背景:把平台从「单机单进程」改造成「1 组 Manager + N 台 Worker + 共享归属状态」,
硬约束 = 全程兼容单例模式(deployMode 默认 local;生产切换前 47 一行未动)。
主要改动
1) 数据模型 v7(SQLite 与 PG 两方言同步):新增 dsh_hosts 注册表 +
dsh_instances.{host_id,epoch,heartbeat_at,lease_until};claimInstance 原子抢占
(UPDATE … WHERE host_id IS NULL OR lease_until < now)+ pinInstanceHost 钉住归属。
2) 租约与 fencing:src/supervisor/lease.ts(acquire/renew/release + stillHolder 判据 +
ttl > 2×renew 硬校验);心跳里续租,失权即向 worker 下发更高 epoch(self-fencing)。
⚠️ release 只清租约(lease_until),**保留 host_id** —— host_id 是「用户数据在哪台」的锚点。
3) Worker agent(src/worker/agent.ts,子命令 dshs worker):实例生命周期 + 文件面 /fs/*
+ 幂等键(operationId)+ 鉴权(timingSafeEqual);Worker 不写控制面数据
(apiKey/uid 由 Manager 随 launch 投递,R5 收窄)。
4) 远端 Spawner + LeasedSpawner:按 host 路由(**粘性优先**:有历史归属且那台 up 就留在原地,
否则按容量选最空的)+ 容量准入 + deployMode=cluster 装配(systemd drop-in,可回滚)。
5) bwrap 修正:**所有挂载点的中间目录统一前置 + 去重 + 由外到内**(「就近创建」会在嵌套前缀下
遮掉已绑挂载点 ⇒ bwrap: Can't chdir);且**只能用 --tmpfs**,用 --perms 会让 47 的
bwrap 0.4.0 直接拒启动(沙箱全挂)。
6) 跨机隧道 src/worker/tunnel.ts:SSH ControlMaster + 动态 -R 转发;**自愈由 agent 本地
20s 定时器驱动**(不能只放 /healthz —— 心跳本身经隧道进来,断了就没人触发它)。
7) 文件面按归属路由(RemoteUserFs):实例与文件必须落在同一台机器,否则实例看不到自己的文件。
8) 观测面:dshs doctor / dshs cluster status。
验证(本次均已实跑)
- test/lease.test.mjs:SQLite 10/10 == PG 10/10
- 组件级端到端 5 个:verify-cluster-{agent,lease,fs,migrate,live}.mjs
- 真跨机(47 Manager / 106 Worker,跨云 + 反向隧道)verify-cluster-cross.mjs 九步全绿
- 域名形态访问 verify-cluster-domain.mjs(<user>.域名 → Manager → 远端实例;越权 403)
- 冒烟 scripts/smoke-*:6/8,失败项与改动前基线完全相同(无回归)
- 生产切换与回滚剧本见 dsh-server-docs/交接单/T08-集群化落地-兼容单例模式.md §16
149 lines
7.1 KiB
TypeScript
149 lines
7.1 KiB
TypeScript
/**
|
||
* The unified async DB interface. Routes depend only on this — never on
|
||
* `better-sqlite3` or `pg` directly — so the backend can switch between SQLite
|
||
* (`deployMode=local`) and Postgres (`deployMode=k8s`) without touching callers.
