feat(mesh): fleet role + shared config/presence KV (Phase 2)

- add static 'role' (authority|follower) to NodeConfig/CastleConfig, wired from
  castle.yaml through the registry to the mesh wire; civil pinned authority
- castle-presence: TTL KV bucket each node renews (churn signal); delete-on-stop
- castle-config: authority-gated get/put + change-watch SSE (follower reconcile
  hook hangs off it)
- bound the NATS drain on stop() so shutdown can't hang
- tests: role config/registry round-trip, wire round-trip, role write-gating

Single-node verified; follower reconcile pending the second node.
This commit is contained in:
2026-07-07 05:03:07 -07:00
parent 6c00a9d33c
commit c67c06d8e6
9 changed files with 211 additions and 10 deletions

View File

@@ -95,6 +95,18 @@ class TestRegistrySerialization:
assert bare.schedule is None
assert bare.managed is False
def test_node_role_preserved(self) -> None:
reg = NodeRegistry(
node=NodeConfig(hostname="civil", role="authority"), deployed={}
)
restored = json_to_registry(registry_to_json(reg))
assert restored.node.role == "authority"
def test_node_role_defaults_follower(self) -> None:
reg = NodeRegistry(node=NodeConfig(hostname="n"), deployed={})
restored = json_to_registry(registry_to_json(reg))
assert restored.node.role == "follower"
def test_no_secrets_in_payload(self) -> None:
"""env vars, run_cmd, and castle_root must never appear on the wire."""
original = _make_registry()