The private network writes nothing into the runtime's file (hq issue 190)
daemon.json and docker.service belong to the docker module, which holds node-container-runtime
and now states the registry itself through ${seat:mesh-artifact-store:reach} (hq ADR 0222). The
overlay stops generating registry-trust and registry-trust-reload. A generated resource is now
held to the collision check every module is, so a second writer cannot come back through
computed code; resolution never saw what a generator declares.
This commit is contained in:
@@ -1,15 +1,13 @@
|
||||
package overlay
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestTheNetworkCarriesRegistryTrust(t *testing.T) {
|
||||
// novox/hq ADR 0082: being on the network is what grants a machine the right to pull from the
|
||||
// mesh's artifact store in the clear, so the network module writes the runtime's trust — and
|
||||
// writes nothing when the mesh has no store to trust.
|
||||
// novox/hq ADR 0222, issue 190: the runtime's file and service are the runtime's module's. The
|
||||
// private network writes nothing into either — being on it still grants the right to pull from the
|
||||
// mesh's store in the clear (ADR 0082), and the runtime's module states that trust itself.
|
||||
func TestTheNetworkWritesNothingOfTheRuntimes(t *testing.T) {
|
||||
nodes := []Node{
|
||||
{Name: "anchor", Site: "lab", Hub: true, Endpoint: "192.0.2.10:51820", Key: "k1", Address: "10.42.0.1"},
|
||||
{Name: "node2", Site: "lab", Key: "k2", Address: "10.42.0.2"},
|
||||
@@ -18,47 +16,15 @@ func TestTheNetworkCarriesRegistryTrust(t *testing.T) {
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
plain, _, err := g.Resources("node2")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
for _, r := range plain {
|
||||
if r["id"] == "registry-trust" {
|
||||
t.Fatal("trust was written with no artifact store to trust")
|
||||
for _, node := range []string{"anchor", "node2"} {
|
||||
resources, part, err := g.Resources(node)
|
||||
if err != nil || !part {
|
||||
t.Fatalf("%s: resources: %v part=%v", node, err, part)
|
||||
}
|
||||
}
|
||||
|
||||
g.TrustRegistry("anchor.internal:5000")
|
||||
trusted, part, err := g.Resources("node2")
|
||||
if err != nil || !part {
|
||||
t.Fatalf("resources: %v part=%v", err, part)
|
||||
}
|
||||
var file, service map[string]any
|
||||
for _, r := range trusted {
|
||||
switch r["id"] {
|
||||
case "registry-trust":
|
||||
file = r
|
||||
case "registry-trust-reload":
|
||||
service = r
|
||||
for _, r := range resources {
|
||||
if r["path"] == "/etc/docker/daemon.json" || r["unit"] == "docker.service" {
|
||||
t.Errorf("%s: the private network declares the runtime's %v", node, r)
|
||||
}
|
||||
}
|
||||
}
|
||||
if file == nil || service == nil {
|
||||
t.Fatalf("the trust file or its reload is missing: %v", trusted)
|
||||
}
|
||||
if file["path"] != "/etc/docker/daemon.json" || file["merge"] != "json" || file["into"] != "json" {
|
||||
t.Fatalf("the trust is not written into daemon.json (ADR 0102): %v", file)
|
||||
}
|
||||
if content, _ := file["content"].(string); !strings.Contains(content, `"anchor.internal:5000"`) {
|
||||
t.Fatalf("the trust does not name the store: %v", file["content"])
|
||||
}
|
||||
if service["unit"] != "docker.service" {
|
||||
t.Fatalf("the reload is not the runtime's: %v", service)
|
||||
}
|
||||
// Reloaded, never restarted: a restart stops every container on the machine (ADR 0102).
|
||||
if _, restarts := service["restart-on"]; restarts {
|
||||
t.Fatalf("the runtime is restarted for its trust: %v", service)
|
||||
}
|
||||
if fmt.Sprint(service["reload-on"]) != "[registry-trust]" {
|
||||
t.Fatalf("the runtime is not reloaded for its trust: %v", service)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user