Declare openings and a refusal-only guard on an adopted node in place of the filter (hq ADR 0100)

This commit is contained in:
2026-09-22 17:21:44 +02:00
parent a86a6c2974
commit c3b1617693
6 changed files with 526 additions and 13 deletions
+12 -7
View File
@@ -485,16 +485,21 @@ func declarationWith(ctx context.Context, open *stores, node string,
break
}
composed, err := plan.Compose(catalogue.Rendering{
Settings: settings, Generators: gens, Grants: grants, Needed: needed, Ports: ports,
Certificate: certificate, Authority: authority, Mesh: private, Names: names,
Suffix: overlay.Suffix(), Foundation: foundation, Kept: kept})
// Whether this node is adopted (novox/hq ADR 0100): then the found firewall stays in force, and
// the declaration carries openings and the mesh's guard in place of a filter.
record, err := inv.NodeByName(ctx, node)
if err != nil {
return sendable{}, err
}
// Whether this node is adopted, and what was taken on it, said in every declaration it is
// sent from this one place (novox/hq ADR 0100).
adoption, err := adoptionOf(ctx, inv, node, plan, composed)
composed, err := plan.Compose(catalogue.Rendering{
Settings: settings, Generators: gens, Grants: grants, Needed: needed, Ports: ports,
Certificate: certificate, Authority: authority, Mesh: private, Names: names,
Suffix: overlay.Suffix(), Foundation: foundation, Kept: kept, Adopted: record.Adopted})
if err != nil {
return sendable{}, err
}
// And what was taken on it, said in every declaration it is sent from this one place.
adoption, err := adoptionOf(ctx, inv, record, plan, composed)
if err != nil {
return sendable{}, err
}
+2 -6
View File
@@ -41,16 +41,12 @@ func (s sendable) Body() ([]byte, error) {
}
// adoptionOf is the envelope for a node, nil when it is converged.
func adoptionOf(ctx context.Context, inv *inventory.Inventory, node string,
func adoptionOf(ctx context.Context, inv *inventory.Inventory, record inventory.Node,
plan catalogue.Resolution, composed catalogue.Composed) (*adoptionEnvelope, error) {
record, err := inv.NodeByName(ctx, node)
if err != nil {
return nil, err
}
if !record.Adopted {
return nil, nil
}
taken, err := inv.Taken(ctx, node)
taken, err := inv.Taken(ctx, record.Name)
if err != nil {
return nil, err
}