Compare commits
47
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
905f3363c9 | ||
|
|
9f9d9b3b25 | ||
|
|
bde4b61b3b | ||
|
|
d07018f3c5 | ||
|
|
729a5f9e6c | ||
|
|
773b561f5e | ||
|
|
ca7e81e964 | ||
|
|
08bb56f1d3 | ||
|
|
1a44d281c2 | ||
|
|
1c8fe65601 | ||
|
|
8eb6c3e94a | ||
|
|
9d4d847dc4 | ||
|
|
bea1a1c513 | ||
|
|
b1df688c62 | ||
|
|
21d38c9b0e | ||
|
|
1f86ed4135 | ||
|
|
689dd060b0 | ||
|
|
99c4c4ef04 | ||
|
|
e5e1666f91 | ||
|
|
bd58d1c3ef | ||
|
|
d134c89a7c | ||
|
|
a9307d9f33 | ||
|
|
5eb1c9c2b7 | ||
|
|
37b8edeec6 | ||
|
|
424406b2d6 | ||
|
|
90455c61f6 | ||
|
|
1f6793cf0c | ||
|
|
6ef522fbda | ||
|
|
46f65c12a0 | ||
|
|
8f7c02d77a | ||
|
|
a637df01ea | ||
|
|
252eb786a7 | ||
|
|
9d13b0593b | ||
|
|
30d548a762 | ||
|
|
550e4c6acb | ||
|
|
1587fd97f9 | ||
|
|
b5df244096 | ||
|
|
db47bb68e9 | ||
|
|
db84142d38 | ||
|
|
c9204591bf | ||
|
|
e8e707e013 | ||
|
|
0c003774ba | ||
|
|
fbc3d320ea | ||
|
|
cf495e315f | ||
|
|
86bc1fad2c | ||
|
|
c9eba5f3b8 | ||
|
|
24f024dd74 |
@@ -59,7 +59,7 @@ PROVISIONER_IMAGE ?= mesh-provision-postgres:$(VERSION)
|
|||||||
PROVISIONER_DEV_TAG ?= mesh-provision-postgres:development
|
PROVISIONER_DEV_TAG ?= mesh-provision-postgres:development
|
||||||
|
|
||||||
provisioner-image:
|
provisioner-image:
|
||||||
docker build -f examples/postgres-provisioner/Dockerfile \
|
docker build --build-arg GO_BASE=$(GO_BASE) -f examples/postgres-provisioner/Dockerfile \
|
||||||
-t $(PROVISIONER_IMAGE) -t $(PROVISIONER_DEV_TAG) .
|
-t $(PROVISIONER_IMAGE) -t $(PROVISIONER_DEV_TAG) .
|
||||||
@echo
|
@echo
|
||||||
@docker image inspect $(PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
@docker image inspect $(PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
||||||
@@ -70,7 +70,7 @@ OBJECTSTORE_IMAGE ?= mesh-provision-objectstore:$(VERSION)
|
|||||||
OBJECTSTORE_DEV_TAG ?= mesh-provision-objectstore:development
|
OBJECTSTORE_DEV_TAG ?= mesh-provision-objectstore:development
|
||||||
|
|
||||||
objectstore-image:
|
objectstore-image:
|
||||||
docker build -f examples/objectstore-provisioner/Dockerfile \
|
docker build --build-arg GO_BASE=$(GO_BASE) -f examples/objectstore-provisioner/Dockerfile \
|
||||||
-t $(OBJECTSTORE_IMAGE) -t $(OBJECTSTORE_DEV_TAG) .
|
-t $(OBJECTSTORE_IMAGE) -t $(OBJECTSTORE_DEV_TAG) .
