Files
felhom-controller/controller/internal/web/intermediary.go
T
admin 3adfa41a09 controller v0.67.2: gate keys present on BoundUnderParent (reboot convergence)
The drive-absent gate treats a stable path usable only when bound under the parent
(BoundUnderParent), not merely host-mounted. Makes a host reboot converge: apps
stay gated until the agent binds the drive under the parent, then are restarted
(recreated) on the populated path. Test updated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 17:10:02 +02:00

277 lines
11 KiB
Go

package web
import (
"context"
"encoding/json"
"net/http"
"path"
"strings"
"time"
"gitea.dooplex.hu/admin/felhom-controller/internal/agentapi"
"gitea.dooplex.hu/admin/felhom-controller/internal/settings"
)
// Intermediary-mount model (controller side). Post-migration a drive is visible in the guest ONLY at its
// STABLE path /mnt/felhom-drives/<name> (the host swaps the backing drive underneath it; see the agent's
// internal/localapi/intermediary.go + SPIKE-intermediary-mount). So:
// - the REGISTERED storage path + every app's HDD_PATH + FileBrowser source = the STABLE path;
// - the AGENT still operates on the RAW /mnt/<name> host PVE mount (assign/attach/eject/decommission),
// so controller→agent `where` is mapped back to raw via agentWhere().
// The drive-absent GATE stops + blocks apps when their drive vanishes and auto-restarts them when it
// returns (host-side, no guest reboot).
// StableParentDir is the permanent in-guest parent the agent binds drives under (mirrors
// localapi.StableParentDir).
const StableParentDir = "/mnt/felhom-drives"
// stablePathForName maps a drive name to its registered stable in-guest path.
func stablePathForName(name string) string { return StableParentDir + "/" + name }
// agentWhere maps a registered storage path — stable /mnt/felhom-drives/<name> OR a legacy raw /mnt/<name>
// — to the RAW /mnt/<name> host mount the agent operates on. Idempotent for an already-raw path
// (path.Base drops the directory either way).
func agentWhere(registeredPath string) string {
name := path.Base(strings.TrimRight(registeredPath, "/"))
if name == "" || name == "." || name == "/" {
return registeredPath
}
return "/mnt/" + name
}
// appsOnStoragePath returns the deployed stack names whose HDD_PATH equals the given (stable) storage
// path — the apps that depend on that drive.
func (s *Server) appsOnStoragePath(storagePath string) []string {
var names []string
for _, st := range s.stackMgr.GetStacks() {
if cfg := s.stackMgr.LoadAppConfigByName(st.Name); cfg != nil && cfg.Env["HDD_PATH"] == storagePath {
names = append(names, st.Name)
}
}
return names
}
// stopAppsOnPath stops every deployed app on the given storage path and returns their names (the
// gate-stopped set — distinct from a user stop, which never enters this set). Best-effort per app.
func (s *Server) stopAppsOnPath(storagePath string) []string {
var stopped []string
for _, name := range s.appsOnStoragePath(storagePath) {
if err := s.stackMgr.StopStack(name); err != nil {
s.logger.Printf("[WARN] [gate] stop %s on absent %s: %v", name, storagePath, err)
continue
}
stopped = append(stopped, name)
}
return stopped
}
// restartStacks starts each named stack (the gate-stopped set on drive return). Best-effort per app.
func (s *Server) restartStacks(names []string) {
for _, name := range names {
if err := s.stackMgr.StartStack(name); err != nil {
s.logger.Printf("[WARN] [gate] restart %s: %v", name, err)
}
}
}
// gateAction is the reconcile's decision for one registered storage path.
type gateAction struct {
Path string
Stop bool // drive ABSENT + not yet marked → stop apps, mark disconnected
Return bool // drive RETURNED (present + currently disconnected) → re-attach, restart, clear
Raw string // raw /mnt/<name> for the re-attach
}
// planDriveGates is the PURE decision core: given the registry + the agent's disk list, decide per path
// whether to gate (stop) or un-gate (return). A drive is "present" iff a disk with a matching GuestPath
// (stable) or MountPath (legacy raw) is State=="attached". Decommissioned paths are skipped (handled by
// the decommission flow, not the transient gate). No side effects → unit-testable.
