diff --git a/cmd/mesh-controller/network.go b/cmd/mesh-controller/network.go index 3c1e0b6..7f62c24 100644 --- a/cmd/mesh-controller/network.go +++ b/cmd/mesh-controller/network.go @@ -396,14 +396,17 @@ func onTheNetwork(ctx context.Context, inv *inventory.Inventory, return out, nil } -// onThePrivateNetwork is every node's address on the overlay, sorted. +// onThePrivateNetwork is every node's address on the private network, sorted — the same set +// the names and the resolver mean by it (onTheNetwork), so a rule saying "from the mesh" admits +// exactly the machines the mesh names. // // A node with no address is left out rather than rendered as an empty source: an empty entry in a // source set is a syntax error in the rule file, and a rule file that does not load leaves the // node filtering whatever it was filtering before -- the one outcome worse than a wrong rule, // because nothing reports it. -func onThePrivateNetwork(ctx context.Context, inv *inventory.Inventory) ([]string, error) { - places, err := inv.Overlays(ctx) +func onThePrivateNetwork(ctx context.Context, inv *inventory.Inventory, + shelf map[string]catalogue.Manifest) ([]string, error) { + places, err := onTheNetwork(ctx, inv, shelf) if err != nil { return nil, err } diff --git a/cmd/mesh-controller/network_test.go b/cmd/mesh-controller/network_test.go index da7f02b..ec42473 100644 --- a/cmd/mesh-controller/network_test.go +++ b/cmd/mesh-controller/network_test.go @@ -6,6 +6,7 @@ import ( "testing" "github.com/novox/mesh-controller/internal/inventory" + "github.com/novox/mesh-controller/internal/overlay" ) // placementOf is what the mesh holds about where one node is. @@ -96,7 +97,7 @@ func TestOnlyAMachineOnThePrivateNetworkIsNamed(t *testing.T) { t.Fatalf("two machines on the network are not both named: %v", names) } // The laptop keeps its place and its address, and stops running the network. - if err := open.inventory.Unassign(ctx, "laptop", "mesh-wireguard"); err != nil { + if err := open.inventory.Unassign(ctx, "laptop", overlay.Name); err != nil { t.Fatal(err) } names, err = namesInTheMesh(ctx, open.inventory, shelf) diff --git a/cmd/mesh-controller/plan.go b/cmd/mesh-controller/plan.go index f3d49e7..55d09fc 100644 --- a/cmd/mesh-controller/plan.go +++ b/cmd/mesh-controller/plan.go @@ -426,7 +426,12 @@ func declarationWith(ctx context.Context, open *stores, node string, // resolves to. Every node's address, including this one's: a machine reaching itself by its // own overlay address rather than by loopback is ordinary, and leaving it out would filter // the node's own traffic to itself with no rule naming why. - private, err := onThePrivateNetwork(ctx, inv) + // One reading of the catalogue for the three questions below that resolve the whole mesh. + shelf, err := inv.Catalogue(ctx) + if err != nil { + return nil, err + } + private, err := onThePrivateNetwork(ctx, inv, shelf) if err != nil { return nil, err } @@ -434,10 +439,6 @@ func declarationWith(ctx context.Context, open *stores, node string, // And every machine's name, so a container can reach one. The same set that writes the // machine's own hosts file — one reading, so a container and its machine cannot disagree // about where another machine is. - shelf, err := inv.Catalogue(ctx) - if err != nil { - return nil, err - } names, err := namesInTheMesh(ctx, inv, shelf) if err != nil { return nil, err