|
||||||
@echo
|
@echo
|
||||||
@docker image inspect $(OBJECTSTORE_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
@docker image inspect $(OBJECTSTORE_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
||||||
@@ -81,7 +81,7 @@ REDIS_PROVISIONER_IMAGE ?= mesh-provision-redis:$(VERSION)
|
|||||||
REDIS_PROVISIONER_DEV_TAG ?= mesh-provision-redis:development
|
REDIS_PROVISIONER_DEV_TAG ?= mesh-provision-redis:development
|
||||||
|
|
||||||
redis-provisioner-image:
|
redis-provisioner-image:
|
||||||
docker build -f examples/redis-provisioner/Dockerfile \
|
docker build --build-arg GO_BASE=$(GO_BASE) -f examples/redis-provisioner/Dockerfile \
|
||||||
-t $(REDIS_PROVISIONER_IMAGE) -t $(REDIS_PROVISIONER_DEV_TAG) .
|
-t $(REDIS_PROVISIONER_IMAGE) -t $(REDIS_PROVISIONER_DEV_TAG) .
|
||||||
@echo
|
@echo
|
||||||
@docker image inspect $(REDIS_PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
@docker image inspect $(REDIS_PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
||||||
@@ -91,7 +91,7 @@ PROXY_IMAGE ?= mesh-route-proxy:$(VERSION)
|
|||||||
PROXY_DEV_TAG ?= mesh-route-proxy:development
|
PROXY_DEV_TAG ?= mesh-route-proxy:development
|
||||||
|
|
||||||
proxy-image:
|
proxy-image:
|
||||||
docker build -f examples/route-proxy/Dockerfile -t $(PROXY_IMAGE) -t $(PROXY_DEV_TAG) .
|
docker build --build-arg GO_BASE=$(GO_BASE) -f examples/route-proxy/Dockerfile -t $(PROXY_IMAGE) -t $(PROXY_DEV_TAG) .
|
||||||
@echo
|
@echo
|
||||||
@docker image inspect $(PROXY_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
@docker image inspect $(PROXY_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
||||||
|
|
||||||
|
|||||||
@@ -95,11 +95,22 @@ func reportsReaching(t *testing.T, open *stores, reachable []link.Reach, held ..
|
|||||||
// filter is not sent to one that has not. The anchor reports one, as a real host does; this
|
// filter is not sent to one that has not. The anchor reports one, as a real host does; this
|
||||||
// fixture lacked it from 2026-09-28 and nothing ran the test (issue 177).
|
// fixture lacked it from 2026-09-28 and nothing ran the test (issue 177).
|
||||||
Outward: []string{"eth0"},
|
Outward: []string{"eth0"},
|
||||||
|
// And what filters it (ADR 0168): its front end, the runtime's own, and a chain a
|
||||||
|
// predecessor left in the runtime's user chain.
|
||||||
|
Filters: anchorFilters,
|
||||||
}); err != nil {
|
}); err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// anchorFilters is what the adopted anchor says filters it: ufw's chains, the runtime's, and a
|
||||||
|
// predecessor's chain the mesh did not write.
|
||||||
|
var anchorFilters = []link.Filter{
|
||||||
|
{Where: "table ip filter, chain ufw-reject-input", Owner: "found-firewall", Refuses: "reject"},
|
||||||
|
{Where: "table ip filter, chain DOCKER", Owner: "runtime", Refuses: `iifname != "docker0" oifname "docker0" drop`},
|
||||||
|
{Where: "table ip filter, chain DOCKER-USER", Owner: "other", Refuses: `iifname "eth0" tcp dport 6000 drop`},
|
||||||
|
}
|
||||||
|
|
||||||
var (
|
var (
|
||||||
heldContainer = link.Held{ID: "hello-web.server", Module: "hello-web", Kind: "container",
|
heldContainer = link.Held{ID: "hello-web.server", Module: "hello-web", Kind: "container",
|
||||||
Target: "hello-web", Since: time.Now()}
|
Target: "hello-web", Since: time.Now()}
|
||||||
@@ -143,7 +154,24 @@ func TestTheFlipIsRefusedWhileAFoundContainerIsHeld(t *testing.T) {
|
|||||||
func TestTakingNamesWhatItReplaces(t *testing.T) {
|
func TestTakingNamesWhatItReplaces(t *testing.T) {
|
||||||
open, _ := anAdoptedAnchor(t)
|
open, _ := anAdoptedAnchor(t)
|
||||||
reportsHolding(t, open, heldContainer, heldFile)
|
reportsHolding(t, open, heldContainer, heldFile)
|
||||||
said, err := take(t.Context(), open, "anchor", "hello-web", takeOptions{Yes: true})
|
ctx := t.Context()
|
||||||
|
// The machine holds something for the module, so the take acts on the preview the operator
|
||||||
|
// saw and names its digest (novox/hq ADR 0163).
