The mesh says what filters a converged machine: filters kept per node, shown by node show, named by status, and previewed with their fates (hq ADR 0168)
A host reports every table and chain that refuses traffic with its owner, and a converged machine's found firewall's state. The controller keeps both on the node's record (migration 0054), shows them on node show, names every converged machine something other than the mesh filters in status — text and JSON, and such a machine is not well — and the converge preview lists what filters the machine with the fate of each: retired with the front end, left as the runtime's, left as a ban, or left in force and not the mesh's. What was invisible for eleven hours (issues 144, 145) is said by name.
This commit is contained in:
@@ -218,3 +218,45 @@ func TestWhatAnAdoptedNodeHoldsIsKeptAndAnAliveWordDoesNotWipeIt(t *testing.T) {
|
||||
t.Fatalf("a report from an adopted node holding nothing did not empty held: %+v", got)
|
||||
}
|
||||
}
|
||||
|
||||
// What filters a machine, and the state of its found firewall, are kept from every report that
|
||||
// carries them and never cleared by one that does not (novox/hq ADR 0168).
|
||||
func TestWhatFiltersAMachineIsKeptFromItsReport(t *testing.T) {
|
||||
inv, _, _ := heardFrom(t, link.Report{
|
||||
Node: "home-server", Applied: []string{"a"},
|
||||
Filters: []link.Filter{
|
||||
{Where: "table inet mesh, chain forward", Owner: "mesh", Refuses: "policy drop"},
|
||||
{Where: "chain HAL-MESH-ONLY (iptables-legacy)", Owner: "other", Refuses: "-j DROP"},
|
||||
},
|
||||
FoundFirewall: &link.FoundFirewall{Kind: "ufw", Active: false, RetiredBy: "found-inactive"},
|
||||
})
|
||||
ctx := context.Background()
|
||||
f, err := inv.FilteringOf(ctx, "home-server")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(f.Filters) != 2 || f.Filters[1].Owner != inventory.FilterOther || f.Alone() {
|
||||
t.Fatalf("recorded %+v", f)
|
||||
}
|
||||
if f.FoundFirewall == nil || f.FoundFirewall.RetiredBy != "found-inactive" || f.FoundFirewall.Active {
|
||||
t.Fatalf("the found firewall's state: %+v", f.FoundFirewall)
|
||||
}
|
||||
if len(f.Others()) != 1 || f.Others()[0].Where != "chain HAL-MESH-ONLY (iptables-legacy)" {
|
||||
t.Fatalf("others: %+v", f.Others())
|
||||
}
|
||||
// A bare word that the node is there clears nothing.
|
||||
if _, err := (link.Enrolment{Inventory: inv}).Heard(ctx, link.Report{Node: "home-server"}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if again, _ := inv.FilteringOf(ctx, "home-server"); len(again.Filters) != 2 {
|
||||
t.Fatalf("a bare report cleared what filters the machine: %+v", again)
|
||||
}
|
||||
// The next full report replaces it: the chain removed by hand is gone from the record.
|
||||
if _, err := (link.Enrolment{Inventory: inv}).Heard(ctx, link.Report{Node: "home-server", Applied: []string{"a"},
|
||||
Filters: []link.Filter{{Where: "table inet mesh, chain forward", Owner: "mesh", Refuses: "policy drop"}}}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if again, _ := inv.FilteringOf(ctx, "home-server"); len(again.Filters) != 1 || !again.Alone() {
|
||||
t.Fatalf("the next report did not replace what filters the machine: %+v", again)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user