Proto commits in cs3org/reva

These 44 commits are when the Protocol Buffers files have changed:

Commit:73005d6
Author:Gianmaria Del Monte
Committer:Gianmaria Del Monte

rjobs: add RetryAfter, Permanent and the aborted state Jobs can choose the retry delay or give up for good. The attempt number now comes from the delivery count.

Commit:3883e70
Author:Gianmaria Del Monte
Committer:Gianmaria Del Monte

rjobs: let jobs report their progress Jobs implementing ProgressJob get a Reporter. The latest snapshot is persisted periodically and once more before the terminal status, and is shown by the admin API and CLI.

Commit:d366cbf
Author:Gianmaria Del Monte
Committer:Gianmaria Del Monte

rjobs: enqueue jobs registered by other runners Runners tag job consumers with metadata, so Enqueue accepts a job that only another process runs. Add 'admin jobs forget' to drop a removed job.

Commit:594339b
Author:Gianmaria Del Monte
Committer:Gianmaria Del Monte

Expose admin status and impersonation over HTTP Clients that only speak the public HTTPS surface cannot reach the Admin API, which is gRPC on its own listener. A new admin HTTP service gives them the part they need: GET /admin/status says whether the caller is an admin, and POST /admin/impersonate returns a token acting as another user. Impersonate steps the caller up and impersonates in one request, so the admin token never leaves the server; both steps are audited as before, with a reason if the client gives one. Status is backed by a new CheckAdmin RPC that mints nothing, so asking leaves no audit trail. Impersonation tokens no longer share the admin token's lifetime. An impersonated session is used like any other, long transfers included, and fifteen minutes cut those off. They now last as long as a token from signing in, or impersonation_ttl.

Commit:cfe0d1e
Author:Gianmaria Del Monte
Committer:Gianmaria Del Monte

Expose admin status and impersonation over HTTP Clients that only speak the public HTTPS surface cannot reach the Admin API, which is gRPC on its own listener. A new admin HTTP service gives them the part they need: GET /admin/status says whether the caller is an admin, and POST /admin/impersonate returns a token acting as another user. Impersonate steps the caller up and impersonates in one request, so the admin token never leaves the server; both steps are audited as before, with a reason if the client gives one. Status is backed by a new CheckAdmin RPC that mints nothing, so asking leaves no audit trail. Impersonation tokens no longer share the admin token's lifetime. An impersonated session is used like any other, long transfers included, and fifteen minutes cut those off. They now last as long as a token from signing in, or impersonation_ttl.

Commit:f75964b
Author:Gianmaria Del Monte

Expose admin status and impersonation over HTTP Clients that only speak the public HTTPS surface cannot reach the Admin API, which is gRPC on its own listener. A new admin HTTP service gives them the part they need: GET /admin/status says whether the caller is an admin, and POST /admin/impersonate returns a token acting as another user. Impersonate steps the caller up and impersonates in one request, so the admin token never leaves the server; both steps are audited as before, with a reason if the client gives one. Status is backed by a new CheckAdmin RPC that mints nothing, so asking leaves no audit trail. Impersonation tokens no longer share the admin token's lifetime. An impersonated session is used like any other, long transfers included, and fifteen minutes cut those off. They now last as long as a token from signing in, or impersonation_ttl.

Commit:a786472
Author:Jesse Geens
Committer:GitHub

Feature/admin api (#5773) * Add the Admin API and control channel protobuf definitions * Add the invocation framework, admin scope and registry selection support * Host a per-process control channel and register service instances by node id * Add the admin gRPC service, its loader wiring and the reva admin CLI * Document the Admin API and add its changelog * Serve admin local root over a Unix socket authenticated by OS credentials * Register serverless services on the control channel by control-address node id * Buffer recent log lines in memory for the Admin API to read * Add streaming invocations and the control InvokeStream RPC * Expose recent logs as a built-in service invocation * Read and follow service logs with reva admin logs * Tag request logs with their service and user so admin logs finds them * Trace a request or a user across the fleet with reva admin trace * Report build information through a built-in version invocation * Dump goroutine stacks with reva admin stack * Report and set a process's log level at runtime with reva admin logs level * Diff a service's config across instances with reva admin config -diff * Move the reva admin CLI into its own cmd/reva/admin package * Reset a service's log level back to its configured value with reva admin logs level reset * Take instances out of rotation at runtime with reva admin services drain/enable * Skip the user-group lookup for admin tokens so local-root fan-out works under skip_user_groups_in_token * Report in-flight request activity so an operator knows when a drained instance has quiesced * Give admin subcommands a real -h synopsis and services a grouped subcommand guide * Interact with the jobs runner through typed reva admin jobs API methods over the invoke channel * Keep a job run's start time on its terminal status write * Report the reva version in the version invocation * Fix protolint issues in the admin and control protobufs * Updated doc * Added further clarification comments --------- Co-authored-by: Gianmaria Del Monte <g.macmount@gmail.com> Co-authored-by: Giuseppe Lo Presti <giuseppe.lopresti@cern.ch>