|
||||||
|
preview, err := take(ctx, open, "anchor", "hello-web", takeOptions{})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
saw := takeDigestIn(t, preview)
|
||||||
|
if !strings.Contains(preview, "nothing taken; `take anchor hello-web --yes "+saw+"`") {
|
||||||
|
t.Fatalf("the preview does not say how to act on it:\n%s", preview)
|
||||||
|
}
|
||||||
|
if taken, _ := open.inventory.Taken(ctx, "anchor"); len(taken) != 0 {
|
||||||
|
t.Fatal("the preview took something")
|
||||||
|
}
|
||||||
|
if _, err := take(ctx, open, "anchor", "hello-web", takeOptions{Yes: true}); err == nil || !strings.Contains(err.Error(), "name its digest") {
|
||||||
|
t.Fatalf("--yes without the digest was not refused: %v", err)
|
||||||
|
}
|
||||||
|
said, err := take(ctx, open, "anchor", "hello-web", takeOptions{Yes: true, Digest: saw})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
@@ -153,6 +181,67 @@ func TestTakingNamesWhatItReplaces(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// takeDigestIn is the digest a take's preview printed.
|
||||||
|
func takeDigestIn(t *testing.T, preview string) string {
|
||||||
|
t.Helper()
|
||||||
|
for _, line := range strings.Split(preview, "\n") {
|
||||||
|
if fields := strings.Fields(line); len(fields) == 2 && fields[0] == "preview" {
|
||||||
|
return fields[1]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
t.Fatalf("the preview printed no digest:\n%s", preview)
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
|
||||||
|
// A take acts on the preview the operator saw, and on an account of the machine that is still the
|
||||||
|
// machine: a changed preview and a stale account refuse (novox/hq ADR 0163, rule 1).
|
||||||
|
func TestATakeIsRefusedOnAChangedPreviewOrAStaleAccount(t *testing.T) {
|
||||||
|
open, _ := anAdoptedAnchor(t)
|
||||||
|
ctx := t.Context()
|
||||||
|
reportsHolding(t, open, heldContainer, heldFile)
|
||||||
|
preview, err := take(ctx, open, "anchor", "hello-web", takeOptions{})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
saw := takeDigestIn(t, preview)
|
||||||
|
|
||||||
|
// The machine reports again, and what it holds has changed: the found container now carries
|
||||||
|
// facts the preview never showed.
|
||||||
|
changed := heldContainer
|
||||||
|
changed.Facts = map[string]any{"image": "hello:2", "declared_image": "registry.example/hello"}
|
||||||
|
reportsHolding(t, open, changed, heldFile)
|
||||||
|
_, err = take(ctx, open, "anchor", "hello-web", takeOptions{Yes: true, Digest: saw})
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "has changed since preview "+saw) {
|
||||||
|
t.Fatalf("a changed preview was acted on: %v", err)
|
||||||
|
}
|
||||||
|
if taken, _ := open.inventory.Taken(ctx, "anchor"); len(taken) != 0 {
|
||||||
|
t.Fatal("a refused take took something")
|
||||||
|
}
|
||||||
|
|
||||||
|
// And an account older than the flip allows.
|
||||||
|
preview, err = take(ctx, open, "anchor", "hello-web", takeOptions{})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
saw = takeDigestIn(t, preview)
|
||||||
|
saved := reportFreshFor
|
||||||
|
reportFreshFor = -time.Second
|
||||||
|
defer func() { reportFreshFor = saved }()
|
||||||
|
_, err = take(ctx, open, "anchor", "hello-web", takeOptions{Yes: true, Digest: saw})
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "a take acts only on an account newer than") {
|
||||||
|
t.Fatalf("a stale account was acted on: %v", err)
|
||||||
|
}
|
||||||
|
reportFreshFor = saved
|
||||||
|
if _, err := take(ctx, open, "anchor", "hello-web", takeOptions{Yes: true, Digest: saw}); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
// A module the machine holds nothing for has nothing to compare: --yes alone suffices.
