Files
arcadia-cloud/lib/arcadia_cloud/digital_ocean/client.ex
Giuliano Silvestro b1a124f044 Phase 2: first real DO write step — CreateDropletSnapshot
DigitalOcean.Client write methods:
- create_droplet_snapshot/3 — POST a snapshot action (async)
- get_droplet_action/3      — poll action status
- list_droplet_snapshots/2  — snapshots for a droplet
- delete_snapshot/2         — DELETE (used by compensation)
All use the "provisioning" token purpose.

Steps.CreateDropletSnapshot — the first saga step that touches real
infra:
- execute: deterministic snapshot name (arcadia-snap-<droplet>-<saga8>);
  checks context for a prior snapshot_id, then checks DO for a snapshot
  already carrying that name (crash-between-post-and-save recovery),
  then posts the action, polls to completion, finds the resulting
  snapshot, records snapshot_id + snapshot_name in context.
- compensate: deletes the snapshot; treats HTTP 404 as success.

Provisioning.snapshot_droplet/2 — convenience saga starter.

Two DO eventual-consistency gotchas surfaced + handled:
- After a snapshot action reports "completed", the snapshot lags a few
  seconds before appearing in /droplets/:id/snapshots. The step now
  retries the lookup (find_snapshot_with_retry, 12x5s) instead of
  failing with :snapshot_not_found_after_completion.
- Deletion has the same lag the other way — a deleted snapshot lingers
  in the listing briefly. compensate just trusts the DELETE 2xx/404;
  no post-delete verification needed.

Live smoke verified end-to-end against holyspiritbraypark.com:
[CreateDropletSnapshot, Fail] saga — the step created real snapshot
229305609, the Fail step triggered compensation, compensation deleted
the snapshot. Final: saga rolled_back, ledger
[create_droplet_snapshot: compensated, fail: failed], zero leftover on DO.

Test-harness note: smoke tests create sagas via Provisioning.create_saga
(no Oban enqueue) so a single manual Runner.perform/1 owns execution —
start_saga/1 enqueues an Oban job, and running both racing the same saga
corrupts the step ledger. Production only ever runs via Oban.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-20 08:38:35 +10:00

