refactor(gateway): move DockerGateway to the backend layer, drop the dead standalone-gateway path
lint / lint (push) Successful in 54s
lint / lint (push) Successful in 54s
The `DockerGateway` container-lifecycle impl now lives in `backend/docker/gateway.py` (the shape backend gateway classes will share); `orchestrator/gateway.py` keeps only the backend-neutral pieces (the `Gateway` ABC, constants, `rotate_gateway_ca`). Delete the standalone-gateway path it was the only consumer of. `--gateway` on `python -m bot_bottle.orchestrator` was invoked nowhere — the production docker flow runs the gateway data plane inside the combined `bot-bottle-infra` container via `OrchestratorService`, never this class. Removing it takes with it `Orchestrator.ensure_gateway()` and the `gateway` ctor arg; `gateway_status()` becomes a stub reporting `configured: false` so the documented `GET /gateway` control-plane route keeps its contract. Fix a latent bug the move surfaced: `launch.py` read the shared gateway CA via `docker exec bot-bottle-orch-gateway`, a container the consolidated flow never creates — so the agent CA install was reaching a nonexistent name. Read it from `bot-bottle-infra` (INFRA_NAME) instead. Repoint the affected tests to the new module; drop the unit test + fake that covered the deleted standalone wiring. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -27,7 +27,6 @@ from datetime import datetime, timezone
|
||||
|
||||
from .broker import LaunchBroker, LaunchRequest, sign_request
|
||||
from .registry import DEFAULT_REAP_GRACE_SECONDS, BottleRecord, RegistryStore
|
||||
from .gateway import Gateway
|
||||
from ..supervise import (
|
||||
AuditEntry,
|
||||
COMPONENT_FOR_TOOL,
|
||||
@@ -72,12 +71,10 @@ class Orchestrator:
|
||||
registry: RegistryStore,
|
||||
broker: LaunchBroker,
|
||||
sign_secret: bytes,
|
||||
gateway: Gateway | None = None,
|
||||
) -> None:
|
||||
self.registry = registry
|
||||
self._broker = broker
|
||||
self._secret = sign_secret
|
||||
self._gateway = gateway
|
||||
# Per-bottle egress auth tokens (env_name -> value), keyed by bottle_id.
|
||||
# Held **in memory only** — never written to the registry DB — so the
|
||||
# gateway can inject each bottle's upstream credential without secrets
|
||||
@@ -383,22 +380,15 @@ class Orchestrator:
|
||||
|
||||
# --- consolidated gateway ----------------------------------------------
|
||||
|
||||
def ensure_gateway(self) -> None:
|
||||
"""Ensure the single per-host gateway is built and up (idempotent).
|
||||
No-op when no gateway is configured."""
|
||||
if self._gateway is not None:
|
||||
self._gateway.ensure_built()
|
||||
self._gateway.ensure_running()
|
||||
|
||||
def gateway_status(self) -> dict[str, object]:
|
||||
"""Report the shared gateway for the control plane / console."""
|
||||
if self._gateway is None:
|
||||
return {"configured": False}
|
||||
return {
|
||||
"configured": True,
|
||||
"name": self._gateway.name,
|
||||
"running": self._gateway.is_running(),
|
||||
}
|
||||
"""Report the shared gateway for the control plane / console.
|
||||
|
||||
The orchestrator no longer owns a standalone gateway lifecycle — the
|
||||
consolidated flow runs the gateway data plane inside the per-host infra
|
||||
container/VM (see `backend/*/gateway`), so this reports `configured:
|
||||
false`. Retained for the documented `GET /gateway` control-plane
|
||||
contract."""
|
||||
return {"configured": False}
|
||||
|
||||
|
||||
__all__ = ["Orchestrator"]
|
||||
|
||||
Reference in New Issue
Block a user