Notes the first-load suspension event - #119
Merged
Merged
Conversation
Encryptor.Telemetry's "Suspension changes" section listed three occasions for [:encryptor, :suspension, :changed] under a shared store. The code emits on a fourth: the refresh that loads the view emits action :refresh, outcome :ok even when the store's set is empty, because until then the vault denies every scope. The section now names that refresh, including the reload after a restarted Lifecycle. A dated Note on ADR-0009 reads the fourth Consequences bullet as naming Envelope.scope_ref/2, which is what encryptor_ecto's key store docs and code call; the bullet named tenant_ref/2, removed in 0.5.0. Refs: enc-jdix
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Wording only: no code, no event, no public name and no wire spelling changes.
The first-load suspension event
Encryptor.Telemetry's "Suspension changes" section listed three occasions for[:encryptor, :suspension, :changed]under a shared:suspension_store. The code emits on one more: the refresh that loads the view emitsaction: :refresh,outcome: :okand the loadedcounteven when the store's set is empty, because until that load the vault denies every scope. The section now names that refresh, both as the first successful refresh after the vault starts and as the first one after a restartedEncryptor.Vault.Lifecyclehas recreated the view. ADR-0010's accepted Note of 2026-09-24, section 2, already reads decision 8's list as including this occasion.ADR-0009, fourth Consequences bullet
The bullet says encryptor_ecto's key store defines its reference as
Envelope.tenant_ref/2of the host's selector. That function was renamed by decision 3 and shipped in 0.5.0 with no alias. A dated Note appended at the foot of the record reads the bullet as namingEnvelope.scope_ref/2; the bullet itself is left as written.Review (in-turn)
Re-read the diff against the bead's acceptance ("an appended dated Note on ADR-0009 for the bullet; the moduledoc names the first-load emission"). Checked by anchor on this branch:
Encryptor.Vault.Suspension.refresh/2emits whenever the privateapply_view/2answers true, andapply_view/2answers true for a view it has just renamed from the unloaded name, whatever its membership;Encryptor.Vault.Suspension.suspended?/2looks up only the served name and, under a shared store, answers suspended for every scope while that name is absent;Encryptor.Vault.Lifecycle's init callsEncryptor.Vault.Suspension.create/1, which makes a shared store's view under the unloaded name, and the vault supervisor restarts children:one_for_one, so a restartedLifecycleleaves a view the next refresh loads again; thecountmeasurement is the loaded view's size. In encryptor_ecto at4722b05(read only):Encryptor.Ecto.KeyStore's moduledoc section "The table" defines thetenant_refcolumn asEncryptor.Envelope.scope_ref/2of the host's selector, and its privatescope_ref/2callsEnvelope.scope_ref/2.Encryptor.Envelopehas notenant_ref/2. The ADR diff removes no line; the Note is after the record's last heading and carries no status.Provenance
changelog.d/README.md.Gate
mix qualitygreen on the committed tree rebased onto main (all stages, Docs and Doc links included; 673 of 673 tests).Refs: enc-jdix