These 44 commits are when the Protocol Buffers files have changed:
| Commit: | 73005d6 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Gianmaria Del Monte | |
rjobs: add RetryAfter, Permanent and the aborted state Jobs can choose the retry delay or give up for good. The attempt number now comes from the delivery count.
| Commit: | 3883e70 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Gianmaria Del Monte | |
rjobs: let jobs report their progress Jobs implementing ProgressJob get a Reporter. The latest snapshot is persisted periodically and once more before the terminal status, and is shown by the admin API and CLI.
| Commit: | d366cbf | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Gianmaria Del Monte | |
rjobs: enqueue jobs registered by other runners Runners tag job consumers with metadata, so Enqueue accepts a job that only another process runs. Add 'admin jobs forget' to drop a removed job.
| Commit: | 594339b | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Gianmaria Del Monte | |
Expose admin status and impersonation over HTTP Clients that only speak the public HTTPS surface cannot reach the Admin API, which is gRPC on its own listener. A new admin HTTP service gives them the part they need: GET /admin/status says whether the caller is an admin, and POST /admin/impersonate returns a token acting as another user. Impersonate steps the caller up and impersonates in one request, so the admin token never leaves the server; both steps are audited as before, with a reason if the client gives one. Status is backed by a new CheckAdmin RPC that mints nothing, so asking leaves no audit trail. Impersonation tokens no longer share the admin token's lifetime. An impersonated session is used like any other, long transfers included, and fifteen minutes cut those off. They now last as long as a token from signing in, or impersonation_ttl.
| Commit: | cfe0d1e | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Gianmaria Del Monte | |
Expose admin status and impersonation over HTTP Clients that only speak the public HTTPS surface cannot reach the Admin API, which is gRPC on its own listener. A new admin HTTP service gives them the part they need: GET /admin/status says whether the caller is an admin, and POST /admin/impersonate returns a token acting as another user. Impersonate steps the caller up and impersonates in one request, so the admin token never leaves the server; both steps are audited as before, with a reason if the client gives one. Status is backed by a new CheckAdmin RPC that mints nothing, so asking leaves no audit trail. Impersonation tokens no longer share the admin token's lifetime. An impersonated session is used like any other, long transfers included, and fifteen minutes cut those off. They now last as long as a token from signing in, or impersonation_ttl.
| Commit: | f75964b | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
Expose admin status and impersonation over HTTP Clients that only speak the public HTTPS surface cannot reach the Admin API, which is gRPC on its own listener. A new admin HTTP service gives them the part they need: GET /admin/status says whether the caller is an admin, and POST /admin/impersonate returns a token acting as another user. Impersonate steps the caller up and impersonates in one request, so the admin token never leaves the server; both steps are audited as before, with a reason if the client gives one. Status is backed by a new CheckAdmin RPC that mints nothing, so asking leaves no audit trail. Impersonation tokens no longer share the admin token's lifetime. An impersonated session is used like any other, long transfers included, and fifteen minutes cut those off. They now last as long as a token from signing in, or impersonation_ttl.
| Commit: | a786472 | |
|---|---|---|
| Author: | Jesse Geens | |
| Committer: | GitHub | |
Feature/admin api (#5773) * Add the Admin API and control channel protobuf definitions * Add the invocation framework, admin scope and registry selection support * Host a per-process control channel and register service instances by node id * Add the admin gRPC service, its loader wiring and the reva admin CLI * Document the Admin API and add its changelog * Serve admin local root over a Unix socket authenticated by OS credentials * Register serverless services on the control channel by control-address node id * Buffer recent log lines in memory for the Admin API to read * Add streaming invocations and the control InvokeStream RPC * Expose recent logs as a built-in service invocation * Read and follow service logs with reva admin logs * Tag request logs with their service and user so admin logs finds them * Trace a request or a user across the fleet with reva admin