Hold the catalogue's store, broker and filter manifests to what adoption needs of them (hq ADR 0100)
This commit is contained in:
@@ -186,7 +186,7 @@ func AsGuard(ports []int) string {
|
|||||||
func GuardUnitText() string {
|
func GuardUnitText() string {
|
||||||
return "[Unit]\n" +
|
return "[Unit]\n" +
|
||||||
"Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)\n" +
|
"Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)\n" +
|
||||||
"After=network-pre.target\n" +
|
"Before=network-pre.target\n" +
|
||||||
"Wants=network-pre.target\n" +
|
"Wants=network-pre.target\n" +
|
||||||
"\n" +
|
"\n" +
|
||||||
"[Service]\n" +
|
"[Service]\n" +
|
||||||
|
|||||||
@@ -0,0 +1,66 @@
|
|||||||
|
package catalogue
|
||||||
|
|
||||||
|
import (
|
||||||
|
"os"
|
||||||
|
"reflect"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// The catalogue's foundation modules as they are, parsed by the real parser (novox/hq ADR 0100):
|
||||||
|
// the store and the broker say which of their ports the mesh guards on an adopted node, and the
|
||||||
|
// filter module loads its table through a unit of its own whose stop deletes only that table.
|
||||||
|
func catalogueManifest(t *testing.T, module string) Manifest {
|
||||||
|
t.Helper()
|
||||||
|
raw, err := os.ReadFile("../../../mesh-catalog/modules/" + module + "/module.json")
|
||||||
|
if err != nil {
|
||||||
|
t.Skipf("the catalogue is not beside this checkout: %v", err)
|
||||||
|
}
|
||||||
|
m, err := ParseManifest(raw)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("%s does not parse:\n%v", module, err)
|
||||||
|
}
|
||||||
|
return m
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTheStoreAndTheBrokerSayWhatTheMeshGuards(t *testing.T) {
|
||||||
|
if got := catalogueManifest(t, "postgres").Guards; !reflect.DeepEqual(got, []int{5432}) {
|
||||||
|
t.Errorf("postgres guards %v; the store's port must be refused from outside", got)
|
||||||
|
}
|
||||||
|
if got := catalogueManifest(t, "lavinmq").Guards; !reflect.DeepEqual(got, []int{15672}) {
|
||||||
|
t.Errorf("lavinmq guards %v; the management port must be refused from outside", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTheFilterModuleNeverFlushesTheRuleset(t *testing.T) {
|
||||||
|
m := catalogueManifest(t, "nftables")
|
||||||
|
var unit map[string]any
|
||||||
|
var load map[string]any
|
||||||
|
for _, r := range m.Resources {
|
||||||
|
switch r["id"] {
|
||||||
|
case "unit":
|
||||||
|
unit = r
|
||||||
|
case "load":
|
||||||
|
load = r
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if load == nil || load["unit"] != "mesh-filter.service" {
|
||||||
|
t.Fatalf("the filter is not loaded by its own unit: %v", load)
|
||||||
|
}
|
||||||
|
content, _ := unit["content"].(string)
|
||||||
|
if unit == nil || unit["path"] != "/etc/systemd/system/mesh-filter.service" {
|
||||||
|
t.Fatalf("the filter's unit is not written: %v", unit)
|
||||||
|
}
|
||||||
|
if strings.Contains(content, "flush") {
|
||||||
|
t.Fatalf("stopping the filter flushes the whole ruleset — the runtime's and the found "+
|
||||||
|
"firewall's with it:\n%s", content)
|
||||||
|
}
|
||||||
|
if !strings.Contains(content, "ExecStop=nft delete table inet mesh\n") ||
|
||||||
|
!strings.Contains(content, "ExecStart=nft -f "+m.Filtering.Into+"\n") {
|
||||||
|
t.Fatalf("the unit does not load the computed rule set and delete only its own table:\n%s",
|
||||||
|
content)
|
||||||
|
}
|
||||||
|
if !reflect.DeepEqual(load["restart-on"], []any{"filtering", "unit"}) {
|
||||||
|
t.Fatalf("the filter is not reloaded when its rules or its unit change: %v", load["restart-on"])
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user