copy.ReportedVersion = "changed"
|
||||||
|
if value.Snapshot() != snapshot {
|
||||||
|
t.Fatal("snapshot mutation changed aggregate")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
for _, phase := range []instance.Phase{"", "unknown"} {
|
||||||
|
value := lifecycleInstance(t, instance.Snapshot{Phase: phase, Readiness: instance.Ready}, false)
|
||||||
|
if value.Snapshot().Phase != instance.PhasePending || value.Snapshot().Readiness != instance.Unknown {
|
||||||
|
t.Fatal("missing or unknown checkpoint did not restart conservatively")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if value, err := instance.Reconstitute(instance.ObservationTarget{}, instance.Snapshot{}, false); err == nil || value != nil {
|
||||||
|
t.Fatal("invalid target reconstructed an aggregate")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestBeginValidationPreservesObservedRevision(t *testing.T) {
|
||||||
|
snapshot := instance.Snapshot{
|
||||||
|
Phase: instance.PhaseReady, ObservedRevision: 0, Readiness: instance.Ready, ReportedVersion: "17",
|
||||||
|
}
|
||||||
|
value := lifecycleInstance(t, snapshot, false)
|
||||||
|
target := value.Target()
|
||||||
|
for range 2 {
|
||||||
|
if err := value.BeginValidation(); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
got := value.Snapshot()
|
||||||
|
if got.Phase != instance.PhaseValidating || got.Readiness != instance.Unknown ||
|
||||||
|
got.ObservedRevision != snapshot.ObservedRevision || got.ReportedVersion != snapshot.ReportedVersion {
|
||||||
|
t.Fatal("recording validation intent claimed a completed observation or erased diagnostic version")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if value.Target() != target {
|
||||||
|
t.Fatal("lifecycle action mutated identity or configuration")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDeletionRequiresRequestAndPreventsValidation(t *testing.T) {
|
||||||
|
snapshot := instance.Snapshot{Phase: instance.PhaseReady, Readiness: instance.Ready, ObservedRevision: 1}
|
||||||
|
active := lifecycleInstance(t, snapshot, false)
|
||||||
|
if err := active.BeginDeletion(); err == nil {
|
||||||
|
t.Fatal("deletion without a request accepted")
|
||||||
|
}
|
||||||
|
if active.Snapshot() != snapshot {
|
||||||
|
t.Fatal("rejected deletion mutated state")
|
||||||
|
}
|
||||||
|
for _, phase := range []instance.Phase{
|
||||||
|
instance.PhasePending, instance.PhaseValidating, instance.PhaseInitializingRegistry,
|
||||||
|
instance.PhaseReady, instance.PhaseDeleting,
|
||||||
|
} {
|
||||||
|
snapshot.Phase = phase
|
||||||
|
value := lifecycleInstance(t, snapshot, true)
|
||||||
|
if err := value.BeginValidation(); err == nil {
|
||||||
|
t.Fatal("validation accepted after deletion request")
|
||||||
|
}
|
||||||
|
if value.Snapshot() != snapshot {
|
||||||
|
t.Fatal("rejected validation mutated state")
|
||||||
|
}
|
||||||
|
for range 2 {
|
||||||
|
if err := value.BeginDeletion(); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if got := value.Snapshot(); got.Phase != instance.PhaseDeleting || got.Readiness != instance.Unknown ||
|
||||||
|
got.ObservedRevision != snapshot.ObservedRevision {
|
||||||
|
t.Fatal("incorrect deletion checkpoint")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestZeroInstanceCannotTransition(t *testing.T) {
|
||||||
|
var value instance.Instance
|
||||||
|
if err := value.BeginValidation(); err == nil {
|
||||||
|
t.Fatal("zero instance started validation")
|
||||||
|
}
|
||||||
|
if err := value.BeginDeletion(); err == nil {
|
||||||
|
t.Fatal("zero instance started deletion")
|
||||||
|
}
|
||||||
|
if value.Snapshot() != (instance.Snapshot{}) {
|
||||||
|
t.Fatal("invalid transition changed zero instance")
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,81 @@
|
|||||||
|
/*
|
||||||
|
Copyright 2026.
|
||||||
|
|
||||||
|
Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
|
you may not use this file except in compliance with the License.
|
||||||
|
You may obtain a copy of the License at
|
||||||
|
|
||||||
|
http://www.apache.org/licenses/LICENSE-2.0
|
||||||
|
|
||||||
|
Unless required by applicable law or agreed to in writing, software
|
||||||
|
distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
|
See the License for the specific language governing permissions and
|
||||||
|
limitations under the License.
