refactor: remove legacy workspace runtime branches
This commit is contained in:
@@ -1,15 +1,12 @@
|
||||
import { constants, realpathSync, statSync, accessSync } from "node:fs";
|
||||
import { isAbsolute, relative } from "node:path";
|
||||
import { buildInstallationContract, type InstallationRole, type InstallationSuffix } from "./contracts.js";
|
||||
import { buildInstallationContract, type InstallationSuffix } from "./contracts.js";
|
||||
import {
|
||||
DWH_TRANSPORTS,
|
||||
VECTOR_TRANSPORTS,
|
||||
validateWorkspaceDescriptor,
|
||||
type DwhTransport,
|
||||
type VectorTransport,
|
||||
type WorkspaceDescriptor,
|
||||
} from "./schema.js";
|
||||
import type { DeprecatedV2Descriptor } from "./deprecated-v2-descriptor.js";
|
||||
|
||||
export interface ResolvedEvidenceBinding {
|
||||
values: Record<string, string>;
|
||||
@@ -18,42 +15,26 @@ export interface ResolvedEvidenceBinding {
|
||||
|
||||
export interface RuntimeBindings {
|
||||
dwh: ResolvedBinding;
|
||||
vector: ResolvedBinding;
|
||||
vectorWriter: ResolvedBinding;
|
||||
embedding: ResolvedBinding;
|
||||
evidence: ResolvedEvidenceBinding;
|
||||
}
|
||||
|
||||
export interface ResolvedBinding {
|
||||
transport: DwhTransport | VectorTransport;
|
||||
transport: DwhTransport;
|
||||
values: Record<string, string>;
|
||||
missing: string[];
|
||||
}
|
||||
|
||||
const REQUIRED_SUFFIXES: Record<"DWH" | "VECTOR", Record<string, readonly InstallationSuffix[]>> = {
|
||||
DWH: {
|
||||
postgres_direct: ["HOST", "PORT", "USER", "PASSWORD_FILE"],
|
||||
rest_api: ["BASE_URL", "API_KEY_FILE"],
|
||||
ssh_tunnel: [
|
||||
"USER", "PASSWORD_FILE", "SSH_HOST", "SSH_PORT", "SSH_USER",
|
||||
"SSH_PRIVATE_KEY_FILE", "SSH_KNOWN_HOSTS_FILE", "SSH_TARGET_HOST", "SSH_TARGET_PORT",
|
||||
],
|
||||
},
|
||||
VECTOR: {
|
||||
pgvector_direct: ["HOST", "PORT", "USER", "PASSWORD_FILE"],
|
||||
rest_api: ["BASE_URL", "API_KEY_FILE"],
|
||||
ssh_tunnel: [
|
||||
"USER", "PASSWORD_FILE", "SSH_HOST", "SSH_PORT", "SSH_USER",
|
||||
"SSH_PRIVATE_KEY_FILE", "SSH_KNOWN_HOSTS_FILE", "SSH_TARGET_HOST", "SSH_TARGET_PORT",
|
||||
],
|
||||
},
|
||||
const REQUIRED_SUFFIXES: Record<DwhTransport, readonly InstallationSuffix[]> = {
|
||||
postgres_direct: ["HOST", "PORT", "USER", "PASSWORD_FILE"],
|
||||
rest_api: ["BASE_URL", "API_KEY_FILE"],
|
||||
ssh_tunnel: [
|
||||
"USER", "PASSWORD_FILE", "SSH_HOST", "SSH_PORT", "SSH_USER",
|
||||
"SSH_PRIVATE_KEY_FILE", "SSH_KNOWN_HOSTS_FILE", "SSH_TARGET_HOST", "SSH_TARGET_PORT",
|
||||
],
|
||||
};
|
||||
|
||||
const EMBEDDING_REQUIRED_SUFFIXES: readonly InstallationSuffix[] = ["BASE_URL"];
|
||||
|
||||
function isTransport(value: string | undefined): value is DwhTransport | VectorTransport {
|
||||
return value !== undefined
|
||||
&& ([...DWH_TRANSPORTS, ...VECTOR_TRANSPORTS] as readonly string[]).includes(value);
|
||||
function isTransport(value: string | undefined): value is DwhTransport {
|
||||
return value !== undefined && (DWH_TRANSPORTS as readonly string[]).includes(value);
|
||||
}
|
||||
|
||||
function isInside(path: string, root: string): boolean {
|
||||
@@ -76,18 +57,23 @@ function safeSecretFilePath(path: string, secretRoots: readonly string[]): strin