|
||
* @module dshs/db/adapter
|
||
*/
|
||
|
||
import type {
|
||
BusinessPlugin,
|
||
ClaimResult,
|
||
CredentialKey,
|
||
CredentialKeyMeta,
|
||
CredentialLandingRow,
|
||
CreateSessionInput,
|
||
CreateUserInput,
|
||
Domain,
|
||
DshHost,
|
||
DshHostStatus,
|
||
DshInstance,
|
||
DshInstanceRole,
|
||
DshInstanceStatus,
|
||
PublicUser,
|
||
SessionRow,
|
||
SessionUser,
|
||
UpsertBusinessPluginInput,
|
||
UpsertDshHostInput,
|
||
UpsertDshInstanceInput,
|
||
User,
|
||
UserRole,
|
||
Workspace,
|
||
} from './types.js'
|
||
|
||
export interface DbAdapter {
|
||
// users
|
||
createUser(input: CreateUserInput): Promise<User>
|
||
findUserByUsername(username: string): Promise<User | undefined>
|
||
findUserBySlug(slug: string): Promise<User | undefined>
|
||
findUserById(id: string): Promise<User | undefined>
|
||
listPublicUsers(): Promise<PublicUser[]>
|
||
countAdmins(): Promise<number>
|
||
setUserRole(id: string, role: UserRole, approvedBy?: string): Promise<boolean>
|
||
/** Assign a Linux uid to a user (used by the legacy backfill). */
|
||
setUserUid(userId: string, uid: number): Promise<void>
|
||
/** Ids of users whose uid column is still null (legacy rows awaiting backfill). */
|
||
listUsersWithoutUid(): Promise<string[]>
|
||
/**
|
||
* Permanently delete a user and every owned row (credential_vault / domains /
|
||
* sessions / dsh_instances / audit_log / folder_plugins / workspaces), inside
|
||
* one transaction. Returns false when no such user exists.
|
||
*/
|
||
deleteUser(userId: string): Promise<boolean>
|
||
// sessions
|
||
createSession(input: CreateSessionInput): Promise<void>
|
||
findSession(tokenHash: string): Promise<SessionRow | undefined>
|
||
deleteSession(tokenHash: string): Promise<void>
|
||
deleteUserSessions(userId: string): Promise<void>
|
||
findSessionWithUser(tokenHash: string): Promise<SessionUser | undefined>
|
||
/** Whether the user has any session that has not yet expired (idle reap). */
|
||
hasActiveSession(userId: string): Promise<boolean>
|
||
// audit
|
||
audit(actor: string | null, action: string, detail?: string | null): Promise<void>
|
||
// workspaces / plugins
|
||
findWorkspaceByPath(userId: string, relPath: string): Promise<Workspace | undefined>
|
||
getOrCreateWorkspace(userId: string, relPath: string): Promise<Workspace>
|
||
setFolderPlugins(workspaceId: string, selections: ReadonlyArray<{ id: string; enabled: boolean }>): Promise<void>
|
||
getEnabledPluginIds(workspaceId: string): Promise<string[]>
|
||
// business plugins (系统外插件候选池)
|
||
listBusinessPlugins(): Promise<BusinessPlugin[]>
|
||
findBusinessPlugin(id: string): Promise<BusinessPlugin | undefined>
|
||
upsertBusinessPlugin(input: UpsertBusinessPluginInput): Promise<BusinessPlugin>
|
||
deleteBusinessPlugin(id: string): Promise<boolean>
|
||
// domains
|
||
findDomainByUser(userId: string): Promise<Domain | undefined>
|
||
findDomainById(id: string): Promise<Domain | undefined>
|
||
listDomains(): Promise<Domain[]>
|
||
upsertDomain(userId: string, domain: string, nginxConfig: string): Promise<Domain>
|
||
setDomainVerified(id: string, verified: boolean): Promise<boolean>
|
||
// credential vault
|
||
listCredentialKeys(userId: string): Promise<CredentialKey[]>
|
||
/** 档案 86:该用户**全部已启用**的条目(spawn 时按它们写实例配置)。 */
