1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
//! Multi-tenancy infrastructure: pool factory, executor construction, health monitoring.
use ;
use Executor;
use Result;
pub use ;
/// Type-erased async factory for creating tenant executors.
///
/// Stored in `AppState` so that the management API handler (`upsert_tenant_handler`)
/// can build an `Executor` without requiring `A: FromPoolConfig` as a bound on
/// the route handler or the `Server` impl. The factory is set once at server
/// startup by code that knows the concrete adapter type.
pub type TenantExecutorFactory = ;
/// Create a `TenantExecutorFactory` for an adapter that implements `FromPoolConfig`.
///
/// Captures the `FromPoolConfig` bound at construction time so that the factory
/// can be stored as a type-erased closure in `AppState`.
///
/// The first argument is the tenant key, used for schema isolation naming.
///
/// `database_tls` is the server's own `[database_tls]` setting, stamped onto every
/// tenant pool here rather than read from the registration request. Tenant pool
/// configuration arrives as an admin-API request body, so the transport security of
/// a tenant's connections must be decided by the operator who configured the server,
/// not by the payload that registers the tenant (#801). This mirrors the way
/// `search_path` is recomputed rather than trusted.
///
/// `read_replica_policy` is stamped for the same reason (#957). A tenant names its
/// own replica URLs — topology, like its connection string — but not the pin
/// window, staleness budget or probe cadence those replicas are routed under: a
/// registration that could send its own `max_lag` would be choosing how stale its
/// reads may be, against a server whose operator already decided.
///
/// `vector_scan` is stamped for the third time in the same shape (#1116): whether a
/// filtered similarity search may quietly return fewer rows than it was asked for
/// is the operator's answer, not the registration payload's.
///
/// The server's [`RuntimeConfig`](fraiseql_core::runtime::RuntimeConfig) is the fourth
/// (#1333), and it is deliberately **not** captured here like the three above. The
/// booting server rebuilds its executor after this factory is made —
/// `prepare_functions_runtime` installs the `before:mutation` gate and the
/// function-query resolver at serve time — so a snapshot taken now would be missing the
/// very gate #1327 exists for. The caller passes the live config per registration
/// instead, which is the same reason `search_path` is recomputed rather than trusted.