Derive the guard from taken modules only: their published private-network ports and their manifests' guards (hq ADR 0103)

This commit is contained in:
2026-09-22 17:58:37 +02:00
parent 28b7fb81ba
commit 8db66e9532
4 changed files with 182 additions and 24 deletions
+14 -1
View File
@@ -539,11 +539,24 @@ func renderingFor(ctx context.Context, open *stores, node string,
if err != nil {
return catalogue.Rendering{}, inventory.Node{}, err
}
// And, on an adopted node, which modules were taken there: the guard is derived from those
// only (novox/hq ADR 0103).
var taken map[string]bool
if record.Adopted {
list, err := inv.Taken(ctx, node)
if err != nil {
return catalogue.Rendering{}, inventory.Node{}, err
}
taken = map[string]bool{}
for _, m := range list {
taken[m] = true
}
}
return catalogue.Rendering{
Settings: settings, Generators: gens, Grants: grants, Needed: needed, Ports: ports,
Certificate: certificate, Authority: authority, Mesh: private, Names: names,
Suffix: overlay.Suffix(), Foundation: foundation, Kept: kept, Adopted: record.Adopted,
Given: given,
Given: given, Taken: taken,
}, record, nil
}