|
||
listEnabledCredentialKeys(userId: string): Promise<CredentialKey[]>
|
||
/** 档案 87:同上 + **encrypted ref** —— **仅供 `server.ts` 的落地层**,绝不经 API 返回。 */
|
||
listCredentialLandingRows(userId: string): Promise<CredentialLandingRow[]>
|
||
getEnabledCredentialKeyRef(userId: string): Promise<string | null>
|
||
setCredentialKey(
|
||
userId: string,
|
||
name: string,
|
||
encryptedRef: string,
|
||
meta?: CredentialKeyMeta,
|
||
): Promise<CredentialKey>
|
||
selectCredentialKey(userId: string, id: string): Promise<boolean>
|
||
/** 档案 86:开/关**单个**条目(不动其它条目 —— 用户口径:可同时启用多个)。 */
|
||
toggleCredentialKey(userId: string, id: string, enabled: boolean): Promise<boolean>
|
||
/** 档案 86:用户是否使用「平台共享模型」(admin 配的那把)—— 用户侧偏好。 */
|
||
getSharedModelEnabled(userId: string): Promise<boolean>
|
||
setSharedModelEnabled(userId: string, enabled: boolean): Promise<boolean>
|
||
deleteCredentialKey(userId: string, id: string): Promise<boolean>
|
||
// instances (desired state the k8s controller reconciles against — docs/k8s.md §5.7)
|
||
upsertInstance(input: UpsertDshInstanceInput): Promise<void>
|
||
findInstance(id: string): Promise<DshInstance | undefined>
|
||
findUserInstance(userId: string, role: DshInstanceRole): Promise<DshInstance | undefined>
|
||
listInstancesByRole(role: DshInstanceRole): Promise<DshInstance[]>
|
||
/** Record a state transition; `exitCode`/`lastError` also stamp `last_exit`. */
|
||
setInstanceStatus(
|
||
id: string,
|
||
status: DshInstanceStatus,
|
||
outcome?: { exitCode?: number; lastError?: string },
|
||
): Promise<boolean>
|
||
deleteInstance(id: string): Promise<boolean>
|
||
deleteUserInstances(userId: string): Promise<void>
|
||
// ── 集群化:worker 注册表 + 实例归属/租约(v7;T08 S2 / 设计 §3.1–§3.2)──
|
||
// ⚠️ local 模式**不写**这些表(`LocalSpawner` 靠进程内 Map + 单机互斥),
|
||
// 所以这些方法在单机路径上恒为"空/未认领",不影响现有行为。
|
||
/** 注册/更新一台 worker(join 幂等:同 id 重复执行 = 更新)。 */
|
||
upsertDshHost(input: UpsertDshHostInput): Promise<DshHost>
|
||
findDshHost(id: string): Promise<DshHost | undefined>
|
||
listDshHosts(): Promise<DshHost[]>
|
||
/** 心跳/状态上报:可只改状态,或同时带上容量水位与心跳时间。 */
|
||
setDshHostStatus(
|
||
id: string,
|
||
status: DshHostStatus,
|
||
usedMb?: number,
|
||
heartbeatAt?: number,
|
||
): Promise<boolean>
|
||
/**
|
||
* **原子抢占**某用户的 main 实例归属(承重墙,见设计 §3.2)。
|
||
* 仅当"无人持有 **或** 租约已过期"才成功;成功时 `epoch` +1(fencing)。
|
||
* 返回 `ok:false` = 有人在管 ⇒ 调用方**退让**(不是接管)。
|
||
*/
|
||
claimInstance(
|
||
userId: string,
|
||
hostId: string,
|
||
ttlMs: number,
|
||
meta?: { folder?: string; patch?: string },
|
||
): Promise<ClaimResult>
|
||
/** 续租。**必须带 epoch**:不匹配说明已被他人抢占 ⇒ 本次续租失败(fencing)。 */
|
||
renewInstanceLease(userId: string, hostId: string, epoch: number, ttlMs: number): Promise<boolean>
|
||
/** 主动释放(停实例时)。同样带 epoch 校验,避免误清他人的归属。 */
|
||
releaseInstanceLease(userId: string, hostId: string, epoch: number): Promise<boolean>
|
||
/** 钉住归属(首次触达工作区时用):只写 `host_id`,不动 epoch/租约。 */
|
||
pinInstanceHost(userId: string, hostId: string): Promise<void>
|
||
/** 租约已过期、但仍标着归属的实例 —— 供巡检/自愈(**不代表可以立即接管**,见 R9)。 */
|
||
listExpiredInstanceLeases(now: number): Promise<DshInstance[]>
|
||
/** 某 worker 上的全部实例 —— 对账用**一次拿回整机**(替代逐用户查询)。 */
|
||
listInstancesByHost(hostId: string): Promise<DshInstance[]>
|
||
// lifecycle
|
||
close(): Promise<void>
|
||
}
|