A working private network, and four reasons it did not work
Three machines across two sites, two of them behind no reachable address, all nine paths open. The mesh computes the graph, delivers it as a declaration, and the nodes bring it up. Every fault below looked like success from inside the mesh: the graph was right, the files were right, the services were up, every node reported it had applied. None was reachable by reasoning. A running interface does not re-read its configuration. A node joins, every existing node's peer list changes, the file is replaced -- and the service is already running, so nothing reloads it. Fixed as declared state rather than a command: the service must reflect the file. A command to restart would be an action, and the link may not carry one. The host refused exactly that, which is how this shape was arrived at. A hub sharing a site with a spoke appeared twice in that spoke's peer list -- once as a direct peer, once as the route of last resort. WireGuard takes one entry per key and refuses the file. The ordinary shape of a small mesh, and in none of the tests written before it ran. Two nodes at one site that neither can be dialled were peered directly. Nobody opens the path, and the direct route is more specific than the hub's, so it wins and blackholes -- this design's own warning arriving in its implementation. They now route through the hub unless one end can be dialled. And Docker sets the FORWARD policy to DROP, so a hub with ip_forward enabled carried nothing between its spokes. The substrate at tier 1 silently breaks the network at tier 2, and nothing in either tier's state says so. The hub inserts its own rule above those chains and removes it on the way down. Two weak tests found by injection along the way: one asserted the keepalive rule only against the hub, whose peer entries happen not to set that field at all, so it tested an absence; the other checked the firewall rules by looking for FORWARD anywhere, which the PostDown line satisfies on its own.
This commit is contained in:
@@ -91,14 +91,28 @@ func Compute(nodes []Node, overlayCIDR string) (Graph, error) {
|
||||
for _, self := range usable {
|
||||
var peers []Peer
|
||||
|
||||
// A node may share a site with the hub, and then the hub is one peer rather than two.
|
||||
// Written before the loop because it changes what that loop may emit: WireGuard takes one
|
||||
// entry per public key, so a hub appearing twice is a configuration it refuses — and the
|
||||
// mesh would have produced it silently. The lab found this on the first two machines that
|
||||
// shared a site with their hub.
|
||||
hubIsHere := !self.Hub && self.Site != "" && self.Site == hub.Site
|
||||
|
||||
for _, other := range usable {
|
||||
if other.Name == self.Name {
|
||||
if other.Name == self.Name || (hubIsHere && other.Name == hub.Name) {
|
||||
continue
|
||||
}
|
||||
// Two nodes at the same site peer directly. A site is where a machine physically is,
|
||||
// and machines that share one have a path that does not need the hub — so using it
|
||||
// keeps their traffic off a link that may be somewhere else entirely.
|
||||
if self.Site != "" && self.Site == other.Site {
|
||||
// Two nodes at the same site peer directly — but only if one of them can be
|
||||
// dialled. If neither can, nobody opens the path, and the direct route is more
|
||||
// specific than the hub's, so it wins and blackholes. That is this design's own
|
||||
// stated hazard arriving in it: *a more specific route to a dead endpoint
|
||||
// blackholes; it does not fall back to the general one.*
|
||||
//
|
||||
// Found in the lab with two machines at one site behind no reachable address, which
|
||||
// is the ordinary shape of a home: they were given each other as peers, neither
|
||||
// could start, and they could not reach each other at all while both reached the hub
|
||||
// perfectly.
|
||||
if self.Site != "" && self.Site == other.Site && (self.Reachable() || other.Reachable()) {
|
||||
peers = append(peers, Peer{
|
||||
Name: other.Name, Key: other.Key,
|
||||
Endpoint: other.Endpoint,
|
||||
@@ -113,12 +127,19 @@ func Compute(nodes []Node, overlayCIDR string) (Graph, error) {
|
||||
// Everything else goes through the hub, including a node that roams. AllowedIPs is
|
||||
// the whole overlay, so this is the route of last resort — and because direct peers
|
||||
// above are single addresses, they win on specificity without either being ambiguous.
|
||||
why := "the hub — everything not at this site"
|
||||
if hubIsHere {
|
||||
// One entry doing both jobs: the direct path to a machine that happens to be
|
||||
// here, and the route to everywhere else. Splitting them would need two entries
|
||||
// for one key, which is the thing being avoided.
|
||||
why = "the hub, which is also at this site — everything goes here"
|
||||
}
|
||||
peers = append(peers, Peer{
|
||||
Name: hub.Name, Key: hub.Key,
|
||||
Endpoint: hub.Endpoint,
|
||||
Allowed: overlayCIDR,
|
||||
Keepalive: !self.Reachable(),
|
||||
Why: "the hub — everything not at this site",
|
||||
Why: why,
|
||||
})
|
||||
} else {
|
||||
// The hub holds every node that does not share a site with it, because those nodes
|
||||
|
||||
Reference in New Issue
Block a user