|
||||||
|
*/
|
||||||
|
|
||||||
|
package instance
|
||||||
|
|
||||||
|
// Definition is the immutable effective configuration of an Instance.
|
||||||
|
// Available extensions are observations, not part of the declared configuration.
|
||||||
|
type Definition struct {
|
||||||
|
endpoint Endpoint
|
||||||
|
adminCredential CredentialReference
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewDefinition(endpoint Endpoint, adminCredential CredentialReference) (Definition, error) {
|
||||||
|
definition := Definition{endpoint: endpoint, adminCredential: adminCredential}
|
||||||
|
if err := definition.Validate(); err != nil {
|
||||||
|
return Definition{}, err
|
||||||
|
}
|
||||||
|
return definition, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (d Definition) Endpoint() Endpoint { return d.endpoint }
|
||||||
|
func (d Definition) AdminCredential() CredentialReference { return d.adminCredential }
|
||||||
|
|
||||||
|
// Validate rejects invalid zero-value components even when constructors were bypassed.
|
||||||
|
func (d Definition) Validate() error {
|
||||||
|
if err := d.endpoint.Validate(); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
return d.adminCredential.Validate()
|
||||||
|
}
|
||||||
|
|
||||||
|
// ObservationTarget binds facts to a registration and its declared configuration.
|
||||||
|
// It does not identify a physical PostgreSQL server or prove observation freshness.
|
||||||
|
// Secret content refresh and same-target observation freshness remain application
|
||||||
|
// responsibilities; no credentials or Secret contents are carried by this value.
|
||||||
|
type ObservationTarget struct {
|
||||||
|
identity Identity
|
||||||
|
revision Revision
|
||||||
|
definition Definition
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewObservationTarget(identity Identity, revision Revision, definition Definition) (ObservationTarget, error) {
|
||||||
|
target := ObservationTarget{identity: identity, revision: revision, definition: definition}
|
||||||
|
if err := target.Validate(); err != nil {
|
||||||
|
return ObservationTarget{}, err
|
||||||
|
}
|
||||||
|
return target, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t ObservationTarget) Identity() Identity { return t.identity }
|
||||||
|
func (t ObservationTarget) Revision() Revision { return t.revision }
|
||||||
|
func (t ObservationTarget) Definition() Definition { return t.definition }
|
||||||
|
|
||||||
|
func (t ObservationTarget) Validate() error {
|
||||||
|
if err := t.identity.Validate(); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if err := t.revision.Validate(); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
return t.definition.Validate()
|
||||||
|
}
|
||||||
|
|
||||||
|
// Matches rejects invalid targets before comparing values. Matching is necessary,
|
||||||
|
// but not sufficient, for the aggregate to accept a fresh capability observation.
|
||||||
|
func (t ObservationTarget) Matches(other ObservationTarget) bool {
|
||||||
|
return t.Validate() == nil && other.Validate() == nil && t == other
|
||||||
|
}
|
||||||
@@ -0,0 +1,165 @@
|
|||||||
|
/*
|
||||||
|
Copyright 2026.
|
||||||
|
|
||||||
|
Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
|
you may not use this file except in compliance with the License.
|
||||||
|
You may obtain a copy of the License at
|
||||||
|
|
||||||
|
http://www.apache.org/licenses/LICENSE-2.0
|
||||||
|
|
||||||
|
Unless required by applicable law or agreed to in writing, software
|
||||||
|
distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
|
See the License for the specific language governing permissions and
|
||||||
|
limitations under the License.
