IAdapterLeaseScope
Namespace: Meshmakers.Octo.Sdk.Common.Services
The lease half of IAdapterTenantScope, implemented only by a pool member (AB#4924, increment 6).
public interface IAdapterLeaseScope : IAdapterTenantScope
Implements IAdapterTenantScope
Remarks:
🔴 Two nested notions of "the current tenant", and keeping them apart is the point. A lease binds the whole process to one borrowing tenant for the duration of one work item; an execution is one pipeline run inside it. On a dedicated adapter only the execution notion exists, which is why IAdapterTenantScope is the interface everything else in the fleet consumes and this one adds nothing to it for them.
The distinction is load-bearing rather than cosmetic. The lease arrives on a hub callback
and the executions it serves run on entirely different async call chains, so an
AsyncLocal set by the callback would not flow into them — the lease tenant has to be
a value the whole process can see. That is exactly the process-wide tenant value concept §4
warns about, and it is safe here for one reason only: it exists only while a lease is
held. Between leases there is no tenant at all and reading one throws. The isolation
invariant is a property of time, as the concept says, and this is where that sentence
becomes code.
Properties
HasLease
Whether a lease is currently held.
public abstract bool HasLease { get; }
Property Value
LeaseTenantId
The borrowing tenant of the current lease, or null between leases.
public abstract string LeaseTenantId { get; }
Property Value
Remarks:
Deliberately nullable while IAdapterTenantScope.TenantId throws: a caller asking "is a lease held and for whom" has a legitimate no-lease answer, whereas a caller reaching for the tenant of the work it is doing outside any work has a bug.
Methods
BeginLease(String)
Enters a lease. Dispose to leave it — which is what makes the process tenant-free again.
IDisposable BeginLease(string tenantId)
Parameters
tenantId String
Returns
Exceptions
InvalidOperationException
A lease is already held. 🔴 Never a silent overwrite: two overlapping leases on one process
is precisely the cross-tenant data incident the design exists to make impossible, so it
fails loudly at the moment the second one arrives rather than producing an execution that
reads the wrong tenant.