No container is given the mesh's names; it resolves them
novox/hq ADR 0148, step 3. Every container got the whole roster as --add-host entries at creation and nothing re-read them (issues 109, 135); once the roster was in the digest so that could be caught, one name moving anywhere replaced every container in the mesh (issue 151). A container resolves through its machine's resolver, which the resolver module tells the runtime about once per machine. A module's own hosts entries stay exactly as declared. Also brings the resolver tests up to the catalogue as it now is: the runtime is reloaded (never restarted) and given live-restore, and the resolver answers by address, not by interface (issue 110).
This commit is contained in:
@@ -198,37 +198,33 @@ func TestTheApexLabelComposesToTheBarePrivateAddress(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// novox/hq ADR 0066 propagate, by ADR 0148's means: a granted route name is published into the
|
||||
// machine's roster mapped to the node that serves it, beside the `<node>.internal` names, and the
|
||||
// machine's resolver answers it to every container. Nothing is written into the container itself —
|
||||
// a routed name that moved would otherwise be wrong inside every container until each was recreated.
|
||||
func TestARoutedNameResolvesToTheServingNode(t *testing.T) {
|
||||
// novox/hq ADR 0066 propagate: a granted route name is published into internal resolution,
|
||||
// mapped to the node that serves it, alongside the `<node>.internal` names — so every
|
||||
// container, and an in-mesh ACME validator, resolves a routed name to the proxy that serves it.
|
||||
// The names map is what withMeshNames writes into every container as `--add-host`; a route name
|
||||
// mapped to the serving node's address rides the same mechanism.
|
||||
names := map[string]string{
|
||||
"anchor.internal": "10.42.0.1",
|
||||
"git.example.tld": "10.42.0.1",
|
||||
}
|
||||
got := containersOf(t, Resolution{Node: "anchor", Modules: []Manifest{{
|
||||
Module: "app",
|
||||
Resources: []map[string]any{{"id": "web", "type": "container", "name": "web",
|
||||
"image": "registry.example/web@sha256:" + strings.Repeat("a", 64)}},
|
||||
}}}, Rendering{Names: map[string]string{
|
||||
"anchor.internal": "10.42.0.1",
|
||||
"git.example.tld": "10.42.0.1",
|
||||
}})
|
||||
}}}, Rendering{Names: names})
|
||||
if len(got) != 1 {
|
||||
t.Fatalf("expected one container, got %d", len(got))
|
||||
}
|
||||
given := namesOf(got[0])
|
||||
var sawNode, sawRoute bool
|
||||
for _, h := range given {
|
||||
if h == "anchor.internal:10.42.0.1" {
|
||||
sawNode = true
|
||||
}
|
||||
if h == "git.example.tld:10.42.0.1" {
|
||||
if given := namesOf(got[0]); len(given) != 0 {
|
||||
t.Fatalf("the routed name was copied into the container, where it would go stale: %v", given)
|
||||
}
|
||||
var sawRoute bool
|
||||
for _, e := range entriesFrom(names, nil, "internal") {
|
||||
if e.Name == "git.example.tld" && e.Address == "10.42.0.1" {
|
||||
sawRoute = true
|
||||
}
|
||||
}
|
||||
if !sawNode {
|
||||
t.Fatalf("the container lost the mesh's node names: %v", given)
|
||||
}
|
||||
if !sawRoute {
|
||||
t.Fatalf("the routed name was not published to the serving node: %v", given)
|
||||
t.Fatalf("the routed name is not in the roster the machine's resolver answers from")
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user