|
||||||
|
if _, err := take(ctx, open, "anchor", "notes", takeOptions{Yes: true}); err == nil {
|
||||||
|
// notes holds a file, so this one needs the digest too.
|
||||||
|
t.Fatal("notes holds a found file and was taken without a digest")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestConvergingPreviewsThenChangesAndAdoptingKeepsWhatWasTaken(t *testing.T) {
|
func TestConvergingPreviewsThenChangesAndAdoptingKeepsWhatWasTaken(t *testing.T) {
|
||||||
open, sent := anAdoptedAnchor(t)
|
open, sent := anAdoptedAnchor(t)
|
||||||
ctx := t.Context()
|
ctx := t.Context()
|
||||||
@@ -186,6 +275,20 @@ func TestConvergingPreviewsThenChangesAndAdoptingKeepsWhatWasTaken(t *testing.T)
|
|||||||
if strings.Contains(preview, "15672") {
|
if strings.Contains(preview, "15672") {
|
||||||
t.Errorf("a loopback listener is in the preview:\n%s", preview)
|
t.Errorf("a loopback listener is in the preview:\n%s", preview)
|
||||||
}
|
}
|
||||||
|
// What filters the machine now, and the fate of each (novox/hq ADR 0168): the predecessor's
|
||||||
|
// chain is named as not the mesh's and left, so the reader knows before the flip.
|
||||||
|
for _, want := range []string{
|
||||||
|
"table ip filter, chain DOCKER-USER",
|
||||||
|
"NOT THE MESH'S; left in force",
|
||||||
|
`iifname "eth0" tcp dport 6000 drop`,
|
||||||
|
"table ip filter, chain ufw-reject-input",
|
||||||
|
"the found firewall's; retired with it",
|
||||||
|
"the container runtime's own; left",
|
||||||
|
} {
|
||||||
|
if !strings.Contains(preview, want) {
|
||||||
|
t.Errorf("the preview does not say %q:\n%s", want, preview)
|
||||||
|
}
|
||||||
|
}
|
||||||
for _, line := range strings.Split(preview, "\n") {
|
for _, line := range strings.Split(preview, "\n") {
|
||||||
if strings.Contains(line, "5000") && !strings.Contains(line, "WILL CLOSE") {
|
if strings.Contains(line, "5000") && !strings.Contains(line, "WILL CLOSE") {
|
||||||
t.Errorf("an undeclared published port is not said to close: %s", line)
|
t.Errorf("an undeclared published port is not said to close: %s", line)
|
||||||
|
|||||||
+299
-23
@@ -29,6 +29,10 @@ func showMode(ctx context.Context, inv *inventory.Inventory, node inventory.Node
|
|||||||
if said, err := inv.AdoptionOf(ctx, node.Name); err == nil && len(said.Strays) > 0 {
|
if said, err := inv.AdoptionOf(ctx, node.Name); err == nil && len(said.Strays) > 0 {
|
||||||
showStrays(said.Strays)
|
showStrays(said.Strays)
|
||||||
}
|
}
|
||||||
|
// And what filters it, truthfully (novox/hq ADR 0168): the mesh alone, or not.
|
||||||
|
if filtering, err := inv.FilteringOf(ctx, node.Name); err == nil {
|
||||||
|
showFiltering(filtering, false)
|
||||||
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
fmt.Printf(" mode adopted since %s\n",
|
fmt.Printf(" mode adopted since %s\n",
|
||||||
@@ -72,10 +76,65 @@ func showMode(ctx context.Context, inv *inventory.Inventory, node inventory.Node
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
showStrays(said.Strays)
|
showStrays(said.Strays)
|
||||||
|
if filtering, err := inv.FilteringOf(ctx, node.Name); err == nil {
|
||||||
|
showFiltering(filtering, true)
|
||||||
|
}
|
||||||
fmt.Printf(" as of %s\n", said.At.Local().Format(time.DateTime))
|
fmt.Printf(" as of %s\n", said.At.Local().Format(time.DateTime))
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// showFiltering says what filters a machine, with owners (novox/hq ADR 0168), and for a converged
|
||||||
|
// machine the state of the firewall it was found with. A machine that has not said is not said to
|
||||||
|
// be filtered by anything.
