refactor(service-role-loader): retire active_services #13
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "refactor/drop-active-services"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
Every service role is now switched on by its own
<role>_enabledflagthrough
service_roles, soactive_servicesno longer loaded anything aflag could not. What it still did was outlive the roles it named: a host
that kept a retired
iptables-*role in the list failed its run at theloader with "role not found" — after hardening had applied, before
firewall-applyran — and no gate can see it, because inventories areuntracked.
What changed
service-role-loaderfails a host that still setsactive_services, No changes this sessionbefore loading anything, also under
--checkand a tagged run. Themessage names the flag to set for a
service_rolesmember, and namesany other entry as one to add to
service_rolesor drop as retired.active_servicesdefault aregone;
firewall-applyno longer seeds services from the list.it has to join
service_rolesand have its flag set.CONTRIBUTING.mdalso gainsa note on running the gates from a sandbox that lacks the user's
collections.
Verification
make VENV=.venv-jail check: every gate passes, including the newretiredgate (tests/gates/check_retired_services.sh) andrender,whose
fx_labfixture now comes in through a flag.make testandmake propagation(no podman in theenvironment used).
Risks and follow-ups
A tenant inventory or
host_varsthat still setsactive_servicesnowfails at the loader on its next run,
--checkincluded — by design.Only the one known stale entry existed, and it was already removed
locally. Run
make testandmake propagationbefore merging.