feat(manager-core,orchestrator-core): multi-app scoping (Phase 3b)
Apps become the isolation boundary for scripts, routes, domains, and
later data. Doing this now — while the surface is small — avoids
several migrations on populated tables once v1.1 data-plane services
ship.
Schema (migration 0005_apps.sql):
- New tables: apps, app_domains (with shape_key UNIQUE for collision
detection), app_slug_history (for permanent slug-rename redirects).
- app_id added to scripts, routes, execution_logs (non-null, cascading
rules per row).
- Script-name uniqueness becomes per-app; the route unique index is
swapped for an app-scoped version.
- The "default" app is seeded unconditionally with a localhost claim;
existing scripts/routes backfill into it. Fresh installs additionally
get the Hello World seed via seed_hello_world_if_fresh after
migrations run (idempotent — only fires when the default app has no
scripts).
Orchestrator dispatch is two-phase: AppDomainTable resolves Host →
app_id (most-specific match wins, exact beats wildcard), then the
existing route matcher runs against that app's partitioned slice via
RouteTable. Unknown hosts return 404 at the app layer with a clear
message; /api/v1/execute/{id} still works as the implicit
__internal__ claim, decoupled from any public domain.
Manager API: full CRUD for /api/v1/admin/apps/* and
/api/v1/admin/apps/{id_or_slug}/domains/*, with slug:check + force
takeover semantics implementing the rename-history flow (two-step
check → confirm, never a single endpoint). Script create requires
app_id; list accepts ?app= filter. Route create validates host
against the parent app's claims; conflict detection stays strictly
intra-app.
Dashboard: /admin/apps and /admin/apps/{slug} (overview + scripts +
domains + settings tabs, with slug-history-aware redirects). Root
path redirects to the apps list. Script detail page gains an app
breadcrumb and threads app_id into the route preview.
Deferred per design: per-app admin roles. The require_admin middleware
remains the seam where role checks will slot in later.
Blueprint §11.5 and roadmap updated to reflect what shipped; docs/
versioning.md notes the schema 3 → 5 bump.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
92
crates/manager-core/src/app_bootstrap.rs
Normal file
92
crates/manager-core/src/app_bootstrap.rs
Normal file
@@ -0,0 +1,92 @@
|
||||
//! Hello-World seed for fresh installs.
|
||||
//!
|
||||
//! Idempotent. Runs after migrations and after admin bootstrap. Only
|
||||
//! seeds when the default app is empty (no scripts, no routes); on
|
||||
//! upgrades it does nothing so existing content isn't polluted.
|
||||
|
||||
use std::sync::Arc;
|
||||
|
||||
use picloud_shared::{App, AppId, HostKind, PathKind};
|
||||
|
||||
use crate::app_repo::AppRepository;
|
||||
use crate::repo::{NewScript, ScriptRepository, ScriptRepositoryError};
|
||||
use crate::route_repo::{NewRoute, RouteRepository};
|
||||
|
||||
const HELLO_RHAI_SOURCE: &str = include_str!("../seeds/hello.rhai");
|
||||
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum HelloWorldOutcome {
|
||||
/// Default app already has scripts (or doesn't exist) — left alone.
|
||||
SkippedExisting,
|
||||
/// Inserted the hello.rhai script and the `/hello` route.
|
||||
Seeded,
|
||||
}
|
||||
|
||||
#[derive(Debug, thiserror::Error)]
|
||||
pub enum SeedError {
|
||||
#[error("default app not found — did the migration run?")]
|
||||
MissingDefaultApp,
|
||||
#[error("repository error: {0}")]
|
||||
Repo(#[from] ScriptRepositoryError),
|
||||
}
|
||||
|
||||
pub async fn seed_hello_world_if_fresh(
|
||||
apps: Arc<dyn AppRepository>,
|
||||
scripts: Arc<dyn ScriptRepository>,
|
||||
routes: Arc<dyn RouteRepository>,
|
||||
) -> Result<HelloWorldOutcome, SeedError> {
|
||||
let default = apps
|
||||
.get_by_slug("default")
|
||||
.await?
|
||||
.ok_or(SeedError::MissingDefaultApp)?;
|
||||
|
||||
// Idempotence: only seed when both scripts AND routes are empty.
|
||||
// (Either alone is suspicious enough to skip — the operator may have
|
||||
// already started shaping the default app.)
|
||||
let existing_scripts = scripts.list_for_app(default.id).await?;
|
||||
let existing_routes = routes.list_for_app(default.id).await?;
|
||||
if !existing_scripts.is_empty() || !existing_routes.is_empty() {
|
||||
return Ok(HelloWorldOutcome::SkippedExisting);
|
||||
}
|
||||
|
||||
seed_into(&*scripts, &*routes, &default).await?;
|
||||
Ok(HelloWorldOutcome::Seeded)
|
||||
}
|
||||
|
||||
async fn seed_into(
|
||||
scripts: &dyn ScriptRepository,
|
||||
routes: &dyn RouteRepository,
|
||||
default: &App,
|
||||
) -> Result<(), ScriptRepositoryError> {
|
||||
let script = scripts
|
||||
.create(NewScript {
|
||||
app_id: default.id,
|
||||
name: "hello".to_string(),
|
||||
description: Some("Reference example: returns a greeting at GET /hello.".to_string()),
|
||||
source: HELLO_RHAI_SOURCE.to_string(),
|
||||
timeout_seconds: Some(5),
|
||||
memory_limit_mb: None,
|
||||
sandbox: None,
|
||||
})
|
||||
.await?;
|
||||
|
||||
routes
|
||||
.create(NewRoute {
|
||||
app_id: default.id,
|
||||
script_id: script.id,
|
||||
host_kind: HostKind::Any,
|
||||
host: String::new(),
|
||||
host_param_name: None,
|
||||
path_kind: PathKind::Exact,
|
||||
path: "/hello".to_string(),
|
||||
// Accept any method so both `curl /hello` and
|
||||
// `curl -d '{"name":"X"}' /hello` work out of the box.
|
||||
method: None,
|
||||
})
|
||||
.await?;
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
#[allow(dead_code)]
|
||||
fn _typecheck(_id: AppId) {} // suppress unused-import warnings if reshuffled
|
||||
Reference in New Issue
Block a user