Commit:6e6d92a
Author:Gianmaria Del Monte
Committer:Gianmaria Del Monte

Fix protolint issues in the admin and control protobufs

Commit:3e5d3cc
Author:Gianmaria Del Monte
Committer:Gianmaria Del Monte

Interact with the jobs runner through typed reva admin jobs API methods over the invoke channel

Commit:0039085
Author:Gianmaria Del Monte
Committer:Gianmaria Del Monte

Read and follow service logs with reva admin logs

Commit:8088e9c
Author:Gianmaria Del Monte
Committer:Gianmaria Del Monte

Add streaming invocations and the control InvokeStream RPC

Commit:b8f1c69
Author:Gianmaria Del Monte
Committer:Gianmaria Del Monte

Add the Admin API and control channel protobuf definitions

Commit:5a88060
Author:Gianmaria Del Monte
Committer:GitHub

Fix protolint issues in the admin and control protobufs

Commit:02fb9a7
Author:Gianmaria Del Monte
Committer:GitHub

Interact with the jobs runner through typed reva admin jobs API methods over the invoke channel

Commit:f048915
Author:Gianmaria Del Monte
Committer:GitHub

Read and follow service logs with reva admin logs

Commit:5762522
Author:Gianmaria Del Monte
Committer:GitHub

Add streaming invocations and the control InvokeStream RPC

Commit:4ef4aff
Author:Gianmaria Del Monte
Committer:GitHub

Add the Admin API and control channel protobuf definitions

Commit:c769a03
Author:Gianmaria Del Monte
Committer:Jesse Geens

Fix protolint issues in the admin and control protobufs

Commit:ce454cf
Author:Gianmaria Del Monte
Committer:Jesse Geens

Interact with the jobs runner through typed reva admin jobs API methods over the invoke channel

Commit:92e49d2
Author:Gianmaria Del Monte
Committer:Jesse Geens

Read and follow service logs with reva admin logs

Commit:f7b152e
Author:Gianmaria Del Monte
Committer:Jesse Geens

Add streaming invocations and the control InvokeStream RPC

Commit:b318d63
Author:Gianmaria Del Monte
Committer:Jesse Geens

Add the Admin API and control channel protobuf definitions

Commit:8d1b4ab
Author:Giuseppe Lo Presti
Committer:GitHub

Pass lock metadata on uploads + use upstream EOS GRPC bindings (#4514)

The documentation is generated from this commit.

Commit:d3d77c7
Author:Giuseppe Lo Presti

Updated copyright

Commit:084c1b5
Author:Hugo Labrador
Committer:GitHub

New observability + general refactor of http/grpc clients (#4166) * remove unused fs and tracing * add helloworld example and fix auth logic to bail out early * remove hack on appctx and add traceid * configurable prom collectors * grpc reflection working * wire http traffic * intrument outgoing grpc calls * add stuff * merge appctx and ctx * refactor rhttp to httpclient * tidy go.mod * remove drone tests * add changelog * fix test * go 1.21 * pass tests * fix sql tests * go fmt * more linters * make all linters happy * update docs * add back ceph example * remove otelhttp library * remove files and add tests * align with upstream

