A module can name the mesh's range: ${machine:mesh-range} (novox/hq ADR 0112)
A module cannot know the private network's CIDR — it is a per-mesh value chosen at genesis — but sometimes must name it: an intrusion filter that must never ban a tunnel peer. Carry the overlay range on the Rendering and offer it as the machine fact mesh-range, the same way a machine's own address is offered, so the module names it rather than hardcoding a value (data is the mesh's). Absent when the mesh has no range. Enables the fail2ban ignoreip fix.
This commit is contained in:
@@ -57,7 +57,7 @@ func machineUsed(content string) []string {
|
||||
// the hosts file and the resolver's wildcards are written from, so a file naming the machine's
|
||||
// address and the file every other machine reaches it by cannot disagree. Absent, like `at`, when
|
||||
// the machine is off the network or the mesh has not placed it.
|
||||
func machineFacts(r Resolution, names map[string]string) map[string]string {
|
||||
func machineFacts(r Resolution, names map[string]string, meshRange string) map[string]string {
|
||||
out := map[string]string{"name": r.Node}
|
||||
if r.At != "" {
|
||||
out["at"] = r.At
|
||||
@@ -65,6 +65,12 @@ func machineFacts(r Resolution, names map[string]string) map[string]string {
|
||||
out["address"] = address
|
||||
}
|
||||
}
|
||||
// The private network's whole range — a mesh-wide fact, not this machine's, but named here
|
||||
// because a module cannot know it and sometimes must (an intrusion filter that must never ban a
|
||||
// tunnel peer). Absent when the mesh has no range to give.
|
||||
if meshRange != "" {
|
||||
out["mesh-range"] = meshRange
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user