Files
dsh_shenxian/src/db/adapter.ts
T
admin c70d5d860e feat(cluster): 集群化落地 —— Manager/Worker 拆分 + 归属租约 + 跨机验证(T08)
背景:把平台从「单机单进程」改造成「1 组 Manager + N 台 Worker + 共享归属状态」,
硬约束 = 全程兼容单例模式(deployMode 默认 local;生产切换前 47 一行未动)。

主要改动
1) 数据模型 v7(SQLite 与 PG 两方言同步):新增 dsh_hosts 注册表 +
   dsh_instances.{host_id,epoch,heartbeat_at,lease_until};claimInstance 原子抢占
   (UPDATE … WHERE host_id IS NULL OR lease_until < now)+ pinInstanceHost 钉住归属。
2) 租约与 fencing:src/supervisor/lease.ts(acquire/renew/release + stillHolder 判据 +
   ttl > 2×renew 硬校验);心跳里续租,失权即向 worker 下发更高 epoch(self-fencing)。
   ⚠️ release 只清租约(lease_until),**保留 host_id** —— host_id 是「用户数据在哪台」的锚点。
3) Worker agent(src/worker/agent.ts,子命令 dshs worker):实例生命周期 + 文件面 /fs/*
   + 幂等键(operationId)+ 鉴权(timingSafeEqual);Worker 不写控制面数据
   (apiKey/uid 由 Manager 随 launch 投递,R5 收窄)。
4) 远端 Spawner + LeasedSpawner:按 host 路由(**粘性优先**:有历史归属且那台 up 就留在原地,
   否则按容量选最空的)+ 容量准入 + deployMode=cluster 装配(systemd drop-in,可回滚)。
5) bwrap 修正:**所有挂载点的中间目录统一前置 + 去重 + 由外到内**(「就近创建」会在嵌套前缀下
   遮掉已绑挂载点 ⇒ bwrap: Can't chdir);且**只能用 --tmpfs**,用 --perms 会让 47 的
   bwrap 0.4.0 直接拒启动(沙箱全挂)。
6) 跨机隧道 src/worker/tunnel.ts:SSH ControlMaster + 动态 -R 转发;**自愈由 agent 本地
   20s 定时器驱动**(不能只放 /healthz —— 心跳本身经隧道进来,断了就没人触发它)。
7) 文件面按归属路由(RemoteUserFs):实例与文件必须落在同一台机器,否则实例看不到自己的文件。
8) 观测面:dshs doctor / dshs cluster status。

验证(本次均已实跑)
- test/lease.test.mjs:SQLite 10/10 == PG 10/10
- 组件级端到端 5 个:verify-cluster-{agent,lease,fs,migrate,live}.mjs
- 真跨机(47 Manager / 106 Worker,跨云 + 反向隧道)verify-cluster-cross.mjs 九步全绿
- 域名形态访问 verify-cluster-domain.mjs(<user>.域名 → Manager → 远端实例;越权 403)
- 冒烟 scripts/smoke-*:6/8,失败项与改动前基线完全相同(无回归)
- 生产切换与回滚剧本见 dsh-server-docs/交接单/T08-集群化落地-兼容单例模式.md §16
2026-09-15 18:47:02 +08:00

