Files
arcadia-cloud/priv/repo/migrations/20260520130000_create_drift.exs
Giuliano Silvestro 445b7b60d4 Phase 2: drift detection
Compares cloud_provisioned.spec (what we asked DO for) against the live
cloud_resources row (what DO actually has). Any divergence becomes an
operator-resolvable drift record.

cloud_drift table: one row per drifted field. status open/accepted/
reverted/stale. Partial unique index keeps at most one OPEN drift per
(resource, field); resolved rows are retained as history.

ArcadiaCloud.Drift context:
- detect_all/0 — sweeps every provisioned resource. Per field in spec,
  resolves the actual value (top-level schema field first, then attrs),
  compares with loose equality (stringified scalars; lists as sets so
  JSON round-trips don't false-positive). Mismatches upsert a cloud_drift
  row + emit a drift_detected event in the resource event log.
- close_stale_drift — an open drift whose field no longer mismatches
  (fixed elsewhere) closes as "stale" on the next sweep.
- accept_drift/2 — the live value becomes the new desired-state: parent
  cloud_provisioned.spec is updated, spec_version bumped, drift closed
  "accepted". Revert (mutating live infra back to spec) is intentionally
  NOT here — it needs a saga and lands with the droplet-resize work.

DriftDetectionWorker — Oban cron at :20 past the hour, offset past the
:15 resource syncs so it compares against fresh inventory.

Provisioning.record_provisioned/3 — populates cloud_provisioned desired-
state (upsert on resource_id, bumps spec_version). Future provisioning
sagas call this; for now it's how drift gets something to detect.

API (platform_admin only):
- GET  /api/v1/drift            — open drift inbox
- POST /api/v1/drift/:id/accept — adopt live value as desired-state

Smoke verified: recorded a droplet's desired spec with a deliberately
wrong size_slug + a correct region; detect_all flagged only size_slug,
wrote the drift_detected event; accept updated the spec to the live
value and closed the drift; re-detect found zero drift.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-20 11:08:27 +10:00

36 lines
1.3 KiB
Elixir

defmodule ArcadiaCloud.Repo.Migrations.CreateDrift do
use Ecto.Migration
def change do
# One row per drifted field of a provisioned resource. The operator
# resolves each: "accept" (desired-state := actual) or "revert"
# (schedule a saga to put actual back to desired).
create table(:cloud_drift, primary_key: false) do
add :id, :binary_id, primary_key: true
add :resource_id, references(:cloud_resources, type: :binary_id, on_delete: :delete_all),
null: false
add :provisioned_id,
references(:cloud_provisioned, type: :binary_id, on_delete: :delete_all),
null: false
add :field, :string, null: false
add :expected, :map
add :actual, :map
add :status, :string, null: false, default: "open"
add :detected_at, :utc_datetime, null: false
add :resolved_at, :utc_datetime
add :resolved_by, :string
timestamps(type: :utc_datetime)
end
# At most one OPEN drift per (resource, field); resolved ones are history.
create unique_index(:cloud_drift, [:resource_id, :field],
where: "status = 'open'",
name: :cloud_drift_open_unique
)
create index(:cloud_drift, [:status])
create index(:cloud_drift, [:provisioned_id])
end
end