|
||||
}
|
||||
}
|
||||
|
||||
function requireSupportedDescriptor(workspace: unknown): void {
|
||||
if (typeof workspace !== "object" || workspace === null) {
|
||||
throw new Error("Workspace bindings support only workspace schema version 3");
|
||||
}
|
||||
const metadata = Reflect.get(workspace, "workspace");
|
||||
if (typeof metadata !== "object" || metadata === null
|
||||
|| Reflect.get(metadata, "schema_version") !== 3) {
|
||||
throw new Error("Workspace bindings support only workspace schema version 3");
|
||||
}
|
||||
}
|
||||
|
||||
function requiredSuffixes(
|
||||
workspace: WorkspaceDescriptor,
|
||||
role: Exclude<InstallationRole, "EVIDENCE">,
|
||||
transport: DwhTransport | VectorTransport,
|
||||
transport: DwhTransport,
|
||||
): readonly InstallationSuffix[] {
|
||||
if (role === "EMBEDDING") return EMBEDDING_REQUIRED_SUFFIXES;
|
||||
if (role === "VECTOR_WRITER") return ["API_KEY_FILE"];
|
||||
const required = REQUIRED_SUFFIXES[role][transport] ?? [];
|
||||
const diagnostic = role === "DWH"
|
||||
? workspace.diagnostics?.dwh_rest
|
||||
: (workspace as unknown as DeprecatedV2Descriptor).diagnostics?.vector_rest?.metadata;
|
||||
return transport === "rest_api" && diagnostic?.auth === "none"
|
||||
const required = REQUIRED_SUFFIXES[transport];
|
||||
return transport === "rest_api" && workspace.diagnostics?.dwh_rest?.auth === "none"
|
||||
? required.filter((suffix) => suffix !== "API_KEY_FILE")
|
||||
: required;
|
||||
}
|
||||
@@ -98,37 +84,29 @@ function requiredSuffixes(
|
||||
*/
|
||||
export function resolveBinding(
|
||||
workspace: WorkspaceDescriptor,
|
||||
role: Exclude<InstallationRole, "EVIDENCE">,
|
||||
role: "DWH",
|
||||
env: NodeJS.ProcessEnv,
|
||||
secretRoots: readonly string[],
|
||||
): ResolvedBinding {
|
||||
requireSupportedDescriptor(workspace);
|
||||
const descriptor = validateWorkspaceDescriptor(workspace);
|
||||
if (descriptor.workspace.schema_version === 3 && role !== "DWH") {
|
||||
return { transport: "rest_api", values: {}, missing: [] };
|
||||
}
|
||||
|
||||
const contract = buildInstallationContract(descriptor);
|
||||
const legacy = descriptor as unknown as DeprecatedV2Descriptor;
|
||||
const variables = contract.variables.filter((variable) => variable.role === role);
|
||||
const transportVariable = variables.find((variable) => variable.suffix === "TRANSPORT");
|
||||
const supported = role === "DWH"
|
||||
? descriptor.dwh.supported_transports
|
||||
: role === "VECTOR"
|
||||
? legacy.semantic_index.vector_store.supported_transports
|
||||
: ["rest_api"] as const;
|
||||
const supported = descriptor.dwh.supported_transports;
|
||||
const selectedValue = transportVariable ? env[transportVariable.name] : undefined;
|
||||
const selectedTransport = isTransport(selectedValue) ? selectedValue : supported[0];
|
||||
const missing: string[] = [];
|
||||
|
||||
if (transportVariable && (!isTransport(selectedValue) || !supported.includes(selectedTransport as never))) {
|
||||
if (transportVariable && (!isTransport(selectedValue) || !supported.includes(selectedTransport))) {
|
||||
