f77023db1d
test / integration-docker (pull_request) Successful in 11s
test / unit (pull_request) Successful in 43s
lint / lint (push) Successful in 56s
test / integration-firecracker (pull_request) Successful in 3m19s
test / coverage (pull_request) Successful in 19s
test / publish-infra (pull_request) Has been skipped
tracker-policy-pr / check-pr (pull_request) Successful in 7s
Separate the gateway (data plane) from the orchestrator (control plane) at the
module level. The gateway runtime files move out of the package root — and the
backend-neutral Gateway lifecycle ABC + GATEWAY_* constants move out of
orchestrator/ — into a new bot_bottle/gateway/ package:
gateway/__init__.py (was orchestrator/gateway.py: Gateway ABC + consts
+ rotate_gateway_ca)
gateway/gateway_init.py (the PID-1 daemon supervisor)
gateway/egress_addon.py, egress_addon_core.py, egress_dlp_config.py,
dlp_detectors.py (the egress mitmproxy daemon)
gateway/git_http_backend.py (the git-http daemon)
gateway/git_gate_render.py (the git-gate pre-receive rendering)
gateway/supervise_server.py (the supervise MCP daemon)
gateway/policy_resolver.py (the data-plane control-plane RPC client)
orchestrator/ now holds only control-plane files. The shared plan/types/auth
layer (egress.py=EgressPlan, git_gate.py=GitGatePlan, supervise.py,
supervise_types.py, control_auth.py) and the launch-time git-gate provisioning
helpers stay at root, so orchestrator/ and backend/ still own them.
Because these daemons are invoked as `python3 -m bot_bottle.<name>`, loaded flat
by mitmproxy, and referenced in Dockerfile.gateway, the move updates more than
Python imports: the `-m` invocations (firecracker/macOS infra scripts), the
Dockerfile.gateway addon shim + ENTRYPOINT, gateway_init's _DAEMONS module
paths, and the git-gate CGI heredocs all now point at bot_bottle.gateway.*.
No behavior change; full unit suite green (2251).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
55 lines
1.7 KiB
Python
55 lines
1.7 KiB
Python
"""Shared base class for host-side egress apply across backends.
|
|
|
|
Each backend subclasses EgressApplicator and overrides _signal_bundle_reload
|
|
with the backend-specific kill command.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
from abc import ABC, abstractmethod
|
|
from pathlib import Path
|
|
|
|
from ..bottle_state import egress_state_dir
|
|
from ..egress import EGRESS_ROUTES_FILENAME
|
|
from ..gateway.egress_addon_core import LOG_OFF, load_config
|
|
|
|
|
|
class EgressApplyError(RuntimeError):
|
|
pass
|
|
|
|
|
|
class EgressApplicator(ABC):
|
|
def apply_routes_change(self, slug: str, content: str) -> tuple[str, str]:
|
|
"""Persist `content` to the live routes file and reload egress."""
|
|
self.validate_routes_content(content)
|
|
routes_path = self._routes_path(slug)
|
|
routes_path.parent.mkdir(parents=True, exist_ok=True)
|
|
before = routes_path.read_text(encoding="utf-8") if routes_path.exists() else ""
|
|
routes_path.write_text(content, encoding="utf-8")
|
|
routes_path.chmod(0o600)
|
|
self._signal_bundle_reload(slug)
|
|
return before, content
|
|
|
|
@staticmethod
|
|
def validate_routes_content(content: str) -> None:
|
|
try:
|
|
config = load_config(content)
|
|
except ValueError as e:
|
|
raise EgressApplyError(
|
|
f"proposed routes.yaml is not valid: {e}"
|
|
) from e
|
|
if config.log != LOG_OFF:
|
|
raise EgressApplyError(
|
|
"proposed routes.yaml must not change egress logging"
|
|
)
|
|
|
|
@staticmethod
|
|
def _routes_path(slug: str) -> Path:
|
|
return egress_state_dir(slug) / EGRESS_ROUTES_FILENAME
|
|
|
|
@abstractmethod
|
|
def _signal_bundle_reload(self, slug: str) -> None: ...
|
|
|
|
|
|
__all__ = ["EgressApplicator", "EgressApplyError"]
|