The mesh says what filters a converged machine: filters kept per node, shown by node show, named by status, and previewed with their fates (hq ADR 0168)
A host reports every table and chain that refuses traffic with its owner, and a converged machine's found firewall's state. The controller keeps both on the node's record (migration 0054), shows them on node show, names every converged machine something other than the mesh filters in status — text and JSON, and such a machine is not well — and the converge preview lists what filters the machine with the fate of each: retired with the front end, left as the runtime's, left as a ban, or left in force and not the mesh's. What was invisible for eleven hours (issues 144, 145) is said by name.
This commit is contained in:
@@ -29,6 +29,10 @@ func showMode(ctx context.Context, inv *inventory.Inventory, node inventory.Node
|
||||
if said, err := inv.AdoptionOf(ctx, node.Name); err == nil && len(said.Strays) > 0 {
|
||||
showStrays(said.Strays)
|
||||
}
|
||||
// And what filters it, truthfully (novox/hq ADR 0168): the mesh alone, or not.
|
||||
if filtering, err := inv.FilteringOf(ctx, node.Name); err == nil {
|
||||
showFiltering(filtering, false)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
fmt.Printf(" mode adopted since %s\n",
|
||||
@@ -72,10 +76,63 @@ func showMode(ctx context.Context, inv *inventory.Inventory, node inventory.Node
|
||||
}
|
||||
}
|
||||
showStrays(said.Strays)
|
||||
if filtering, err := inv.FilteringOf(ctx, node.Name); err == nil {
|
||||
showFiltering(filtering, true)
|
||||
}
|
||||
fmt.Printf(" as of %s\n", said.At.Local().Format(time.DateTime))
|
||||
return nil
|
||||
}
|
||||
|
||||
// showFiltering says what filters a machine, with owners (novox/hq ADR 0168), and for a converged
|
||||
// machine the state of the firewall it was found with. A machine that has not said is not said to
|
||||
// be filtered by anything.
|
||||
func showFiltering(f inventory.Filtering, adopted bool) {
|
||||
if len(f.Filters) == 0 && f.FoundFirewall == nil {
|
||||
return
|
||||
}
|
||||
if fw := f.FoundFirewall; fw != nil && !adopted {
|
||||
switch {
|
||||
case fw.Active:
|
||||
fmt.Printf(" found firewall %s is ACTIVE on this converged machine; the next apply retires it again\n", fw.Kind)
|
||||
case fw.RetiredBy == inventory.FilterMesh || fw.RetiredBy == "mesh":
|
||||
fmt.Printf(" found firewall %s, retired by the mesh; its configuration stays on disk\n", fw.Kind)
|
||||
case fw.RetiredBy != "":
|
||||
fmt.Printf(" found firewall %s, found inactive — not by the mesh\n", fw.Kind)
|
||||
default:
|
||||
fmt.Printf(" found firewall %s, inactive\n", fw.Kind)
|
||||
}
|
||||
}
|
||||
if len(f.Filters) == 0 {
|
||||
return
|
||||
}
|
||||
if f.Alone() {
|
||||
fmt.Printf(" filtered by the mesh alone (%s)\n", filterSummary(f.Filters))
|
||||
return
|
||||
}
|
||||
fmt.Printf(" filtered by NOT the mesh alone: %d rule set(s) the mesh did not write refuse traffic here\n", len(f.Others()))
|
||||
for _, x := range f.Filters {
|
||||
if x.Owner == inventory.FilterOther || x.Owner == inventory.FilterFoundFirewall {
|
||||
fmt.Printf(" %-17s %s — %s: %s\n", "", x.Where, x.Owner, x.Refuses)
|
||||
}
|
||||
}
|
||||
fmt.Printf(" %-17s and its own: %s\n", "", filterSummary(f.Filters))
|
||||
}
|
||||
|
||||
// filterSummary counts a machine's filters by owner: "mesh 2, runtime 3, ban 1".