func planDriveGates(paths []settings.StoragePath, disks []agentapi.DiskInfo) []gateAction {
present := map[string]bool{}
rawByPath := map[string]string{}
for _, d := range disks {
// A STABLE path is usable only when the drive's felhom-data is actually BOUND UNDER THE PARENT
// (BoundUnderParent) — NOT merely when the raw drive is host-mounted (State==attached). This is
// what makes the gate converge a reboot correctly: at boot the raw drive mounts early but the
// agent binds it under the parent slightly later; until then the apps' stable-path binds are empty,
// so the gate keeps them stopped and restarts (recreates) them once the bind is live.
if d.GuestPath != "" {
present[d.GuestPath] = present[d.GuestPath] || d.BoundUnderParent
rawByPath[d.GuestPath] = d.MountPath
}
if d.MountPath != "" { // legacy raw path registered directly — host mount is the usable signal
present[d.MountPath] = present[d.MountPath] || d.State == "attached"
rawByPath[d.MountPath] = d.MountPath
}
}
var actions []gateAction
for _, sp := range paths {
if sp.Decommissioned {
continue
}
// ONLY gate EXTERNAL drives — those registered under the stable parent /mnt/felhom-drives/<name>.
// Internal SSD / system paths (e.g. /mnt/sys_drive/felhom-data) are always-present locals the agent
// never reports as drives; gating them on "absence" would falsely stop/block their apps. (Legacy
// raw /mnt/<name> external paths are present via the agent's MountPath during the transition and get
// repointed under the parent by the migration.)
if !strings.HasPrefix(sp.Path, StableParentDir+"/") {
continue
}
switch {
case !present[sp.Path] && !sp.Disconnected:
actions = append(actions, gateAction{Path: sp.Path, Stop: true})
case present[sp.Path] && sp.Disconnected:
actions = append(actions, gateAction{Path: sp.Path, Return: true, Raw: rawByPath[sp.Path]})
}
}
return actions
}
// ReconcileDriveGates enforces the drive-absent gate: an ABSENT registered drive gets its apps STOPPED +
// recorded (disconnected); a RETURNED drive gets re-bound under the parent and its gate-stopped apps
// restarted. Best-effort + idempotent — safe to call on a timer and on demand.
func (s *Server) ReconcileDriveGates() {
if s.settings == nil || s.stackMgr == nil {
return
}
agent, err := s.agentClient()
if err != nil {
return
}
ctx, cancel := context.WithTimeout(context.Background(), 15*time.Second)
defer cancel()
resp, err := agent.Disks(ctx)
if err != nil {
return
}
for _, a := range planDriveGates(s.settings.GetStoragePaths(), resp.Disks) {
switch {
case a.Stop:
stopped := s.stopAppsOnPath(a.Path)
if err := s.settings.SetDisconnected(a.Path, true, stopped); err != nil {
s.logger.Printf("[WARN] [gate] mark disconnected %s: %v", a.Path, err)
}
s.logger.Printf("[WARN] [gate] drive ABSENT %s — stopped+blocked %d app(s): %v", a.Path, len(stopped), stopped)
go s.SyncFileBrowserMounts()
case a.Return:
if a.Raw != "" {
if err := agent.GuestAttach(ctx, a.Raw); err != nil {
s.logger.Printf("[WARN] [gate] re-attach %s (raw %s): %v", a.Path, a.Raw, err)
}
}
var stopped []string
for _, sp := range s.settings.GetStoragePaths() {
if sp.Path == a.Path {
stopped = sp.StoppedStacks
}
}
s.restartStacks(stopped)
if err := s.settings.ClearDisconnected(a.Path); err != nil {
s.logger.Printf("[WARN] [gate] clear disconnected %s: %v", a.Path, err)
}
s.logger.Printf("[INFO] [gate] drive RETURNED %s — re-attached + restarted gate-stopped apps", a.Path)
go s.SyncFileBrowserMounts()
}
}
}
// driveGateLoop runs ReconcileDriveGates on a timer (the periodic absent/return detector — the slice-8C
// watchdog was retired). Started as a goroutine at server startup.