|
||||||
|
func showFiltering(f inventory.Filtering, adopted bool) {
|
||||||
|
if len(f.Filters) == 0 && f.FoundFirewall == nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if fw := f.FoundFirewall; fw != nil && !adopted {
|
||||||
|
switch {
|
||||||
|
case fw.Active:
|
||||||
|
fmt.Printf(" found firewall %s is ACTIVE on this converged machine; the next apply retires it again\n", fw.Kind)
|
||||||
|
case fw.RetiredBy == "removed":
|
||||||
|
fmt.Printf(" found firewall %s, removed: the mesh's filter is what filters this machine (novox/hq ADR 0180)\n", fw.Kind)
|
||||||
|
case fw.RetiredBy == inventory.FilterMesh || fw.RetiredBy == "mesh":
|
||||||
|
fmt.Printf(" found firewall %s, retired by the mesh; its configuration stays on disk\n", fw.Kind)
|
||||||
|
case fw.RetiredBy != "":
|
||||||
|
fmt.Printf(" found firewall %s, found inactive — not by the mesh\n", fw.Kind)
|
||||||
|
default:
|
||||||
|
fmt.Printf(" found firewall %s, inactive\n", fw.Kind)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if len(f.Filters) == 0 {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if f.Alone() {
|
||||||
|
fmt.Printf(" filtered by the mesh alone (%s)\n", filterSummary(f.Filters))
|
||||||
|
return
|
||||||
|
}
|
||||||
|
fmt.Printf(" filtered by NOT the mesh alone: %d rule set(s) the mesh did not write refuse traffic here\n", len(f.Others()))
|
||||||
|
for _, x := range f.Filters {
|
||||||
|
if x.Owner == inventory.FilterOther || x.Owner == inventory.FilterFoundFirewall {
|
||||||
|
fmt.Printf(" %-17s %s — %s: %s\n", "", x.Where, x.Owner, x.Refuses)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
fmt.Printf(" %-17s and its own: %s\n", "", filterSummary(f.Filters))
|
||||||
|
}
|
||||||
|
|
||||||
|
// filterSummary counts a machine's filters by owner: "mesh 2, runtime 3, ban 1".
|
||||||
|
func filterSummary(filters []inventory.Filter) string {
|
||||||
|
counts := map[string]int{}
|
||||||
|
for _, x := range filters {
|
||||||
|
counts[x.Owner]++
|
||||||
|
}
|
||||||
|
var parts []string
|
||||||
|
for _, owner := range []string{inventory.FilterMesh, inventory.FilterRuntime, inventory.FilterBan, inventory.FilterFoundFirewall, inventory.FilterOther} {
|
||||||
|
if n := counts[owner]; n > 0 {
|
||||||
|
parts = append(parts, fmt.Sprintf("%s %d", owner, n))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return strings.Join(parts, ", ")
|
||||||
|
}
|
||||||
|
|
||||||
// showStrays says what a machine runs that the mesh neither wrote nor holds (ADR 0163).
|
// showStrays says what a machine runs that the mesh neither wrote nor holds (ADR 0163).
|
||||||
func showStrays(strays []inventory.Stray) {
|
func showStrays(strays []inventory.Stray) {
|
||||||
if len(strays) == 0 {
|
if len(strays) == 0 {
|
||||||
@@ -156,11 +215,25 @@ const DefaultFilter = "nftables"
|
|||||||
// take is a module's cutover on an adopted node: the operator's act, done when that module's data
|
// take is a module's cutover on an adopted node: the operator's act, done when that module's data
|
||||||
// has moved. From the next push its resources converge there like any other, replacing what the
|
// has moved. From the next push its resources converge there like any other, replacing what the
|
||||||
// node found and holds for it.
