CluPilotCloud/app/Provisioning/Jobs/PurgeHost.php

62 lines
2.0 KiB
PHP

<?php
namespace App\Provisioning\Jobs;
use App\Models\Host;
use App\Models\VpnPeer;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\InteractsWithQueue;
use Illuminate\Queue\SerializesModels;
use Illuminate\Support\Facades\Cache;
/**
* Finalizes host removal off the web request: deletes each run under its runner
* lock (waiting for any in-flight step to finish rather than racing it), then
* removes the WireGuard peer and the host record. Runs on the provisioning queue.
*/
class PurgeHost implements ShouldQueue
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
public $tries = 1;
public $timeout = 2200;
public function __construct(public string $uuid)
{
$this->onConnection('provisioning');
$this->onQueue('provisioning');
}
public function handle(): void
{
$host = Host::query()->where('uuid', $this->uuid)->first();
if ($host === null) {
return;
}
foreach ($host->runs()->get() as $run) {
// Block until the runner lock is free (a long step may hold it for up
// to the step timeout), then delete — cascades events + resources.
Cache::lock('run:'.$run->uuid, 2200)->block(2100, fn () => $run->delete());
}
if (filled($host->wg_pubkey)) {
// Tombstone the console's view of this peer as well. The FK only
// nulls host_id, which would leave an enabled-but-absent row behind:
// shown forever as "wird angewendet", and re-enabling it would put a
// deleted host's key back on the hub. Soft-deleting hands it to the
// same machinery every other revocation uses — the removal below
// clears the tombstone, and a sync retries if that removal is lost.
VpnPeer::query()->where('public_key', $host->wg_pubkey)->delete();
RemoveWireguardPeer::dispatch($host->wg_pubkey);
}
$host->delete();
}
}