Skip to content

Notes the first-load suspension event - #119

Merged
johnnyt merged 1 commit into
mainfrom
enc-jdix-adr-0009-and-first-load-event-docs
Sep 30, 2026
Merged

johnnyt merged 1 commit into
mainfrom
enc-jdix-adr-0009-and-first-load-event-docs

Conversation

@johnnyt

@johnnyt johnnyt commented Sep 30, 2026

Copy link
Copy Markdown
Member

Wording only: no code, no event, no public name and no wire spelling changes.

The first-load suspension event

Encryptor.Telemetry's "Suspension changes" section listed three occasions for [:encryptor, :suspension, :changed] under a shared :suspension_store. The code emits on one more: the refresh that loads the view emits action: :refresh, outcome: :ok and the loaded count even when the store's set is empty, because until that load the vault denies every scope. The section now names that refresh, both as the first successful refresh after the vault starts and as the first one after a restarted Encryptor.Vault.Lifecycle has recreated the view. ADR-0010's accepted Note of 2026-09-24, section 2, already reads decision 8's list as including this occasion.

ADR-0009, fourth Consequences bullet

The bullet says encryptor_ecto's key store defines its reference as Envelope.tenant_ref/2 of the host's selector. That function was renamed by decision 3 and shipped in 0.5.0 with no alias. A dated Note appended at the foot of the record reads the bullet as naming Envelope.scope_ref/2; the bullet itself is left as written.

Review (in-turn)

Re-read the diff against the bead's acceptance ("an appended dated Note on ADR-0009 for the bullet; the moduledoc names the first-load emission"). Checked by anchor on this branch: Encryptor.Vault.Suspension.refresh/2 emits whenever the private apply_view/2 answers true, and apply_view/2 answers true for a view it has just renamed from the unloaded name, whatever its membership; Encryptor.Vault.Suspension.suspended?/2 looks up only the served name and, under a shared store, answers suspended for every scope while that name is absent; Encryptor.Vault.Lifecycle's init calls Encryptor.Vault.Suspension.create/1, which makes a shared store's view under the unloaded name, and the vault supervisor restarts children :one_for_one, so a restarted Lifecycle leaves a view the next refresh loads again; the count measurement is the loaded view's size. In encryptor_ecto at 4722b05 (read only): Encryptor.Ecto.KeyStore's moduledoc section "The table" defines the tenant_ref column as Encryptor.Envelope.scope_ref/2 of the host's selector, and its private scope_ref/2 calls Envelope.scope_ref/2. Encryptor.Envelope has no tenant_ref/2. The ADR diff removes no line; the Note is after the record's last heading and carries no status.

Provenance

  • No changelog fragment: documentation is excluded by changelog.d/README.md.
  • No test added: the change is prose, and the emission it describes is already relied on by the suspension store tests' first-refresh helper.

Gate

mix quality green on the committed tree rebased onto main (all stages, Docs and Doc links included; 673 of 673 tests).

Refs: enc-jdix

Encryptor.Telemetry's "Suspension changes" section listed three
occasions for [:encryptor, :suspension, :changed] under a shared store.
The code emits on a fourth: the refresh that loads the view emits
action :refresh, outcome :ok even when the store's set is empty,
because until then the vault denies every scope. The section now names
that refresh, including the reload after a restarted Lifecycle.

A dated Note on ADR-0009 reads the fourth Consequences bullet as naming
Envelope.scope_ref/2, which is what encryptor_ecto's key store docs and
code call; the bullet named tenant_ref/2, removed in 0.5.0.

Refs: enc-jdix
@johnnyt
johnnyt merged commit 32234d6 into main Sep 30, 2026
1 check passed
@johnnyt
johnnyt deleted the enc-jdix-adr-0009-and-first-load-event-docs branch September 30, 2026 06:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant