Keep the mesh's trust anchors at the terminal, refuse containerd's tree, and read a found directory as a wait
The review of #170: step-ca's root, roots and path and the identity provider's issuer are what every consumer trusts, and any caller of the settings verb could replace them; they are now terminal keys like places and accesses (hq issue 339). /var/lib/containerd joins the runtimes' data. And a directory the node-engine uses as found failed its module's gate and rolled its builds back; found before the send, it is now a wait for a person the gate passes with, as a relogin is (ADR 0254), and only one the send itself found holds the module.
This commit is contained in:
@@ -62,7 +62,7 @@ var ownerShape = regexp.MustCompile(`^[0-9]+:[0-9]+$`)
|
||||
var (
|
||||
systemTrees = []string{"/etc", "/usr", "/boot", "/root", "/run", "/var/run", "/var/lock", "/proc", "/sys",
|
||||
"/dev", "/bin", "/sbin", "/lib", "/lib32", "/lib64", "/var/lib/mesh", "/var/lib/mesh-host", "/var/spool",
|
||||
"/var/lib/docker", "/var/lib/containers", "/opt"}
|
||||
"/var/lib/docker", "/var/lib/containers", "/var/lib/containerd", "/opt"}
|
||||
systemRoots = []string{"/", "/var", "/var/lib", "/var/cache", "/var/log", "/var/tmp", "/home",
|
||||
"/mnt", "/media", "/srv", "/tmp", "/storage", "/data", "/services"}
|
||||
)
|
||||
@@ -438,3 +438,24 @@ func namesOfAccessIDs(accesses map[string]string) []string {
|
||||
sort.Strings(names)
|
||||
return names
|
||||
}
|
||||
|
||||
// trustAnchors are the settings a provider serves its consumers as what they trust, by module (novox/hq issue
|
||||
// 339): set through a verb, any caller could point every consumer at an authority or an issuer of its own.
|
||||
//
|
||||
// - step-ca, the mesh's internal ACME authority: `root`, the root a consumer is handed to trust (the one
|
||||
// setting that may hold lines, settingsHoldOneLine); `roots` and `path`, where a consumer fetches the roots
|
||||
// and the ACME directory from, which a setting may override as it may any served fact.
|
||||
// - keycloak, the identity provider: `issuer`, the issuer every OIDC consumer checks a login's token against.
|
||||
//
|
||||
// Named here, not in the manifests, because no manifest field says "this is trusted" yet; the catalogue was read
|
||||
// for every served fact and every ${setting:…} on 2026-10-09, and these are the ones a consumer trusts.
|
||||
var trustAnchors = map[string][]string{
|
||||
rootModule: {rootSetting, "roots", "path"},
|
||||
"keycloak": {"issuer"},
|
||||
}
|
||||
|
||||
// TerminalKeys are the settings keys of a module that are set at the controller's terminal alone, never through
|
||||
// a verb (novox/hq issue 339): places and accesses for every module, and a provider's trust anchors.
|
||||
func TerminalKeys(module string) []string {
|
||||
return append([]string{PlacesSetting, AccessesSetting}, trustAnchors[module]...)
|
||||
}
|
||||
|
||||
@@ -109,7 +109,7 @@ func TestTheRuntimesDataAndAnyHomesSSHAreTheMachinesOwn(t *testing.T) {
|
||||
m := Manifest{Module: "notes", Resources: []map[string]any{{"id": "data", "type": "directory"}},
|
||||
Accesses: []Access{{ID: "media"}}}
|
||||
for _, path := range []string{"/var/spool", "/var/spool/cron", "/var/lib/docker", "/var/lib/docker/volumes",
|
||||
"/var/lib/containers/storage", "/opt", "/opt/app", "/home/alice/.ssh", "/home/alice/.ssh/keys",
|
||||
"/var/lib/containers/storage", "/var/lib/containerd", "/var/lib/containerd/io.containerd.snapshotter.v1", "/opt", "/opt/app", "/home/alice/.ssh", "/home/alice/.ssh/keys",
|
||||
"/srv/backup/.ssh", "/root/.ssh"} {
|
||||
layers := []Layer{{From: "laptop", Values: map[string]any{PlacesSetting: map[string]any{"data": path}}}}
|
||||
if _, err := Places(m, layers); err == nil || !strings.Contains(err.Error(), "issue 339") {
|
||||
@@ -127,3 +127,18 @@ func TestTheRuntimesDataAndAnyHomesSSHAreTheMachinesOwn(t *testing.T) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// A trust anchor the mesh hands its consumers is the terminal's too (novox/hq issue 339): the authority's root,
|
||||
// where its roots and directory are, and the identity provider's issuer.
|
||||
func TestTrustAnchorsAreTerminalKeys(t *testing.T) {
|
||||
for module, keys := range map[string][]string{
|
||||
"step-ca": {"places", "accesses", "root", "roots", "path"},
|
||||
"keycloak": {"places", "accesses", "issuer"},
|
||||
"mailu": {"places", "accesses"},
|
||||
} {
|
||||
got := TerminalKeys(module)
|
||||
if strings.Join(got, ",") != strings.Join(keys, ",") {
|
||||
t.Errorf("%s: %v; want %v", module, got, keys)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -446,6 +446,14 @@ const KindUnit = "unit"
|
||||
// starting ReasonRelogin when only a new login is missing.
|
||||
const KindAccount = "account"
|
||||
|
||||
// KindDirectory is a directory of a module that the node-engine uses as found (novox/hq issue 339): there before
|
||||
// the mesh, with another owner or mode than declared, and left so until a person hands it over at the machine
|
||||
// (`mesh-host hand-over`). Stated unhealthy with a reason that starts ReasonUsedAsFound.
|
||||
const KindDirectory = "directory"
|
||||
|
||||
// ReasonUsedAsFound starts the reason of a directory used as found.
|
||||
const ReasonUsedAsFound = "used as found:"
|
||||
|
||||
// ReasonRelogin starts the reason of an account whose running session began before it was put in a group
|
||||
// (ADR 0252): the build did what it should, and a person has one step left (novox/hq ADR 0254).
|
||||
const ReasonRelogin = "relogin needed"
|
||||
|
||||
Reference in New Issue
Block a user