func (s *Server) driveGateLoop() {
t := time.NewTicker(30 * time.Second)
defer t.Stop()
for range t.C {
s.ReconcileDriveGates()
}
}
// ---- H1 endpoints (the UI's settings.js calls these; previously 404/unrouted) -----------------
// handleStorageDisconnect EJECTS a drive without restart: stop its apps (gate-stopped), agent-detach the
// felhom-data bind from under the parent (live, fail-closed), and mark it disconnected. The drive is then
// safely removable. POST {where} where = the registered (stable) path.
func (s *Server) handleStorageDisconnect(w http.ResponseWriter, r *http.Request) {
where, ok := s.gateWhere(w, r)
if !ok {
return
}
stopped := s.stopAppsOnPath(where)
agent, err := s.agentClient()
if err == nil {
if _, derr := agent.EjectDisk(r.Context(), agentWhere(where)); derr != nil {
s.logger.Printf("[WARN] [web] disconnect: agent detach %s failed: %v", where, derr)
}
}
if err := s.settings.SetDisconnected(where, true, stopped); err != nil {
writeDiskJSON(w, http.StatusInternalServerError, false, err.Error(), nil)
return
}
go s.SyncFileBrowserMounts()
writeDiskJSON(w, http.StatusOK, true, "", map[string]any{"where": where, "stopped": stopped})
}
// handleStorageReconnect re-attaches a returned drive without restart: agent-attach the felhom-data bind
// under the parent (live), restart the gate-stopped apps, clear the disconnected mark.
func (s *Server) handleStorageReconnect(w http.ResponseWriter, r *http.Request) {
where, ok := s.gateWhere(w, r)
if !ok {
return
}
var stopped []string
for _, sp := range s.settings.GetStoragePaths() {
if sp.Path == where {
stopped = sp.StoppedStacks
}
}
agent, err := s.agentClient()
if err != nil {
writeDiskJSON(w, http.StatusServiceUnavailable, false, err.Error(), nil)
return
}
if aerr := agent.GuestAttach(r.Context(), agentWhere(where)); aerr != nil {
writeDiskJSON(w, http.StatusBadGateway, false, "újracsatolás sikertelen: "+aerr.Error(), nil)
return
}
s.restartStacks(stopped)
if err := s.settings.ClearDisconnected(where); err != nil {
writeDiskJSON(w, http.StatusInternalServerError, false, err.Error(), nil)
return
}
go s.SyncFileBrowserMounts()
writeDiskJSON(w, http.StatusOK, true, "", map[string]any{"where": where, "restarted": stopped})
}
// handleStorageRestartApps restarts the gate-stopped apps on a path (without changing connection state) —
// the manual "restart the apps that were stopped" action.
func (s *Server) handleStorageRestartApps(w http.ResponseWriter, r *http.Request) {
where, ok := s.gateWhere(w, r)
if !ok {
return
}
var stopped []string
for _, sp := range s.settings.GetStoragePaths() {
if sp.Path == where {
stopped = sp.StoppedStacks
}
}
s.restartStacks(stopped)
writeDiskJSON(w, http.StatusOK, true, "", map[string]any{"where": where, "restarted": stopped})
}
// gateWhere decodes + validates the {where} body shared by the H1 endpoints.
func (s *Server) gateWhere(w http.ResponseWriter, r *http.Request) (string, bool) {
var req struct {
Where string `json:"where"`
}
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
writeDiskJSON(w, http.StatusBadRequest, false, "érvénytelen kérés", nil)
return "", false
}
where := path.Clean(strings.TrimSpace(req.Where))
if where == "" || where == "." || !strings.HasPrefix(where, "/mnt/") {
writeDiskJSON(w, http.StatusBadRequest, false, "érvénytelen csatlakoztatási pont", nil)
return "", false
}
return where, true
}