Do not guard a port this node is told to open to everyone (hq ADR 0103)
This commit is contained in:
@@ -610,13 +610,21 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
||||
func (r Resolution) guarded(out []map[string]any, owner map[string]string, rules []Rule,
|
||||
with Rendering) []int {
|
||||
meshOnly := map[int]bool{}
|
||||
fromEverywhere := map[int]bool{}
|
||||
for _, rule := range rules {
|
||||
if rule.Protocol == "tcp" && rule.From == FromMesh {
|
||||
if rule.Protocol != "tcp" {
|
||||
continue
|
||||
}
|
||||
switch rule.From {
|
||||
case FromMesh:
|
||||
meshOnly[rule.Port] = true
|
||||
case FromEverywhere:
|
||||
fromEverywhere[rule.Port] = true
|
||||
}
|
||||
}
|
||||
for _, port := range with.Foundation {
|
||||
delete(meshOnly, port)
|
||||
fromEverywhere[port] = true
|
||||
}
|
||||
seen := map[int]bool{}
|
||||
var ports []int
|
||||
@@ -655,7 +663,12 @@ func (r Resolution) guarded(out []map[string]any, owner map[string]string, rules
|
||||
}
|
||||
}
|
||||
}
|
||||
guard(at)
|
||||
// Not what this node is told to open to everyone: a per-node exposure setting that
|
||||
// widens a guarded port is the operator saying so, and declaring an opening for it
|
||||
// and a guard dropping it would be one statement refusing the other.
|
||||
if !fromEverywhere[at] {
|
||||
guard(at)
|
||||
}
|
||||
}
|
||||
}
|
||||
sort.Ints(ports)
|
||||
|
||||
Reference in New Issue
Block a user