149 lines
7.1 KiB
TypeScript
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
/**
* The unified async DB interface. Routes depend only on this — never on
* `better-sqlite3` or `pg` directly — so the backend can switch between SQLite
* (`deployMode=local`) and Postgres (`deployMode=k8s`) without touching callers.
* @module dshs/db/adapter
*/
import type {
BusinessPlugin,
ClaimResult,
CredentialKey,
CredentialKeyMeta,
CredentialLandingRow,
CreateSessionInput,
CreateUserInput,
Domain,
DshHost,
DshHostStatus,
DshInstance,
DshInstanceRole,
DshInstanceStatus,
PublicUser,
SessionRow,
SessionUser,
UpsertBusinessPluginInput,
UpsertDshHostInput,
UpsertDshInstanceInput,
User,
UserRole,
Workspace,
} from './types.js'
export interface DbAdapter {
// users
createUser(input: CreateUserInput): Promise<User>
findUserByUsername(username: string): Promise<User | undefined>
findUserBySlug(slug: string): Promise<User | undefined>
findUserById(id: string): Promise<User | undefined>
listPublicUsers(): Promise<PublicUser[]>
countAdmins(): Promise<number>
setUserRole(id: string, role: UserRole, approvedBy?: string): Promise<boolean>
/** Assign a Linux uid to a user (used by the legacy backfill). */
setUserUid(userId: string, uid: number): Promise<void>
/** Ids of users whose uid column is still null (legacy rows awaiting backfill). */
listUsersWithoutUid(): Promise<string[]>
/**
* Permanently delete a user and every owned row (credential_vault / domains /
* sessions / dsh_instances / audit_log / folder_plugins / workspaces), inside
* one transaction. Returns false when no such user exists.
*/
deleteUser(userId: string): Promise<boolean>
// sessions
createSession(input: CreateSessionInput): Promise<void>
findSession(tokenHash: string): Promise<SessionRow | undefined>
deleteSession(tokenHash: string): Promise<void>
deleteUserSessions(userId: string): Promise<void>
findSessionWithUser(tokenHash: string): Promise<SessionUser | undefined>
/** Whether the user has any session that has not yet expired (idle reap). */
hasActiveSession(userId: string): Promise<boolean>
// audit
audit(actor: string | null, action: string, detail?: string | null): Promise<void>
// workspaces / plugins
findWorkspaceByPath(userId: string, relPath: string): Promise<Workspace | undefined>
getOrCreateWorkspace(userId: string, relPath: string): Promise<Workspace>
setFolderPlugins(workspaceId: string, selections: ReadonlyArray<{ id: string; enabled: boolean }>): Promise<void>
getEnabledPluginIds(workspaceId: string): Promise<string[]>
// business plugins (系统外插件候选池)
listBusinessPlugins(): Promise<BusinessPlugin[]>
findBusinessPlugin(id: string): Promise<BusinessPlugin | undefined>
upsertBusinessPlugin(input: UpsertBusinessPluginInput): Promise<BusinessPlugin>
deleteBusinessPlugin(id: string): Promise<boolean>
// domains
findDomainByUser(userId: string): Promise<Domain | undefined>
findDomainById(id: string): Promise<Domain | undefined>
listDomains(): Promise<Domain[]>
upsertDomain(userId: string, domain: string, nginxConfig: string): Promise<Domain>
setDomainVerified(id: string, verified: boolean): Promise<boolean>
// credential vault
listCredentialKeys(userId: string): Promise<CredentialKey[]>
/** 档案 86:该用户**全部已启用**的条目(spawn 时按它们写实例配置)。 */
listEnabledCredentialKeys(userId: string): Promise<CredentialKey[]>
/** 档案 87:同上 + **encrypted ref** —— **仅供 `server.ts` 的落地层**,绝不经 API 返回。 */
listCredentialLandingRows(userId: string): Promise<CredentialLandingRow[]>
getEnabledCredentialKeyRef(userId: string): Promise<string | null>
setCredentialKey(
userId: string,
name: string,
encryptedRef: string,
meta?: CredentialKeyMeta,
): Promise<CredentialKey>
selectCredentialKey(userId: string, id: string): Promise<boolean>
/** 档案 86:开/关**单个**条目(不动其它条目 —— 用户口径:可同时启用多个)。 */
toggleCredentialKey(userId: string, id: string, enabled: boolean): Promise<boolean>
/** 档案 86:用户是否使用「平台共享模型」(admin 配的那把)—— 用户侧偏好。 */
getSharedModelEnabled(userId: string): Promise<boolean>
setSharedModelEnabled(userId: string, enabled: boolean): Promise<boolean>
deleteCredentialKey(userId: string, id: string): Promise<boolean>
// instances (desired state the k8s controller reconciles against — docs/k8s.md §5.7)
upsertInstance(input: UpsertDshInstanceInput): Promise<void>
findInstance(id: string): Promise<DshInstance | undefined>
findUserInstance(userId: string, role: DshInstanceRole): Promise<DshInstance | undefined>
listInstancesByRole(role: DshInstanceRole): Promise<DshInstance[]>
/** Record a state transition; `exitCode`/`lastError` also stamp `last_exit`. */
setInstanceStatus(
id: string,
status: DshInstanceStatus,
outcome?: { exitCode?: number; lastError?: string },
): Promise<boolean>
deleteInstance(id: string): Promise<boolean>
deleteUserInstances(userId: string): Promise<void>
// ── 集群化:worker 注册表 + 实例归属/租约(v7;T08 S2 / 设计 §3.1–§3.2)──
// ⚠️ local 模式**不写**这些表(`LocalSpawner` 靠进程内 Map + 单机互斥),
// 所以这些方法在单机路径上恒为"空/未认领",不影响现有行为。
/** 注册/更新一台 worker(join 幂等:同 id 重复执行 = 更新)。 */
upsertDshHost(input: UpsertDshHostInput): Promise<DshHost>
findDshHost(id: string): Promise<DshHost | undefined>
listDshHosts(): Promise<DshHost[]>
/** 心跳/状态上报:可只改状态,或同时带上容量水位与心跳时间。 */
setDshHostStatus(
id: string,
status: DshHostStatus,
usedMb?: number,
heartbeatAt?: number,
): Promise<boolean>
/**
* **原子抢占**某用户的 main 实例归属(承重墙,见设计 §3.2)。
* 仅当"无人持有 **或** 租约已过期"才成功;成功时 `epoch` +1(fencing)。
* 返回 `ok:false` = 有人在管 ⇒ 调用方**退让**(不是接管)。
*/
claimInstance(
userId: string,
hostId: string,
ttlMs: number,
meta?: { folder?: string; patch?: string },
): Promise<ClaimResult>
/** 续租。**必须带 epoch**:不匹配说明已被他人抢占 ⇒ 本次续租失败(fencing)。 */
renewInstanceLease(userId: string, hostId: string, epoch: number, ttlMs: number): Promise<boolean>
/** 主动释放(停实例时)。同样带 epoch 校验,避免误清他人的归属。 */
releaseInstanceLease(userId: string, hostId: string, epoch: number): Promise<boolean>
/** 钉住归属(首次触达工作区时用):只写 `host_id`,不动 epoch/租约。 */
pinInstanceHost(userId: string, hostId: string): Promise<void>
/** 租约已过期、但仍标着归属的实例 —— 供巡检/自愈(**不代表可以立即接管**,见 R9)。 */
listExpiredInstanceLeases(now: number): Promise<DshInstance[]>
/** 某 worker 上的全部实例 —— 对账用**一次拿回整机**(替代逐用户查询)。 */
listInstancesByHost(hostId: string): Promise<DshInstance[]>
// lifecycle
close(): Promise<void>
}