|
||||
func filterSummary(filters []inventory.Filter) string {
|
||||
counts := map[string]int{}
|
||||
for _, x := range filters {
|
||||
counts[x.Owner]++
|
||||
}
|
||||
var parts []string
|
||||
for _, owner := range []string{inventory.FilterMesh, inventory.FilterRuntime, inventory.FilterBan, inventory.FilterFoundFirewall, inventory.FilterOther} {
|
||||
if n := counts[owner]; n > 0 {
|
||||
parts = append(parts, fmt.Sprintf("%s %d", owner, n))
|
||||
}
|
||||
}
|
||||
return strings.Join(parts, ", ")
|
||||
}
|
||||
|
||||
// showStrays says what a machine runs that the mesh neither wrote nor holds (ADR 0163).
|
||||
func showStrays(strays []inventory.Stray) {
|
||||
if len(strays) == 0 {
|
||||
@@ -661,7 +718,11 @@ func converge(ctx context.Context, open *stores, node string, yes bool, digest s
|
||||
}
|
||||
derived := derivedFilter{rules: rules, foundation: with.Foundation, mesh: with.Mesh,
|
||||
outward: plan.PublicDomain != "", outwardLinks: with.OutwardLinks}
|
||||
preview, saw := previewOf(node, reported, derived, plan, taken, filter, runs[filter])
|
||||
filtering, err := inv.FilteringOf(ctx, node)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
preview, saw := previewOf(node, reported, filtering, derived, plan, taken, filter, runs[filter])
|
||||
preview += "\n\n preview " + saw
|
||||
if !yes {
|
||||
return preview + fmt.Sprintf("\n\nNothing has changed. Run `converge %s --yes %s` to do "+
|
||||
@@ -731,7 +792,7 @@ func converge(ctx context.Context, open *stores, node string, yes bool, digest s
|
||||
// previewOf is what converging a node will change, before it changes it, and a short digest of
|
||||
// what it said: every reachable thing and its fate, the modules the flip takes and the filter. The
|
||||
// digest is what the flip is asked to act on, so it changes whenever any of those would.
|
||||
func previewOf(node string, reported inventory.Adoption, derived derivedFilter,
|
||||
func previewOf(node string, reported inventory.Adoption, filtering inventory.Filtering, derived derivedFilter,
|
||||
plan catalogue.Resolution, taken []string, filter string, filterAssigned bool) (string, string) {
|
||||
var said []string
|
||||
var b strings.Builder
|
||||
@@ -823,6 +884,30 @@ func previewOf(node string, reported inventory.Adoption, derived derivedFilter,
|
||||
fmt.Fprintf(&b, " the found firewall (%s) is disabled, never flushed: its configuration stays on disk\n", fw)
|
||||
}
|
||||
said = append(said, fmt.Sprintf("filter %s assigned=%t firewall=%s", filter, filterAssigned, fw))
|
||||
// What filters the machine now, and the fate of each (novox/hq ADR 0168): the found firewall
|
||||
// retired, the runtime's own and bans left, and what the mesh did not write left and named —
|
||||
// so the reader knows before the flip that the machine will not be filtered by the mesh alone.
|
||||
if len(filtering.Filters) > 0 {
|
||||
b.WriteString("\n what filters the machine now, and what the flip does to each:\n")
|
||||
for _, x := range filtering.Filters {
|
||||
fate := "left: " + x.Owner + "'s"
|
||||
switch x.Owner {
|
||||
case inventory.FilterMesh:
|
||||
fate = "the mesh's guard; replaced by its filter"
|
||||
case inventory.FilterFoundFirewall:
|
||||
fate = "the found firewall's; retired with it"
|
||||
case inventory.FilterRuntime:
|
||||
fate = "the container runtime's own; left"
|
||||
case inventory.FilterBan:
|
||||
fate = "a ban list; left"
|
||||
case inventory.FilterOther:
|
||||
fate = "NOT THE MESH'S; left in force — the machine is not filtered by the mesh alone until you remove it"
|
||||
}
|
||||
fmt.Fprintf(&b, " %-50s %s\n", x.Where, fate)
|
||||
fmt.Fprintf(&b, " %-50s %s\n", "", x.Refuses)
|
||||
said = append(said, "filter "+x.Owner+" "+x.Where)
|
||||
}
|
||||
}
|
||||
// Sorted: the same account, reported in another order, is the same preview.
|
||||
sort.Strings(said)
|
||||
sum := sha256.Sum256([]byte(strings.Join(said, "\n")))
|
||||
|
||||
Reference in New Issue
Block a user