One predicate for the private network: the filter's accept set is the set the names and the resolver mean; the catalogue is read once for the three mesh-wide questions
This commit is contained in:
@@ -426,7 +426,12 @@ func declarationWith(ctx context.Context, open *stores, node string,
|
||||
// resolves to. Every node's address, including this one's: a machine reaching itself by its
|
||||
// own overlay address rather than by loopback is ordinary, and leaving it out would filter
|
||||
// the node's own traffic to itself with no rule naming why.
|
||||
private, err := onThePrivateNetwork(ctx, inv)
|
||||
// One reading of the catalogue for the three questions below that resolve the whole mesh.
|
||||
shelf, err := inv.Catalogue(ctx)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
private, err := onThePrivateNetwork(ctx, inv, shelf)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -434,10 +439,6 @@ func declarationWith(ctx context.Context, open *stores, node string,
|
||||
// And every machine's name, so a container can reach one. The same set that writes the
|
||||
// machine's own hosts file — one reading, so a container and its machine cannot disagree
|
||||
// about where another machine is.
|
||||
shelf, err := inv.Catalogue(ctx)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
names, err := namesInTheMesh(ctx, inv, shelf)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
|
||||
Reference in New Issue
Block a user