pub enum IngressOwnerEffect {
Reassign {
machine: String,
ip_id: String,
},
Withdraw {
machine: String,
reason: String,
},
Refuse {
reason: String,
},
NoOp {
reason: String,
},
}Expand description
What should happen to public ingress, given an ingress_owner observation.
The two failover speeds W267 §Tier 1 names appear here as two variants:
Reassign is the intra-provider one (seconds, no DNS
propagation, no cert re-mint), Withdraw the
cross-provider one (pull the dead origin’s A record and let the survivors
take its share).
Variants§
Reassign
Move ip_id onto machine — the intra-provider failover.
Withdraw
Drop machine from the apex origin set — the cross-provider failover.
Consumed by cloud::reconciler::domain::public_origins’s
health-exclusion argument, which is why this carries a machine name and
not a record id: the DNS layer already knows how to turn a declared
machine into an address, and duplicating that here would be a second
answer to a question R859-F1 settled.
Refuse
Do nothing, and refuse to do it — positive grounds against acting.
Distinct from NoOp because it is worth saying: a
refusal means the world is in a state where the correct action is known
and deliberately not taken, which an operator watching a failover needs
to see. A NoOp is not news.
NoOp
Nothing to do.