Commit:605cec4
Author:Miroslav Bauer
Committer:GitHub

Bump the Copyright date to 2023 (#3584) * Bump the Copyright date to 2023

Commit:1e612bc
Author:Gianmaria Del Monte
Committer:jkoberg

EOS grpc fixes (#3420) * return inode in fileinfo * fix log * fix eos grpc parsing * stat as a root * workaround for inode (revert me) * set parent id in eosfs * Revert "stat as a root" This reverts commit 81ce7b3e66f79d2401549d8ec67c1fa15a187f7b. * set storage id to parent id in storage provider * fix file path * clean path returned by eos * set xattrs for lock as root * fix key when setting attribute * stat as root * Revert "stat as root" This reverts commit e865e6e2f8d75d3759f2e3e0c8ca657a2c6ade6b. * trim prefix for user attrs * do not filter sys attrs * fix add acl * fix initiate file upload reference resolution * fix initiate file upload * Revert "fix initiate file upload" This reverts commit 265d09187d3ab4d646ace20df2ceaf925788e39f. * set sys acl as root * workaround for adding acl * fix unset attr * unset lock as root * Avoid crash when getting checksum in a stat request * fix * add changelog * fix linter * fix license Co-authored-by: Fabrizio Furano <furano@cern.ch>

Commit:f4ad966
Author:Gianmaria Del Monte
Committer:jkoberg

Implementation of CS3 Lock API for EOS storage driver (#2444)

Commit:48a2870
Author:Gianmaria Del Monte
Committer:GitHub

EOS grpc fixes (#3420) * return inode in fileinfo * fix log * fix eos grpc parsing * stat as a root * workaround for inode (revert me) * set parent id in eosfs * Revert "stat as a root" This reverts commit 81ce7b3e66f79d2401549d8ec67c1fa15a187f7b. * set storage id to parent id in storage provider * fix file path * clean path returned by eos * set xattrs for lock as root * fix key when setting attribute * stat as root * Revert "stat as root" This reverts commit e865e6e2f8d75d3759f2e3e0c8ca657a2c6ade6b. * trim prefix for user attrs * do not filter sys attrs * fix add acl * fix initiate file upload reference resolution * fix initiate file upload * Revert "fix initiate file upload" This reverts commit 265d09187d3ab4d646ace20df2ceaf925788e39f. * set sys acl as root * workaround for adding acl * fix unset attr * unset lock as root * Avoid crash when getting checksum in a stat request * fix * add changelog * fix linter * fix license Co-authored-by: Fabrizio Furano <furano@cern.ch>

Commit:af8fe04
Author:Vasco Guita
Committer:Gianmaria Del Monte

Migrate the BuildOnly job from Drone to GitHub Actions

Commit:d25a3a7
Author:Gianmaria Del Monte
Committer:GitHub

Implementation of CS3 Lock API for EOS storage driver (#2444)

Commit:2ec4ae6
Author:Fabrizio Furano
Committer:GitHub

Implement rollback to version (#1927)

Commit:c95ddaf
Author:Ishank Arora
Committer:GitHub

Generate updated protobuf bindings for EOS GRPC (#1916)

Commit:692f38f
Author:Fabrizio Furano
Committer:GitHub

EOS GRPC interface (#1471)

Commit:73f1c7b
Author:Ishank Arora
Committer:GitHub

Add FindAcceptedUsers method to OCM Invite API (#1527)

Commit:bd7234e
Author:Samuel Alfageme
Committer:GitHub

Bump the Copyright in the header to 2021 (#1397)

Commit:655c9ba
Author:Fabrizio Furano
Committer:GitHub

Progress with the eosgrpc client (#1154) Co-authored-by: Ishank Arora <ishank011@gmail.com>

Commit:07ab188
Author:Phil Davis
Committer:GitHub

Change percentagused to percentageused (#903)

Commit:e8f1815
Author:Phil Davis
Committer:GitHub

Fix minor typos (#898)

Commit:0e74029
Author:Fabrizio Furano
Committer:GitHub

eos grpc driver (#664)

Commit:0dbce24
Author:Hugo G. Labrador
Committer:GitHub

Update license year to 2020 (#504)

Commit:f3c5618
Author:Hugo G. Labrador
Committer:GitHub

build: remove vendor modules (#465)

Commit:02e4953
Author:Hugo G. Labrador
Committer:GitHub

vendor deps for network isolated builds (#308) * vendor deps for network isolated builds * clean build * improve ci * speed up build

Commit:9db3db0
Author:Hugo G. Labrador
Committer:GitHub

Gateway+metadata (#289) * Add metadata support * Add gateway as required element of the deployment * New code layout enforcing Go best practices for encapsulation * Support for multiple authentication backends * New user provider grpc service