|
// node found and holds for it.
|
||||||
|
//
|
||||||
|
// **Previewed, and the preview is a comparison** (novox/hq ADR 0163): for every held thing the
|
||||||
|
// module would replace, what runs beside what the module declares, and the difference; the
|
||||||
|
// module's secrets on the machine and where each came from; its settings on the machine. Without
|
||||||
|
// --yes the comparison is printed and nothing changes. `--yes <digest>` cuts over exactly what was
|
||||||
|
// previewed, the way the flip is confirmed: the preview ends with a digest of what it said, and a
|
||||||
|
// take naming an older one, or acting on an account of the machine older than the flip allows, is
|
||||||
|
// refused. A module the machine holds nothing for has nothing to compare, and `--yes` suffices.
|
||||||
// takeOptions is what a take was told about the differences it may pass (novox/hq ADR 0163).
|
// takeOptions is what a take was told about the differences it may pass (novox/hq ADR 0163).
|
||||||
type takeOptions struct {
|
type takeOptions struct {
|
||||||
Yes bool
|
Yes bool
|
||||||
|
// Digest is the preview's, named with --yes; required whenever the machine holds something
|
||||||
|
// for the module.
|
||||||
|
Digest string
|
||||||
Downgrade bool
|
Downgrade bool
|
||||||
Replace map[string]bool
|
Replace map[string]bool
|
||||||
|
// Mint names the secrets the service shall take a new value for, although the mesh minted
|
||||||
|
// one and the service already has its own (rule 2).
|
||||||
|
Mint map[string]bool
|
||||||
}
|
}
|
||||||
|
|
||||||
func take(ctx context.Context, open *stores, node, module string, opts takeOptions) (string, error) {
|
func take(ctx context.Context, open *stores, node, module string, opts takeOptions) (string, error) {
|
||||||
@@ -179,45 +252,128 @@ func take(ctx context.Context, open *stores, node, module string, opts takeOptio
|
|||||||
}
|
}
|
||||||
// The comparison first (novox/hq ADR 0163): every held thing the module would replace, beside
|
// The comparison first (novox/hq ADR 0163): every held thing the module would replace, beside
|
||||||
// what the module declares, and the differences that refuse unless named.
|
// what the module declares, and the differences that refuse unless named.
|
||||||
reported, err := inv.AdoptionOf(ctx, node)
|
c, err := comparisonFor(ctx, open, node, module)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return "", err
|
return "", err
|
||||||
}
|
}
|
||||||
preview, refusals := comparisonOf(reported.Held, module, opts)
|
preview, refusals, saw := comparisonOf(module, c, opts)
|
||||||
if len(refusals) > 0 {
|
if len(refusals) > 0 {
|
||||||
return "", fmt.Errorf("taking %s on %s is refused:\n %s\n%s", module, node,
|
return "", fmt.Errorf("taking %s on %s is refused:\n %s\n%s", module, node,
|
||||||
strings.Join(refusals, "\n "), preview)
|
strings.Join(refusals, "\n "), preview)
|
||||||
}
|
}
|
||||||
|
holds := len(heldOf(c.reported, module)) > 0
|
||||||
|
if holds {
|
||||||
|
preview += "\n preview " + saw
|
||||||
|
}
|
||||||
if !opts.Yes {
|
if !opts.Yes {
|
||||||
return preview + fmt.Sprintf("\nnothing taken; `take %s %s --yes` cuts it over as previewed", node, module), nil
|
if !holds {
|
||||||
|
return preview + fmt.Sprintf("\nnothing taken; `take %s %s --yes` declares it as the mesh's own", node, module), nil
|
||||||
|
}
|
||||||
|
return preview + fmt.Sprintf("\nnothing taken; `take %s %s --yes %s` cuts it over as previewed", node, module, saw), nil
|
||||||
|
}
|
||||||
|
if holds {
|
||||||
|
// The take acts on the preview the operator saw, and on an account of the machine that
|
||||||
|
// is still the machine: the same two refusals the flip makes.