trace * Report build information through a built-in version invocation * Dump goroutine stacks with reva admin stack * Report and set a process's log level at runtime with reva admin logs level * Diff a service's config across instances with reva admin config -diff * Move the reva admin CLI into its own cmd/reva/admin package * Reset a service's log level back to its configured value with reva admin logs level reset * Take instances out of rotation at runtime with reva admin services drain/enable * Skip the user-group lookup for admin tokens so local-root fan-out works under skip_user_groups_in_token * Report in-flight request activity so an operator knows when a drained instance has quiesced * Give admin subcommands a real -h synopsis and services a grouped subcommand guide * Interact with the jobs runner through typed reva admin jobs API methods over the invoke channel * Keep a job run's start time on its terminal status write * Report the reva version in the version invocation * Fix protolint issues in the admin and control protobufs * Updated doc * Added further clarification comments --------- Co-authored-by: Gianmaria Del Monte <g.macmount@gmail.com> Co-authored-by: Giuseppe Lo Presti <giuseppe.lopresti@cern.ch>
| Commit: | 6e6d92a | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Gianmaria Del Monte | |
Fix protolint issues in the admin and control protobufs
| Commit: | 3e5d3cc | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Gianmaria Del Monte | |
Interact with the jobs runner through typed reva admin jobs API methods over the invoke channel
| Commit: | 0039085 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Gianmaria Del Monte | |
Read and follow service logs with reva admin logs
| Commit: | 8088e9c | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Gianmaria Del Monte | |
Add streaming invocations and the control InvokeStream RPC
| Commit: | b8f1c69 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Gianmaria Del Monte | |
Add the Admin API and control channel protobuf definitions
| Commit: | 5a88060 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | GitHub | |
Fix protolint issues in the admin and control protobufs
| Commit: | 02fb9a7 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | GitHub | |
Interact with the jobs runner through typed reva admin jobs API methods over the invoke channel
| Commit: | f048915 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | GitHub | |
Read and follow service logs with reva admin logs
| Commit: | 5762522 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | GitHub | |
Add streaming invocations and the control InvokeStream RPC
| Commit: | 4ef4aff | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | GitHub | |
Add the Admin API and control channel protobuf definitions
| Commit: | c769a03 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Jesse Geens | |
Fix protolint issues in the admin and control protobufs
| Commit: | ce454cf | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Jesse Geens | |
Interact with the jobs runner through typed reva admin jobs API methods over the invoke channel
| Commit: | 92e49d2 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Jesse Geens | |
Read and follow service logs with reva admin logs
| Commit: | f7b152e | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Jesse Geens | |
Add streaming invocations and the control InvokeStream RPC
| Commit: | b318d63 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | Jesse Geens | |
Add the Admin API and control channel protobuf definitions
| Commit: | 8d1b4ab | |
|---|---|---|
| Author: | Giuseppe Lo Presti | |
| Committer: | GitHub | |
Pass lock metadata on uploads + use upstream EOS GRPC bindings (#4514)
The documentation is generated from this commit.
| Commit: | d3d77c7 | |
|---|---|---|
| Author: | Giuseppe Lo Presti | |
Updated copyright
| Commit: | 084c1b5 | |
|---|---|---|
| Author: | Hugo Labrador | |
| Committer: | GitHub | |
New observability + general refactor of http/grpc clients (#4166) * remove unused fs and tracing * add helloworld example and fix auth logic to bail out early * remove hack on appctx and add traceid * configurable prom collectors * grpc reflection working * wire http traffic * intrument outgoing grpc calls * add stuff * merge appctx and ctx * refactor rhttp to httpclient * tidy go.mod * remove drone tests * add changelog * fix test * go 1.21 * pass tests * fix sql tests * go fmt * more linters * make all linters happy * update docs * add back ceph example * remove otelhttp library * remove files and add tests * align with upstream
| Commit: | 605cec4 | |
|---|---|---|
| Author: | Miroslav Bauer | |
| Committer: | GitHub | |
Bump the Copyright date to 2023 (#3584) * Bump the Copyright date to 2023