|
||||||
|
*/
|
||||||
|
|
||||||
|
package instance_test
|
||||||
|
|
||||||
|
import (
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"git.ddupan.top/panxiao81/postgresql-tenant-operator/internal/domain/instance"
|
||||||
|
)
|
||||||
|
|
||||||
|
func targetParts(t *testing.T) (instance.Identity, instance.Revision, instance.Definition) {
|
||||||
|
t.Helper()
|
||||||
|
identity, err := instance.NewIdentity("uid-1", "shared")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
revision, err := instance.NewRevision(1)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
endpoint, err := instance.NewEndpoint(validEndpoint())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
credential, err := instance.NewCredentialReference(validCredentialReference())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
definition, err := instance.NewDefinition(endpoint, credential)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
return identity, revision, definition
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDefinitionRejectsInvalidComponents(t *testing.T) {
|
||||||
|
_, _, definition := targetParts(t)
|
||||||
|
cases := []struct {
|
||||||
|
endpoint instance.Endpoint
|
||||||
|
credential instance.CredentialReference
|
||||||
|
}{
|
||||||
|
{instance.Endpoint{}, definition.AdminCredential()},
|
||||||
|
{definition.Endpoint(), instance.CredentialReference{}},
|
||||||
|
}
|
||||||
|
for _, tc := range cases {
|
||||||
|
value, err := instance.NewDefinition(tc.endpoint, tc.credential)
|
||||||
|
if err == nil || value != (instance.Definition{}) {
|
||||||
|
t.Fatal("invalid component accepted or partial value returned")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if err := (instance.Definition{}).Validate(); err == nil {
|
||||||
|
t.Fatal("zero definition accepted")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestObservationTargetRejectsInvalidComponents(t *testing.T) {
|
||||||
|
identity, revision, definition := targetParts(t)
|
||||||
|
cases := []struct {
|
||||||
|
identity instance.Identity
|
||||||
|
revision instance.Revision
|
||||||
|
definition instance.Definition
|
||||||
|
}{
|
||||||
|
{instance.Identity{}, revision, definition},
|
||||||
|
{identity, instance.Revision{}, definition},
|
||||||
|
{identity, revision, instance.Definition{}},
|
||||||
|
}
|
||||||
|
for _, tc := range cases {
|
||||||
|
value, err := instance.NewObservationTarget(tc.identity, tc.revision, tc.definition)
|
||||||
|
if err == nil || value != (instance.ObservationTarget{}) {
|
||||||
|
t.Fatal("invalid component accepted or partial target returned")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
zero := instance.ObservationTarget{}
|
||||||
|
if err := zero.Validate(); err == nil {
|
||||||
|
t.Fatal("zero target accepted")
|
||||||
|
}
|
||||||
|
if zero.Matches(zero) {
|
||||||
|
t.Fatal("two invalid targets must not authorize observation reuse")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Acceptance: docs/domain-instance.md §2/§6, observations cannot cross target bindings.
|
||||||
|
func TestObservationTargetMatchesOnlySameBinding(t *testing.T) {
|
||||||
|
identity, revision, definition := targetParts(t)
|
||||||
|
original, err := instance.NewObservationTarget(identity, revision, definition)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
same, err := instance.NewObservationTarget(identity, revision, definition)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if !original.Matches(same) || original.Identity() != identity ||
|
||||||
|
original.Revision() != revision || original.Definition() != definition {
|
||||||
|
t.Fatal("target did not preserve its declared binding")
|
||||||
|
}
|
||||||
|
changedIdentity, err := instance.NewIdentity("uid-2", identity.Name())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
changedRevision, err := instance.NewRevision(2)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
for _, parts := range []struct {
|
||||||
|
identity instance.Identity
|
||||||
|
revision instance.Revision
|
||||||
|
}{{changedIdentity, revision}, {identity, changedRevision}} {
|
||||||
|
changed, err := instance.NewObservationTarget(parts.identity, parts.revision, definition)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if original.Matches(changed) || changed.Matches(original) {
|
||||||
|
t.Fatal("different registration or revision matched")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
endpointValues := definition.Endpoint().Values()
|
||||||
|
endpointValues.Host = "other.example"
|
||||||
|
endpoint, err := instance.NewEndpoint(endpointValues)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
credentialValues := definition.AdminCredential().Values()
|
||||||
|
credentialValues.PasswordKey = "replacement"
|
||||||
|
credential, err := instance.NewCredentialReference(credentialValues)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
for _, components := range []struct {
|
||||||
|
endpoint instance.Endpoint
|
||||||
|
credential instance.CredentialReference
|
||||||
|
}{{endpoint, definition.AdminCredential()}, {definition.Endpoint(), credential}} {
|
||||||
|
changedDefinition, err := instance.NewDefinition(components.endpoint, components.credential)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
changed, err := instance.NewObservationTarget(identity, revision, changedDefinition)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if original.Matches(changed) {
|
||||||
|
t.Fatal("changed definition matched even with the same revision")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if original.Matches(instance.ObservationTarget{}) {
|
||||||
|
t.Fatal("valid target matched zero target")
|
||||||
|
}
|
||||||
|
if !original.Matches(same) {
|
||||||
|
t.Fatal("constructing changed targets mutated the original")
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user