Tell the resolver the machines, not the names the mesh merely serves
The map the control plane hands a resolution holds both: the machines, and every name the mesh was told to route to whichever machine serves it. A container's hosts wants all of it, so a routed name resolves to the proxy. A resolver's zones want only the machines: told the mesh's suffix is its own it answers authoritatively for everything under it and forwards none of it, so a routed name with the suffix appended — drive.example.test.internal — is a name nobody will ever ask for, standing beside the machines and looking as real. Found composing the resolver's first assignment on a live machine, before pushing it. hq issue 111.
This commit is contained in:
@@ -509,6 +509,12 @@ func renderingFor(ctx context.Context, open *stores, node string,
|
||||
// `<node>.internal` names above, so a container — or an internal ACME validator — resolves a
|
||||
// routed name to the proxy that serves it, mesh-wide. The mesh publishes the names it was told
|
||||
// to serve and knows nothing about what they mean.
|
||||
// Kept apart from the machines, because a fact about the machines must not be handed the names
|
||||
// the mesh merely serves (novox/hq 04-ISSUES/111).
|
||||
machines := make(map[string]string, len(names))
|
||||
for name, at := range names {
|
||||
machines[name] = at
|
||||
}
|
||||
routes, err := routeNamesInTheMesh(ctx, open)
|
||||
if err != nil {
|
||||
return catalogue.Rendering{}, inventory.Node{}, err
|
||||
@@ -574,7 +580,8 @@ func renderingFor(ctx context.Context, open *stores, node string,
|
||||
return catalogue.Rendering{
|
||||
Settings: settings, Generators: gens, Grants: grants, Needed: needed, Ports: ports,
|
||||
Certificate: certificate, Authority: authority, Mesh: private, Names: names,
|
||||
Suffix: overlay.Suffix(), Foundation: foundation, Kept: kept, Adopted: record.Adopted,
|
||||
Machines: machines,
|
||||
Suffix: overlay.Suffix(), Foundation: foundation, Kept: kept, Adopted: record.Adopted,
|
||||
Given: given, Taken: taken, Seats: seats, ArtifactStore: artifactStore, Built: built,
|
||||
}, record, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user