mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-01 02:59:08 +02:00
Deleting an account left state behind that DeleteAccount's store associations don't reach. The Agent Network tables outlived the account, keeping its gateway domain claimed and its provider API keys stored. The proxies kept serving its gateway until they next resynced. Cloud-side state, such as managed proxy deployments, had no way to be cleaned up at all. Account deletion now runs registered hooks after the permission check and before any users or data are removed. A failing hook aborts the deletion. Agent Network registers one that tells the proxies to drop the account's gateway mappings. The account's settings, providers, policies, guardrails and budget rules are deleted in the account's transaction. Consumption counters, and the access logs of deleted accounts, are left to the background cleanup; usage records are kept.
15 lines
736 B
Go
15 lines
736 B
Go
package account
|
|
|
|
import "context"
|
|
|
|
// DeletionHook runs when an account is deleted, after the caller's permission to delete
|
|
// it has been checked and before any of its users or data are removed. It lets code that
|
|
// keeps per-account state outside the store tear that state down while the account still
|
|
// exists.
|
|
//
|
|
// A hook that returns an error aborts the deletion and the account is kept. The caller
|
|
// sees the error, so a hook that wants a specific response returns a status error. A
|
|
// retried deletion runs every hook again, and a later step can still fail after the hooks
|
|
// succeed, so a hook must be idempotent and must tolerate the account surviving it.
|
|
type DeletionHook func(ctx context.Context, accountID string) error
|