feat(adminui): manual failover control on the cluster redundancy page

Claude-Session: https://claude.ai/code/session_01GASWkNEi68FSCtvr6rLoEW
This commit is contained in:
Joseph Doherty
2026-07-22 06:44:44 -04:00
parent 69b697bc3e
commit d8a85c3d89
4 changed files with 442 additions and 2 deletions
@@ -1,10 +1,16 @@
@page "/clusters/{ClusterId}/redundancy"
@attribute [Authorize(Policy = AdminUiPolicies.AuthenticatedRead)]
@rendermode RenderMode.InteractiveServer
@using Microsoft.AspNetCore.Authorization
@using Microsoft.EntityFrameworkCore
@using ZB.MOM.WW.OtOpcUa.AdminUI.Redundancy
@using ZB.MOM.WW.OtOpcUa.Configuration
@using ZB.MOM.WW.OtOpcUa.Configuration.Entities
@using ZB.MOM.WW.OtOpcUa.ControlPlane.Redundancy
@inject IDbContextFactory<OtOpcUaConfigDbContext> DbFactory
@inject IManualFailoverService FailoverService
@inject AuthenticationStateProvider AuthState
@inject IAuthorizationService AuthorizationService
@if (!_loaded)
{
@@ -45,6 +51,67 @@ else
</div>
</section>
<section class="panel rise mt-3" style="animation-delay:.11s">
<div class="panel-head">Live redundancy</div>
<div style="padding:1rem">
<div class="kv">
<span class="k">Driver Primary</span>
<span class="v mono">@(_failover.Snapshot?.PrimaryAddress ?? "—")</span>
</div>
<div class="kv">
<span class="k">Up driver members</span>
<span class="v mono">
@(_failover.Snapshot is { DriverAddresses.Count: > 0 } s
? string.Join(", ", s.DriverAddresses)
: "—")
</span>
</div>
<p class="text-muted small mt-2 mb-0">
Read live from cluster state on this node. <strong>Mesh-wide scope:</strong> the Primary is
elected once per Akka mesh, not per cluster row — in the current single-mesh topology this
acts on the whole mesh's Primary, which may be a node of another
<span class="mono">Cluster</span>. See <span class="mono">docs/Redundancy.md</span>.
</p>
<AuthorizeView Policy="@ManualFailoverPageModel.RequiredPolicy">
<Authorized>
<div class="mt-3">
<button class="btn btn-sm btn-outline-danger"
disabled="@(!_failover.CanFailOver)"
title="@(_failover.DisabledReason ?? "Gracefully move the driver Primary to its peer")"
@onclick="() => _failover.RequestFailover()">
Trigger failover
</button>
@if (_failover.DisabledReason is { } reason)
{
<span class="text-muted small ms-2">@reason</span>
}
</div>
@if (_failover.ConfirmOpen)
{
<div class="panel notice mt-3">
<strong>Fail over the driver Primary?</strong>
<ul class="mb-2 mt-2">
<li><span class="mono">@(_failover.Snapshot?.PrimaryAddress)</span> leaves the cluster and its process restarts.</li>
<li>Its peer becomes Primary and advertises <span class="mono">ServiceLevel</span> 250.</li>
<li>Connected OPC UA clients re-select the new Primary.</li>
</ul>
<button class="btn btn-sm btn-danger" @onclick="ConfirmFailoverAsync">Confirm failover</button>
<button class="btn btn-sm btn-outline-secondary ms-2" @onclick="() => _failover.CancelFailover()">Cancel</button>
</div>
}
</Authorized>
</AuthorizeView>
@if (_failover.StatusMessage is { } msg)
{
<div class="mt-3 @(_failover.StatusIsError ? "text-danger" : "text-success")">@msg</div>
}
</div>
</section>
<section class="panel rise mt-3" style="animation-delay:.14s">
<div class="panel-head">Node service-level configuration</div>
@if (_nodes is null || _nodes.Count == 0)
@@ -91,8 +158,16 @@ else
private ServerCluster? _cluster;
private List<ClusterNode>? _nodes;
// Everything consequential about the failover control (peer guard, confirm flow, outcome text)
// lives in this pure model rather than in the markup — the repo has no bUnit, so logic left in a
// .razor is verified only by driving the page. Covered by ManualFailoverPageModelTests.
private ManualFailoverPageModel _failover = default!;
protected override async Task OnInitializedAsync()
{
_failover = new ManualFailoverPageModel(FailoverService);
_failover.Refresh();
await using var db = await DbFactory.CreateDbContextAsync();
_cluster = await db.ServerClusters.AsNoTracking()
.FirstOrDefaultAsync(c => c.ClusterId == ClusterId);
@@ -105,4 +180,22 @@ else
}
_loaded = true;
}
/// <summary>
/// Defense-in-depth: the button is FleetAdmin-gated in markup, but this handler runs on the
/// server circuit — re-check the policy before bouncing a production node (the same pattern the
/// certificate-store actions use).
/// </summary>
private async Task ConfirmFailoverAsync()
{
var authState = await AuthState.GetAuthenticationStateAsync();
if (!(await AuthorizationService.AuthorizeAsync(
authState.User, null, ManualFailoverPageModel.RequiredPolicy)).Succeeded)
{
_failover.CancelFailover();
return;
}
await _failover.ConfirmFailoverAsync(authState.User.Identity?.Name ?? "system");
}
}