missing.push(transportVariable.name);
|
||||
}
|
||||
|
||||
const required = new Set(requiredSuffixes(descriptor, role, selectedTransport));
|
||||
const required = new Set(requiredSuffixes(descriptor, selectedTransport));
|
||||
const values: Record<string, string> = {};
|
||||
for (const variable of variables) {
|
||||
if (variable.suffix === "TRANSPORT") continue;
|
||||
if (variable.transports && !variable.transports.includes(selectedTransport as never)) continue;
|
||||
if (variable.transports && !variable.transports.includes(selectedTransport)) continue;
|
||||
|
||||
const value = env[variable.name];
|
||||
const present = value !== undefined && value.trim() !== "";
|
||||
@@ -149,12 +127,13 @@ export function resolveEvidenceBinding(
|
||||
env: NodeJS.ProcessEnv,
|
||||
secretRoots: readonly string[],
|
||||
): ResolvedEvidenceBinding {
|
||||
requireSupportedDescriptor(workspace);
|
||||
const descriptor = validateWorkspaceDescriptor(workspace);
|
||||
const variables = buildInstallationContract(descriptor).variables
|
||||
.filter((variable) => variable.role === "EVIDENCE");
|
||||
if (variables.length === 0) return { values: {}, missing: [] };
|
||||
|
||||
const source = "evidence" in descriptor ? descriptor.evidence?.source : undefined;
|
||||
const source = descriptor.evidence?.source;
|
||||
const required = new Set<InstallationSuffix>(
|
||||
source?.type === "http"
|
||||
? ["SIGNED_URLS_FILE"]
|
||||
@@ -176,29 +155,22 @@ export function resolveEvidenceBinding(
|
||||
return { values, missing };
|
||||
}
|
||||
|
||||
/** Resolve all runtime roles together so optional writer credentials cannot be smuggled into reader bindings. */
|
||||
/** Resolve the complete schema-v3 runtime binding set. */
|
||||
export function resolveRuntimeBindings(
|
||||
workspace: WorkspaceDescriptor,
|
||||
env: NodeJS.ProcessEnv,
|
||||
secretRoots: readonly string[],
|
||||
): RuntimeBindings {
|
||||
requireSupportedDescriptor(workspace);
|
||||
const descriptor = validateWorkspaceDescriptor(workspace);
|
||||
|
||||
return {
|
||||
dwh: resolveBinding(descriptor, "DWH", env, secretRoots),
|
||||
vector: resolveBinding(descriptor, "VECTOR", env, secretRoots),
|
||||
vectorWriter: resolveBinding(descriptor, "VECTOR_WRITER", env, secretRoots),
|
||||
embedding: resolveBinding(descriptor, "EMBEDDING", env, secretRoots),
|
||||
evidence: resolveEvidenceBinding(descriptor, env, secretRoots),
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* SSH bindings are currently probe-only: diagnostics owns a short-lived tunnel, while the
|
||||
* session runtime has no tunnel owner. Keep activation fail-closed until that lifecycle exists.
|
||||
*/
|
||||
/** SSH bindings remain diagnostic-only until the session runtime owns a long-lived tunnel. */
|
||||
export function supportsSessionRuntime(bindings: RuntimeBindings): boolean {
|
||||
return bindings.dwh.transport !== "ssh_tunnel"
|
||||
&& bindings.vector.transport !== "ssh_tunnel"
|
||||
&& bindings.evidence.missing.length === 0;
|
||||
return bindings.dwh.transport !== "ssh_tunnel" && bindings.evidence.missing.length === 0;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user