|
||||||
|
if age := time.Since(c.reported.At); age > reportFreshFor {
|
||||||
|
return preview, fmt.Errorf("%s last said what it holds %s ago, and a take acts only on "+
|
||||||
|
"an account newer than %s: run `push %s --wait 2m`, then preview again",
|
||||||
|
node, age.Round(time.Second), reportFreshFor, node)
|
||||||
|
}
|
||||||
|
if opts.Digest == "" {
|
||||||
|
return preview, fmt.Errorf("taking %s on %s acts on the preview you saw: name its digest, "+
|
||||||
|
"`take %s %s --yes %s`, once you have read it", module, node, node, module, saw)
|
||||||
|
}
|
||||||
|
if opts.Digest != saw {
|
||||||
|
return preview, fmt.Errorf("what taking %s on %s would replace has changed since preview %s "+
|
||||||
|
"(it is now %s): read the preview above, and run `take %s %s --yes %s` if it is "+
|
||||||
|
"what you want", module, node, opts.Digest, saw, node, module, saw)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
if err := inv.Take(ctx, node, module); err != nil {
|
if err := inv.Take(ctx, node, module); err != nil {
|
||||||
return "", err
|
return "", err
|
||||||
}
|
}
|
||||||
said := fmt.Sprintf("%s is taken on %s", module, node)
|
said := fmt.Sprintf("%s is taken on %s", module, node)
|
||||||
if preview != "" {
|
if holds {
|
||||||
said += "; the next push replaces what the node found and holds for it:\n" + preview
|
said += "; the next push replaces what the node found and holds for it:\n" + preview
|
||||||
}
|
}
|
||||||
return said + fmt.Sprintf("\n run `push %s` to cut it over", node), nil
|
return said + fmt.Sprintf("\n run `push %s` to cut it over", node), nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// comparison is everything a take puts beside what the module declares: the machine's account of
|
||||||
|
// what it holds and what is reachable on it, the module's secrets on the machine, its settings
|
||||||
|
// there, and which found networks a setting keeps for each of its containers (by held id).
|
||||||
|
type comparison struct {
|
||||||
|
reported inventory.Adoption
|
||||||
|
secrets []inventory.SecretState
|
||||||
|
layers []catalogue.Layer
|
||||||
|
keeps map[string][]string
|
||||||
|
// settingsRefused is why the module's settings cannot compose with its definition, when
|
||||||
|
// they cannot — the module would be left out of the declaration (rule 6).
|
||||||
|
settingsRefused string
|
||||||
|
}
|
||||||
|
|
||||||
|
func comparisonFor(ctx context.Context, open *stores, node, module string) (comparison, error) {
|
||||||
|
inv := open.inventory
|
||||||
|
var c comparison
|
||||||
|
var err error
|
||||||
|
if c.reported, err = inv.AdoptionOf(ctx, node); err != nil {
|
||||||
|
return c, err
|
||||||
|
}
|
||||||
|
if c.secrets, err = inv.SecretsOf(ctx, node, module); err != nil {
|
||||||
|
return c, err
|
||||||
|
}
|
||||||
|
if c.layers, err = inv.SettingsFor(ctx, node, module); err != nil {
|
||||||
|
return c, err
|
||||||
|
}
|
||||||
|
shelf, err := inv.Catalogue(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return c, err
|
||||||
|
}
|
||||||
|
if m, known := shelf[module]; known && len(c.layers) > 0 {
|
||||||
|
if err := catalogue.JudgeSettings(m, c.layers, true); err != nil {
|
||||||
|
c.settingsRefused = err.Error()
|
||||||
|
}
|
||||||
|
if kept, err := catalogue.KeptNetworks(m, c.layers, true); err == nil && len(kept) > 0 {
|
||||||
|
c.keeps = map[string][]string{}
|
||||||
|
for id, networks := range kept {
|
||||||
|
c.keeps[module+"."+id] = networks
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return c, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// heldOf is what a node holds for one module.