| Commit: | 1e612bc | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | jkoberg | |
EOS grpc fixes (#3420) * return inode in fileinfo * fix log * fix eos grpc parsing * stat as a root * workaround for inode (revert me) * set parent id in eosfs * Revert "stat as a root" This reverts commit 81ce7b3e66f79d2401549d8ec67c1fa15a187f7b. * set storage id to parent id in storage provider * fix file path * clean path returned by eos * set xattrs for lock as root * fix key when setting attribute * stat as root * Revert "stat as root" This reverts commit e865e6e2f8d75d3759f2e3e0c8ca657a2c6ade6b. * trim prefix for user attrs * do not filter sys attrs * fix add acl * fix initiate file upload reference resolution * fix initiate file upload * Revert "fix initiate file upload" This reverts commit 265d09187d3ab4d646ace20df2ceaf925788e39f. * set sys acl as root * workaround for adding acl * fix unset attr * unset lock as root * Avoid crash when getting checksum in a stat request * fix * add changelog * fix linter * fix license Co-authored-by: Fabrizio Furano <furano@cern.ch>
| Commit: | f4ad966 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | jkoberg | |
Implementation of CS3 Lock API for EOS storage driver (#2444)
| Commit: | 48a2870 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | GitHub | |
EOS grpc fixes (#3420) * return inode in fileinfo * fix log * fix eos grpc parsing * stat as a root * workaround for inode (revert me) * set parent id in eosfs * Revert "stat as a root" This reverts commit 81ce7b3e66f79d2401549d8ec67c1fa15a187f7b. * set storage id to parent id in storage provider * fix file path * clean path returned by eos * set xattrs for lock as root * fix key when setting attribute * stat as root * Revert "stat as root" This reverts commit e865e6e2f8d75d3759f2e3e0c8ca657a2c6ade6b. * trim prefix for user attrs * do not filter sys attrs * fix add acl * fix initiate file upload reference resolution * fix initiate file upload * Revert "fix initiate file upload" This reverts commit 265d09187d3ab4d646ace20df2ceaf925788e39f. * set sys acl as root * workaround for adding acl * fix unset attr * unset lock as root * Avoid crash when getting checksum in a stat request * fix * add changelog * fix linter * fix license Co-authored-by: Fabrizio Furano <furano@cern.ch>
| Commit: | af8fe04 | |
|---|---|---|
| Author: | Vasco Guita | |
| Committer: | Gianmaria Del Monte | |
Migrate the BuildOnly job from Drone to GitHub Actions
| Commit: | d25a3a7 | |
|---|---|---|
| Author: | Gianmaria Del Monte | |
| Committer: | GitHub | |
Implementation of CS3 Lock API for EOS storage driver (#2444)
| Commit: | 2ec4ae6 | |
|---|---|---|
| Author: | Fabrizio Furano | |
| Committer: | GitHub | |
Implement rollback to version (#1927)
| Commit: | c95ddaf | |
|---|---|---|
| Author: | Ishank Arora | |
| Committer: | GitHub | |
Generate updated protobuf bindings for EOS GRPC (#1916)
| Commit: | 692f38f | |
|---|---|---|
| Author: | Fabrizio Furano | |
| Committer: | GitHub | |
EOS GRPC interface (#1471)
| Commit: | 73f1c7b | |
|---|---|---|
| Author: | Ishank Arora | |
| Committer: | GitHub | |
Add FindAcceptedUsers method to OCM Invite API (#1527)
| Commit: | bd7234e | |
|---|---|---|
| Author: | Samuel Alfageme | |
| Committer: | GitHub | |
Bump the Copyright in the header to 2021 (#1397)
| Commit: | 655c9ba | |
|---|---|---|
| Author: | Fabrizio Furano | |
| Committer: | GitHub | |
Progress with the eosgrpc client (#1154) Co-authored-by: Ishank Arora <ishank011@gmail.com>
| Commit: | 07ab188 | |
|---|---|---|
| Author: | Phil Davis | |
| Committer: | GitHub | |
Change percentagused to percentageused (#903)
| Commit: | e8f1815 | |
|---|---|---|
| Author: | Phil Davis | |
| Committer: | GitHub | |
Fix minor typos (#898)
| Commit: | 0e74029 | |
|---|---|---|
| Author: | Fabrizio Furano | |
| Committer: | GitHub | |
eos grpc driver (#664)
| Commit: | 0dbce24 | |
|---|---|---|
| Author: | Hugo G. Labrador | |
| Committer: | GitHub | |
Update license year to 2020 (#504)
| Commit: | f3c5618 | |
|---|---|---|
| Author: | Hugo G. Labrador | |
| Committer: | GitHub | |
build: remove vendor modules (#465)
| Commit: | 02e4953 | |
|---|---|---|
| Author: | Hugo G. Labrador | |
| Committer: | GitHub | |
vendor deps for network isolated builds (#308) * vendor deps for network isolated builds * clean build * improve ci * speed up build
| Commit: | 9db3db0 | |
|---|---|---|
| Author: | Hugo G. Labrador | |
| Committer: | GitHub | |
Gateway+metadata (#289) * Add metadata support * Add gateway as required element of the deployment * New code layout enforcing Go best practices for encapsulation * Support for multiple authentication backends * New user provider grpc service