The bus is never public: the broker port is no longer a foundation opening
The controller widened the bus's from-mesh port to from-anywhere on the broker's host so a machine could enrol before it had a tunnel. ADR 0169 has machines join through the tunnel and decides the bus is never public; every live bus connection already comes from the mesh.
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
package catalogue
|
||||
|
||||
import (
|
||||
"regexp"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// The bus is never public (novox/hq ADR 0169). Its port is what the bus module declares, the mesh,
|
||||
// and the control plane adds no opening of its own: a machine joins through the tunnel, so the
|
||||
// broker's host is filtered like any other. Before this, the broker port was a foundation port and
|
||||
// rendered from anywhere beside its from-the-mesh rule.
|
||||
func TestTheBusPortIsReachedFromTheMeshAlone(t *testing.T) {
|
||||
rules := []Rule{{Port: 4222, Protocol: "tcp", From: FromMesh, Because: []string{"nats"},
|
||||
Why: []string{"the mesh bus"}}}
|
||||
out := AsNftables(rules, []string{"10.10.0.1", "10.10.0.2"}, true, nil, []string{"eth0"}, "mesh0")
|
||||
|
||||
if !regexp.MustCompile(`ip saddr \{ 10\.10\.0\.1, 10\.10\.0\.2 \} tcp dport 4222 accept`).MatchString(out) {
|
||||
t.Fatalf("the bus is not reachable from the mesh:\n%s", out)
|
||||
}
|
||||
if regexp.MustCompile(`(?m)^\s*tcp dport 4222 accept`).MatchString(out) {
|
||||
t.Fatalf("the bus is reachable from anywhere:\n%s", out)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user