mirror of
https://github.com/trustgraph-ai/trustgraph.git
synced 2026-06-10 23:35:14 +02:00
Workspace identity is now determined by queue infrastructure instead of message body fields, closing a privilege-escalation vector where a caller could spoof workspace in the request payload. - Add WorkspaceProcessor base class: discovers workspaces from config at startup, creates per-workspace consumers (queue:workspace), and manages consumer lifecycle on workspace create/delete events - Roll out to librarian, flow-svc, knowledge cores, and config-svc - Config service gets a dual-queue regime: a system queue for cross-workspace ops (getvalues-all-ws, bootstrapper writes to __workspaces__) and per-workspace queues for tenant-scoped ops, with workspace discovery from its own Cassandra store - Remove workspace field from request schemas (FlowRequest, LibrarianRequest, KnowledgeRequest, CollectionManagementRequest) and from DocumentMetadata / ProcessingMetadata — table stores now accept workspace as an explicit parameter - Strip workspace encode/decode from all message translators and gateway serializers - Gateway enforces workspace existence: reject requests targeting non-existent workspaces instead of routing to queues with no consumer - Config service provisions new workspaces from __template__ on creation - Add workspace lifecycle hooks to AsyncProcessor so any processor can react to workspace create/delete without subclassing WorkspaceProcessor
65 lines
No EOL
1.3 KiB
Python
65 lines
No EOL
1.3 KiB
Python
"""
|
|
Dump out TrustGraph processor states.
|
|
"""
|
|
|
|
import os
|
|
import requests
|
|
import argparse
|
|
|
|
default_metrics_url = "http://localhost:8088/api/metrics"
|
|
DEFAULT_TOKEN = os.getenv("TRUSTGRAPH_TOKEN", None)
|
|
|
|
def dump_status(metrics_url, token=None):
|
|
|
|
url = f"{metrics_url}/query?query=processor_info"
|
|
|
|
headers = {}
|
|
if token:
|
|
headers["Authorization"] = f"Bearer {token}"
|
|
|
|
resp = requests.get(url, headers=headers)
|
|
|
|
obj = resp.json()
|
|
|
|
tbl = [
|
|
[
|
|
m["metric"].get("processor", m["metric"]["job"]),
|
|
"\U0001f49a"
|
|
]
|
|
for m in obj["data"]["result"]
|
|
]
|
|
|
|
for row in tbl:
|
|
print(f" {row[0]:30} {row[1]}")
|
|
|
|
def main():
|
|
|
|
parser = argparse.ArgumentParser(
|
|
prog='tg-show-processor-state',
|
|
description=__doc__,
|
|
)
|
|
|
|
parser.add_argument(
|
|
'-m', '--metrics-url',
|
|
default=default_metrics_url,
|
|
help=f'Metrics URL (default: {default_metrics_url})',
|
|
)
|
|
|
|
parser.add_argument(
|
|
'-t', '--token',
|
|
default=DEFAULT_TOKEN,
|
|
help=f'Bearer token for authentication (default: TRUSTGRAPH_TOKEN env var)',
|
|
)
|
|
|
|
args = parser.parse_args()
|
|
|
|
try:
|
|
|
|
dump_status(args.metrics_url, args.token)
|
|
|
|
except Exception as e:
|
|
|
|
print("Exception:", e, flush=True)
|
|
|
|
if __name__ == "__main__":
|
|
main() |