The mesh says what filters a converged machine: filters kept per node, shown by node show, named by status, and previewed with their fates (hq ADR 0168)
A host reports every table and chain that refuses traffic with its owner, and a converged machine's found firewall's state. The controller keeps both on the node's record (migration 0054), shows them on node show, names every converged machine something other than the mesh filters in status — text and JSON, and such a machine is not well — and the converge preview lists what filters the machine with the fate of each: retired with the front end, left as the runtime's, left as a ban, or left in force and not the mesh's. What was invisible for eleven hours (issues 144, 145) is said by name.
This commit is contained in:
@@ -305,6 +305,23 @@ func (e Enrolment) Heard(ctx context.Context, report Report) (news bool, err err
|
||||
return false, err
|
||||
}
|
||||
}
|
||||
// What filters the machine, and the state of its found firewall (novox/hq ADR 0168), whenever
|
||||
// it says — every apply of a host that knows how, adopted or converged; never cleared by a
|
||||
// report that carries none, which is every bare word that the node is there.
|
||||
if len(report.Filters) > 0 || report.FoundFirewall != nil {
|
||||
filters := make([]inventory.Filter, 0, len(report.Filters))
|
||||
for _, f := range report.Filters {
|
||||
filters = append(filters, inventory.Filter{Where: f.Where, Owner: f.Owner, Refuses: f.Refuses})
|
||||
}
|
||||
var found *inventory.FoundFirewall
|
||||
if report.FoundFirewall != nil {
|
||||
found = &inventory.FoundFirewall{Kind: report.FoundFirewall.Kind, Active: report.FoundFirewall.Active,
|
||||
RetiredBy: report.FoundFirewall.RetiredBy}
|
||||
}
|
||||
if err := e.Inventory.RecordFiltering(ctx, node.ID, filters, found); err != nil {
|
||||
return false, err
|
||||
}
|
||||
}
|
||||
// Which of its links face outside (novox/hq ADR 0140), whenever it says so. Recorded on every
|
||||
// report that carries it, adopted or converged, because the filter the mesh composes is written
|
||||
// around it — and never cleared by a report that carries none, which is every bare word that the
|
||||
|
||||
@@ -218,3 +218,45 @@ func TestWhatAnAdoptedNodeHoldsIsKeptAndAnAliveWordDoesNotWipeIt(t *testing.T) {
|
||||
t.Fatalf("a report from an adopted node holding nothing did not empty held: %+v", got)
|
||||
}
|
||||
}
|
||||
|
||||
// What filters a machine, and the state of its found firewall, are kept from every report that
|
||||
// carries them and never cleared by one that does not (novox/hq ADR 0168).
|
||||
func TestWhatFiltersAMachineIsKeptFromItsReport(t *testing.T) {
|
||||
inv, _, _ := heardFrom(t, link.Report{
|
||||
Node: "home-server", Applied: []string{"a"},
|
||||
Filters: []link.Filter{
|
||||
{Where: "table inet mesh, chain forward", Owner: "mesh", Refuses: "policy drop"},
|
||||
{Where: "chain HAL-MESH-ONLY (iptables-legacy)", Owner: "other", Refuses: "-j DROP"},
|
||||
},
|
||||
FoundFirewall: &link.FoundFirewall{Kind: "ufw", Active: false, RetiredBy: "found-inactive"},
|
||||
})
|
||||
ctx := context.Background()
|
||||
f, err := inv.FilteringOf(ctx, "home-server")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(f.Filters) != 2 || f.Filters[1].Owner != inventory.FilterOther || f.Alone() {
|
||||
t.Fatalf("recorded %+v", f)
|
||||
}
|
||||
if f.FoundFirewall == nil || f.FoundFirewall.RetiredBy != "found-inactive" || f.FoundFirewall.Active {
|
||||
t.Fatalf("the found firewall's state: %+v", f.FoundFirewall)
|
||||
}
|
||||
if len(f.Others()) != 1 || f.Others()[0].Where != "chain HAL-MESH-ONLY (iptables-legacy)" {
|
||||
t.Fatalf("others: %+v", f.Others())
|
||||
}
|
||||
// A bare word that the node is there clears nothing.
|
||||
if _, err := (link.Enrolment{Inventory: inv}).Heard(ctx, link.Report{Node: "home-server"}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if again, _ := inv.FilteringOf(ctx, "home-server"); len(again.Filters) != 2 {
|
||||
t.Fatalf("a bare report cleared what filters the machine: %+v", again)
|
||||
}
|
||||
// The next full report replaces it: the chain removed by hand is gone from the record.
|
||||
if _, err := (link.Enrolment{Inventory: inv}).Heard(ctx, link.Report{Node: "home-server", Applied: []string{"a"},
|
||||
Filters: []link.Filter{{Where: "table inet mesh, chain forward", Owner: "mesh", Refuses: "policy drop"}}}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if again, _ := inv.FilteringOf(ctx, "home-server"); len(again.Filters) != 1 || !again.Alone() {
|
||||
t.Fatalf("the next report did not replace what filters the machine: %+v", again)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -197,6 +197,15 @@ type Report struct {
|
||||
// Strays is what runs on the machine that the mesh neither wrote nor holds (ADR 0163).
|
||||
Strays []Stray `json:"strays,omitempty"`
|
||||
|
||||
// Filters is what filters the machine now: every table and chain that refuses traffic, with
|
||||
// its owner — the mesh's, the found firewall's, the container runtime's own, a ban, or other
|
||||
// (novox/hq ADR 0168). Every machine reports it, adopted or converged; absent from a host older
|
||||
// than this.
|
||||
Filters []Filter `json:"filters,omitempty"`
|
||||
// FoundFirewall is the state of the firewall a converged machine was found with: in force now
|
||||
// or not, and how it came to be inactive — the mesh disabled it, or it was found so (ADR 0168).
|
||||
FoundFirewall *FoundFirewall `json:"found_firewall,omitempty"`
|
||||
|
||||
// Profile is what the machine can do, detected again by this apply (novox/hq ADR 0161): the
|
||||
// same shape enrolment sends, so a machine that gained or lost a capability — switched its
|
||||
// network manager — is known at its next push and not at its next enrolment. Absent from a host
|
||||
@@ -278,6 +287,21 @@ type Held struct {
|
||||
Facts map[string]any `json:"facts,omitempty"`
|
||||
}
|
||||
|
||||
// A Filter is one place on a machine that refuses traffic, with its owner (novox/hq ADR 0168):
|
||||
// the host's own shape, carried as data.
|
||||
type Filter struct {
|
||||
Where string `json:"where"`
|
||||
Owner string `json:"owner"`
|
||||
Refuses string `json:"refuses"`
|
||||
}
|
||||
|
||||
// FoundFirewall is the state of a converged machine's found firewall (ADR 0168).
|
||||
type FoundFirewall struct {
|
||||
Kind string `json:"kind"`
|
||||
Active bool `json:"active"`
|
||||
RetiredBy string `json:"retired_by,omitempty"`
|
||||
}
|
||||
|
||||
// A Stray is a container a machine runs that the mesh neither wrote nor holds (ADR 0163).
|
||||
type Stray struct {
|
||||
Kind string `json:"kind"`
|
||||
|
||||
Reference in New Issue
Block a user