197 lines
6.3 KiB
Elixir

defmodule ArcadiaCloud.DigitalOcean.Client do
@moduledoc """
Thin Req wrapper over the DigitalOcean v2 API.
Token resolution: per-purpose, looked up via `ArcadiaCloud.DigitalOcean.Tokens`.
Phase 0/1: env var `DO_API_TOKEN`. Phase 2: from the secrets vault.
Paginated list endpoints stream all pages by default.
"""
alias ArcadiaCloud.DigitalOcean.Tokens
@base "https://api.digitalocean.com/v2"
@page_size 100
# ---- public ---------------------------------------------------------------
def list_droplets(opts \\ []), do: list_paginated("/droplets", "droplets", opts)
def list_projects(opts \\ []), do: list_paginated("/projects", "projects", opts)
def list_domains(opts \\ []), do: list_paginated("/domains", "domains", opts)
def list_volumes(opts \\ []), do: list_paginated("/volumes", "volumes", opts)
def list_floating_ips(opts \\ []), do: list_paginated("/floating_ips", "floating_ips", opts)
def list_snapshots(opts \\ []), do: list_paginated("/snapshots", "snapshots", opts)
def list_firewalls(opts \\ []), do: list_paginated("/firewalls", "firewalls", opts)
def list_load_balancers(opts \\ []), do: list_paginated("/load_balancers", "load_balancers", opts)
def list_droplet_backups(droplet_id, opts \\ []) do
list_paginated("/droplets/#{droplet_id}/backups", "backups", opts)
end
def list_droplet_snapshots(droplet_id, opts \\ []) do
list_paginated("/droplets/#{droplet_id}/snapshots", "snapshots", opts)
end
# ---- write actions --------------------------------------------------------
@doc """
Request a snapshot of a droplet. Returns {:ok, action} — the snapshot
is created asynchronously; poll `get_droplet_action/3` until the action
status is "completed".
"""
def create_droplet_snapshot(droplet_id, snapshot_name, opts \\ []) do
case request(:post, "/droplets/#{droplet_id}/actions",
body: %{type: "snapshot", name: snapshot_name},
purpose: opts[:purpose] || "provisioning"
) do
{:ok, %{"action" => action}} -> {:ok, action}
other -> other
end
end
def get_droplet_action(droplet_id, action_id, opts \\ []) do
case request(:get, "/droplets/#{droplet_id}/actions/#{action_id}",
purpose: opts[:purpose] || "provisioning"
) do
{:ok, %{"action" => action}} -> {:ok, action}
other -> other
end
end
def delete_snapshot(snapshot_id, opts \\ []) do
request(:delete, "/snapshots/#{snapshot_id}", purpose: opts[:purpose] || "provisioning")
end
# ---- billing --------------------------------------------------------------
def get_balance(opts \\ []) do
request(:get, "/customers/my/balance", purpose: opts[:purpose] || "billing")
end
def list_billing_history(opts \\ []) do
list_paginated("/customers/my/billing_history", "billing_history",
Keyword.put(opts, :purpose, opts[:purpose] || "billing"))
end
def get_invoice_summary(invoice_uuid, opts \\ []) do
request(:get, "/customers/my/invoices/#{invoice_uuid}/summary",
purpose: opts[:purpose] || "billing")
end
@doc """
Fetch the CSV body for an invoice. Returns {:ok, csv_string} | {:error, _}.
"""
def fetch_invoice_csv(invoice_uuid, opts \\ []) do
purpose = opts[:purpose] || "billing"
with {:ok, token} <- Tokens.fetch(purpose) do
case Req.request(
method: :get,
url: @base <> "/customers/my/invoices/#{invoice_uuid}/csv",
headers: [
{"authorization", "Bearer " <> token},
{"accept", "text/csv"}
],
retry: :transient,
max_retries: 3,
decode_body: false
) do
{:ok, %Req.Response{status: 200, body: body}} when is_binary(body) ->
{:ok, body}
{:ok, %Req.Response{status: status, body: body}} ->
{:error, {:http, status, body}}
{:error, e} ->
{:error, {:transport, e}}
end
end
end
def create_project(name, purpose, description \\ "", opts \\ []) do
body = %{
name: name,
purpose: purpose,
description: description,
environment: "Development"
}
request(:post, "/projects", body: body, purpose: opts[:purpose] || "provisioning")
|> case do
{:ok, %{"project" => project}} -> {:ok, project}
other -> other
end
end
def list_project_resources(project_id, opts \\ []) do
list_paginated("/projects/#{project_id}/resources", "resources", opts)
end
def assign_to_project(project_id, urns, opts \\ []) when is_list(urns) do
request(:post, "/projects/#{project_id}/resources",
body: %{resources: urns},
purpose: opts[:purpose] || "provisioning"
)
end
# ---- core -----------------------------------------------------------------
defp list_paginated(path, root_key, opts) do
purpose = opts[:purpose] || "sync_full"
do_paginate(path, root_key, purpose, [], 1)
end
defp do_paginate(path, root_key, purpose, acc, page) do
params = [page: page, per_page: @page_size]
case request(:get, path, params: params, purpose: purpose) do
{:ok, %{} = body} ->
items = Map.get(body, root_key, [])
new_acc = acc ++ items
if has_next?(body) do
do_paginate(path, root_key, purpose, new_acc, page + 1)
else
{:ok, new_acc}
end
err ->
err
end
end
defp has_next?(%{"links" => %{"pages" => %{"next" => _}}}), do: true
defp has_next?(_), do: false
defp request(method, path, opts) do
purpose = Keyword.fetch!(opts, :purpose)
with {:ok, token} <- Tokens.fetch(purpose) do
req_opts =
[
method: method,
url: @base <> path,
headers: [{"authorization", "Bearer " <> token}],
retry: :transient,
max_retries: 3
]
|> maybe_put(:params, opts[:params])
|> maybe_put(:json, opts[:body])
case Req.request(req_opts) do
{:ok, %Req.Response{status: status, body: body}} when status in 200..299 ->
{:ok, body}
{:ok, %Req.Response{status: status, body: body}} ->
{:error, {:http, status, body}}
{:error, exception} ->
{:error, {:transport, exception}}
end
end
end
defp maybe_put(opts, _key, nil), do: opts
defp maybe_put(opts, key, value), do: Keyword.put(opts, key, value)
end