ADR 0100: the guard lets the machine itself through; in use is a non-loopback listener; openings say from where; 09 in step with the flip
This commit is contained in:
@@ -77,9 +77,9 @@ have been taken on it. A node stays adopted until the operator converges it. An
|
||||
said to be adopted wherever the mesh reports a node's state.
|
||||
|
||||
**A converged genesis refuses a machine in use.** A machine is in use when a container is running
|
||||
on it or a port is listening that is neither ssh nor one of the operating system's own services.
|
||||
Raised without saying adopted on such a machine, genesis refuses and names what it found — a
|
||||
forgotten flag must not close a working machine.
|
||||
on it, or a port is listening on an address other than loopback that is not ssh's. Raised without
|
||||
saying adopted on such a machine, genesis refuses and names every container and listener it
|
||||
counted — a forgotten flag must not close a working machine.
|
||||
|
||||
**Before a node is adopted, its predecessor's control is stopped by the operator** — the daemons
|
||||
that write its configuration. Its services keep running on what they have.
|
||||
@@ -99,11 +99,13 @@ rewritten, a container stopped or replaced — is reported as changed by somethi
|
||||
or restarted: that is how a predecessor still writing is caught.
|
||||
|
||||
**The firewall found on the machine stays in force.** The mesh loads no table on an adopted node
|
||||
that drops by default or that accepts — neither genesis's base ruleset nor the filter module's
|
||||
that drops by default or holds an accept — neither genesis's base ruleset nor the filter module's
|
||||
derived one. What the mesh needs reachable is declared as **openings**: a resource that says a port
|
||||
is reachable, from where, on the incoming path or the forwarded path — a published container port is
|
||||
forwarded. The controller derives them from the same inputs as the filter: the `listens` of the
|
||||
modules assigned there, the private network's hub port, and the foundation's ports. The host
|
||||
forwarded. The controller derives them from the same inputs as the filter, each from where the
|
||||
filter would admit it: the `listens` of the modules assigned there, the private network's hub port
|
||||
and the bus and the registry from anywhere, the store's port and the broker's management port from
|
||||
the private network. The host
|
||||
converges an opening through the found firewall in that firewall's own terms, marks it as the
|
||||
mesh's, and removes only what it marked; it re-checks each opening on every reconcile, so a reload
|
||||
or a reboot of the found firewall does not lose it for longer than one reconcile. An opening is a
|
||||
@@ -111,12 +113,14 @@ state, not a command, which is what lets it travel over the link. The host repor
|
||||
it found. A machine with no firewall needs no openings; a machine with a kind no host speaks is
|
||||
refused adoption.
|
||||
|
||||
**The mesh guards its own ports itself, in a table of its own that only refuses.** It accepts by
|
||||
default and holds nothing but refusals, so it cannot close anything the machine serves — a drop in
|
||||
any chain is final and an accept in it would change nothing — and it is the mesh's, so the found
|
||||
firewall reloading does not touch it. It refuses the store's port and the broker's management port
|
||||
from anywhere but the private network, matched on the port the packet was sent to, before the
|
||||
container runtime redirects it. The bus and the registry stay reachable from anywhere, as a node
|
||||
**The mesh guards its own ports itself, in a table of its own that only refuses.** It passes
|
||||
everything by default and holds nothing but refusals, and the two ports it refuses are the
|
||||
foundation's own, checked free at genesis, so it cannot close anything the machine serves; it is
|
||||
the mesh's, so the found firewall reloading does not touch it. It refuses the store's port and the
|
||||
broker's management port except from the private network and from the machine itself — its
|
||||
loopback and the container runtime's own networks — at the prerouting hook, ahead of the runtime's
|
||||
destination translation, so it matches the port the packet was sent to, for both address
|
||||
families. The bus and the registry stay reachable from anywhere, as a node
|
||||
enrols over the bus and pulls from the registry before it has a private-network address
|
||||
([ADR 0088](0088-the-foundation-filters-before-anything-listens.md)); so does the private network's
|
||||
hub port. The store is unreachable from outside whatever the found firewall does, and on a machine
|
||||
@@ -134,11 +138,12 @@ checks that too.
|
||||
found container: each service is taken on its own, when its data has moved, never by the flip. The
|
||||
preview lists what is reachable on the machine now — every listening socket and every published
|
||||
container port — and for each whether an assigned module declares it or it will close, and every
|
||||
module the flip will take, with what each will replace. The flip then takes those modules, loads the
|
||||
module the flip will take, with the held files each will replace. The flip then takes those modules, loads the
|
||||
mesh's derived filter in place of its refusal-only table, and retires the found firewall by
|
||||
disabling it, never by flushing: the container runtime's rules and the found firewall's own
|
||||
configuration stay on disk. Returning a converged node to adopted unloads the derived filter,
|
||||
restores the refusal-only table and enables the found firewall again; what was taken stays taken. A
|
||||
restores the refusal-only table, enables the found firewall again and converges the openings
|
||||
through it once more; what was taken stays taken. A
|
||||
node converges when its migration is done; the mesh is migrated when every node has converged.
|
||||
|
||||
**The order is the operator's:** the control-node first, adopted, its modules assigned and taken
|
||||
@@ -179,15 +184,15 @@ port and denying the rest, a service container listening on that port under a na
|
||||
module also uses, a file at a path that module declares, a stand-in for the predecessor's control
|
||||
that would rewrite that file, and a container holding the registry's port. Then:
|
||||
|
||||
- **Genesis converged** on it refuses and names the running container and the listener.
|
||||
- **Genesis converged** on it refuses and names every container and listener it counted.
|
||||
- **Genesis adopted, with the registry's port held**, refuses and names the holder; with another
|
||||
port given, the foundation comes up — and adopting the foundation as modules leaves it on that
|
||||
port.
|
||||
- **Nothing that serves changed**: the service is reachable from a second machine, the file is byte
|
||||
for byte what it was, and the found firewall's rules differ only by rules marked as the mesh's.
|
||||
- **The store is unreachable from outside** — probed from a machine off the private network, and
|
||||
again after the found firewall is reloaded — and reachable over it; the bus is reachable from a
|
||||
machine that has not yet enrolled.
|
||||
again after the found firewall is reloaded — and reachable over it and from a container on the
|
||||
node itself; the bus is reachable from a machine that has not yet enrolled.
|
||||
- **The mesh works through the found firewall, and keeps working after it is reloaded and after the
|
||||
machine reboots**: the second machine enrols, and the openings are there again.
|
||||
- **A predecessor still writing is caught**: with the stand-in left running, the held file's change
|
||||
|
||||
Reference in New Issue
Block a user