Do not guard a port this node is told to open to everyone (hq ADR 0103)
This commit is contained in:
@@ -410,3 +410,22 @@ func TestAGivenPortIsRefusedForAPortNoContainerPublishes(t *testing.T) {
|
|||||||
t.Fatalf("a port no container publishes was given: %v", err)
|
t.Fatalf("a port no container publishes was given: %v", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// novox/hq ADR 0103: a guarded port this node is told to open to everyone is opened, not guarded.
|
||||||
|
// An opening from everywhere beside a guard dropping it is one statement refusing the other.
|
||||||
|
func TestAGuardedPortOpenedToEveryoneIsNotGuarded(t *testing.T) {
|
||||||
|
with := anchorRendering(true)
|
||||||
|
with.Settings["postgres"] = []Layer{{From: "node anchor",
|
||||||
|
Values: map[string]any{ExposeSetting: map[string]any{"5432": FromEverywhere}}}}
|
||||||
|
composed, err := anAdoptedAnchor().Compose(with)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
got := byID(composed.Resources)
|
||||||
|
if o := got["adoption.opening-tcp-5432-forwarded"]; o == nil || o["from"] != OpeningFromEverywhere {
|
||||||
|
t.Fatalf("the store's port is not opened to everyone: %v", o)
|
||||||
|
}
|
||||||
|
if guard, _ := got[GuardID()]["content"].(string); guard != AsGuard([]int{5672, 15672}) {
|
||||||
|
t.Fatalf("a port opened to everyone is still guarded:\n%s", guard)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -610,13 +610,21 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
|||||||
func (r Resolution) guarded(out []map[string]any, owner map[string]string, rules []Rule,
|
func (r Resolution) guarded(out []map[string]any, owner map[string]string, rules []Rule,
|
||||||
with Rendering) []int {
|
with Rendering) []int {
|
||||||
meshOnly := map[int]bool{}
|
meshOnly := map[int]bool{}
|
||||||
|
fromEverywhere := map[int]bool{}
|
||||||
for _, rule := range rules {
|
for _, rule := range rules {
|
||||||
if rule.Protocol == "tcp" && rule.From == FromMesh {
|
if rule.Protocol != "tcp" {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
switch rule.From {
|
||||||
|
case FromMesh:
|
||||||
meshOnly[rule.Port] = true
|
meshOnly[rule.Port] = true
|
||||||
|
case FromEverywhere:
|
||||||
|
fromEverywhere[rule.Port] = true
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
for _, port := range with.Foundation {
|
for _, port := range with.Foundation {
|
||||||
delete(meshOnly, port)
|
delete(meshOnly, port)
|
||||||
|
fromEverywhere[port] = true
|
||||||
}
|
}
|
||||||
seen := map[int]bool{}
|
seen := map[int]bool{}
|
||||||
var ports []int
|
var ports []int
|
||||||
@@ -655,7 +663,12 @@ func (r Resolution) guarded(out []map[string]any, owner map[string]string, rules
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
guard(at)
|
// Not what this node is told to open to everyone: a per-node exposure setting that
|
||||||
|
// widens a guarded port is the operator saying so, and declaring an opening for it
|
||||||
|
// and a guard dropping it would be one statement refusing the other.
|
||||||
|
if !fromEverywhere[at] {
|
||||||
|
guard(at)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
sort.Ints(ports)
|
sort.Ints(ports)
|
||||||
|
|||||||
Reference in New Issue
Block a user