// Package cluster defines the Cluster domain type — a configured Spark/YARN // endpoint pair plus authentication, SSL, rate-limit, and Spark-submit metadata. // // Cluster is the only entity persisted in this project besides the audit log. // It is the discovery root for the LLM agent: list_clusters returns the full // struct (minus the password) so the agent can resolve RM/SHS URLs, choose // the correct auth flavor, and respect the URL allowlist. package cluster import "time" // AuthType enumerates the YARN/Hadoop authentication flavors supported in v1. // // "none" — no credentials; public or pre-trusted clusters // "simple" — YARN SimpleAuth: appends ?user.name= to every request // "basic" — HTTP Basic; AuthUsername + AuthPassword (encrypted at rest) // // Kerberos is intentionally absent in v1; the deployment uses SimpleAuth. type AuthType string const ( AuthNone AuthType = "none" AuthSimple AuthType = "simple" AuthBasic AuthType = "basic" ) // Cluster is one configured Spark-on-YARN endpoint pair. // // Field semantics: // - SparkSubmitExecuteBin: absolute path to spark-submit (or spark2-submit); // exec.Command uses this binary directly, never the shell. // - IsActive: only active clusters are returned by LLM-facing list_clusters. // - AuthPassword: zero value ("") on Update means "do not touch the stored // password" — keeps the existing encrypted blob intact. // - URLAllowlist: extra glob patterns beyond the RM/SHS hosts; fetch_url // uses this to permit long-tail SHS endpoints the agent may construct. // - DefaultSubmitArgs: deprecated; no longer prepended by spark_submit // (post-7920dc9 the builder constructs argv from structured fields). // Kept for backward compatibility with the admin API and DB schema; // actual removal is a follow-up. New cluster configurations should // leave this empty. // - RateLimitPerMin: 0 disables the per-cluster limiter. type Cluster struct { ID string `json:"id"` Name string `json:"name"` RMURL string `json:"rm_url"` SHSURL string `json:"shs_url"` SparkSubmitExecuteBin string `json:"spark_submit_execute_bin"` IsActive bool `json:"is_active"` AuthType AuthType `json:"auth_type"` AuthUsername string `json:"auth_username,omitempty"` AuthPassword string `json:"-"` // never serialized; encrypted at rest in auth_password_enc SSLVerify bool `json:"ssl_verify"` SSLCABundle string `json:"ssl_ca_bundle,omitempty"` URLAllowlist []string `json:"url_allowlist,omitempty"` // Deprecated: see godoc. DefaultSubmitArgs []string `json:"default_submit_args,omitempty"` RateLimitPerMin int `json:"rate_limit_per_min"` CreatedAt time.Time `json:"created_at"` UpdatedAt time.Time `json:"updated_at"` }