Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6a708965e4 | ||
|
|
bb450e5d8c | ||
|
|
206d2ab14b | ||
|
|
78b4730687 | ||
|
|
3941ff4950 |
No files matched your search
@@ -11,7 +11,7 @@ repos:
|
||||
- --allow-multiple-documents
|
||||
- id: check-added-large-files
|
||||
- repo: https://github.com/alessandrojcm/commitlint-pre-commit-hook
|
||||
rev: v9.26.0
|
||||
rev: v9.27.0
|
||||
hooks:
|
||||
- id: commitlint
|
||||
stages: [ commit-msg ]
|
||||
@@ -30,7 +30,7 @@ repos:
|
||||
- id: go-test
|
||||
- id: gofumpt
|
||||
- repo: https://github.com/golangci/golangci-lint
|
||||
rev: v2.13.2
|
||||
rev: v2.14.0
|
||||
hooks:
|
||||
- id: golangci-lint-full
|
||||
- repo: https://github.com/gitleaks/gitleaks
|
||||
|
||||
@@ -46,6 +46,6 @@ Registers per-replica (transient) go-messaging-amqp consumers for privilege even
|
||||
|
||||
### Startup
|
||||
|
||||
Call `Fetch()` **after** `conn.Start` (consumers bound), never before: events published between the snapshot and the binding would otherwise be lost. authz-service only serves a snapshot whose read view has applied every stored event. It sends that position in the `X-Authz-Sequence` header and answers 503 while the read view lags (backlog, backfill, reset); `Fetch` retries 503 for about a minute. `Fetch` merges the snapshot as facts at that sequence number (newer event facts win, pairs missing from the snapshot are removed) and drops later events at or below it. A snapshot older than one already merged is ignored, so concurrent or repeated fetches are safe. A snapshot without the header merges at 0 and logs a warning (rollout window only).
|
||||
Call `Fetch()` **after** `conn.Start` (consumers bound), never before: events published between the snapshot and the binding would otherwise be lost. authz-service only serves a snapshot whose read view has applied every stored event. It sends that position in the `X-Authz-Sequence` header and answers 503 while the read view lags (backlog, backfill, reset); `Fetch` retries 503 for about a minute. `Fetch` merges the snapshot as facts at that sequence number (newer event facts win, pairs missing from the snapshot are removed) and drops later events at or below it. A snapshot older than one already merged is ignored, so concurrent or repeated fetches are safe. A snapshot without the header merges at 0 and logs a warning (rollout window only). When the `/authz` contract changes, deploy authz-service before the services that use this library.
|
||||
|
||||
Don't combine `Setup()` with go-messaging-amqp's `WithReconnect`: a reconnect declares new per-replica queues, so revocations published during the outage are lost unless `Fetch()` runs again. Services exit on connection loss (`CloseListener`) and re-fetch on start.
|
||||
@@ -3,7 +3,7 @@ module gitea.unbound.se/shiny/authz_client
|
||||
go 1.26.2
|
||||
|
||||
require (
|
||||
codeberg.org/messaging/go-messaging-amqp v0.0.5
|
||||
codeberg.org/messaging/go-messaging-amqp v0.0.6
|
||||
codeberg.org/messaging/messaging v0.0.5
|
||||
github.com/stretchr/testify v1.12.1
|
||||
)
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
codeberg.org/messaging/go-messaging-amqp v0.0.5 h1:zzcJ+FVWgBPKyTkq9RXF11yvnhs8IN5BALBC+mps1zA=
|
||||
codeberg.org/messaging/go-messaging-amqp v0.0.5/go.mod h1:6bSCIkKH0V/oI7vaIq8ttINKYwov9c8ckZrwjfvp7kc=
|
||||
codeberg.org/messaging/go-messaging-amqp v0.0.6 h1:TAPcIspjjg44MNXwbcscW+ol1kIX49lnX2N3dsh0e0s=
|
||||
codeberg.org/messaging/go-messaging-amqp v0.0.6/go.mod h1:R4Hg1w964P7OP7vQ9AsXdd4KjgN/YlQ/9+XzXKpEVp4=
|
||||
codeberg.org/messaging/messaging v0.0.5 h1:/ueH90F4RNPUeeJIwdG9oVhDW7+XjCzwOYq8xc0kfQk=
|
||||
codeberg.org/messaging/messaging v0.0.5/go.mod h1:xyWLUcfaVzcN6GWk9uaQsxPVUC2Vm2S89mYZGdiWTWg=
|
||||
codeberg.org/messaging/messaging/tck v0.0.3 h1:a4Nr7ytFqEJloTOyVeAtMNgO9Fig1ZUirjW4FVlK0lc=
|
||||
|
||||
@@ -2,5 +2,15 @@
|
||||
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
||||
"extends": [
|
||||
"config:recommended"
|
||||
],
|
||||
"packageRules": [
|
||||
{
|
||||
"groupName": "OpenTelemetry",
|
||||
"matchPackageNames": [
|
||||
"go.opentelemetry.io/**",
|
||||
"gitea.unbound.se/shiny/otelsetup",
|
||||
"gitea.unbound.se/shiny/logging"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
Reference in new issue
Block a user