|
||||||
|
func heldOf(reported inventory.Adoption, module string) []inventory.Held {
|
||||||
|
var out []inventory.Held
|
||||||
|
for _, h := range reported.Held {
|
||||||
|
if h.Module == module {
|
||||||
|
out = append(out, h)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return out
|
||||||
|
}
|
||||||
|
|
||||||
// comparisonOf is a take's preview: for every held thing of the module, what runs beside what the
|
// comparisonOf is a take's preview: for every held thing of the module, what runs beside what the
|
||||||
// module declares, and the refusals the differences earn unless the take named them
|
// module declares; its secrets and its settings on the machine; and the refusals the differences
|
||||||
// (novox/hq ADR 0163): an image older than the one running, a declared file that differs from the
|
// earn unless the take named them (novox/hq ADR 0163): an image older than the one running, a
|
||||||
// found one. A narrowed port and a shared network are said and not refused.
|
// declared file that differs from the found one, a secret the mesh minted for a service whose data
|
||||||
func comparisonOf(held []inventory.Held, module string, opts takeOptions) (string, []string) {
|
// was found. A narrowed port and a shared network are said and not refused. The digest is of what
|
||||||
|
// the preview says, so anything in it changing changes the digest.
|
||||||
|
func comparisonOf(module string, c comparison, opts takeOptions) (preview string, refusals []string, digest string) {
|
||||||
var b strings.Builder
|
var b strings.Builder
|
||||||
var refusals []string
|
held := heldOf(c.reported, module)
|
||||||
|
foundData := false
|
||||||
for _, h := range held {
|
for _, h := range held {
|
||||||
if h.Module != module {
|
if h.Kind == "container" || h.Kind == "directory" {
|
||||||
continue
|
foundData = true
|
||||||
}
|
}
|
||||||
fmt.Fprintf(&b, " %s", heldLine(h))
|
fmt.Fprintf(&b, " %s", heldLine(h))
|
||||||
if h.Kept != "" {
|
if h.Kept != "" {
|
||||||
fmt.Fprintf(&b, ", original kept at %s", h.Kept)
|
fmt.Fprintf(&b, ", original kept at %s", h.Kept)
|
||||||
}
|
}
|
||||||
b.WriteString("\n")
|
b.WriteString("\n")
|
||||||
for _, line := range comparisonLines(h) {
|
for _, line := range comparisonLinesWith(h, c.keeps[h.ID], c.reported) {
|
||||||
fmt.Fprintf(&b, " %s\n", line)
|
fmt.Fprintf(&b, " %s\n", line)
|
||||||
}
|
}
|
||||||
f := factsOf(h)
|
f := factsOf(h)
|
||||||
@@ -232,7 +388,52 @@ func comparisonOf(held []inventory.Held, module string, opts takeOptions) (strin
|
|||||||
h.Target, h.Target))
|
h.Target, h.Target))
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
return b.String(), refusals
|
// The module's secrets on the machine (rule 2 and 3): a service whose data was found already
|
||||||
|
// has a value for each, so one the mesh minted and nobody accepted refuses unless --mint says
|
||||||
|
// the service shall take a new one.
|
||||||
|
for _, sec := range c.secrets {
|
||||||
|
name := sec.Name
|
||||||
|
if sec.Local != "" {
|
||||||
|
name += " (" + sec.Local + ")"
|
||||||
|
}
|
||||||
|
what := "own secret"
|
||||||
|
accept := fmt.Sprintf("`secret accept <node> %s %s`", module, sec.Name)
|
||||||
|
if !sec.Own() {
|
||||||
|
what = "secret from " + sec.Provider
|
||||||
|
accept = fmt.Sprintf("`secret accept <node> %s %s --provider %s`", module, sec.Name, sec.Provider)
|
||||||
|
if sec.Local != "" {
|
||||||
|
accept = strings.TrimSuffix(accept, "`") + " --local " + sec.Local + "`"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
switch {
|
||||||
|
case sec.Origin == inventory.OriginAccepted:
|
||||||
|
fmt.Fprintf(&b, " %s %s: accepted from a person, carried in as it is\n", what, name)
|
||||||
|
case opts.Mint[sec.Name]:
|
||||||
|
fmt.Fprintf(&b, " %s %s: minted by the mesh; the service takes the new value, as --mint said\n", what, name)
|
||||||
|
case foundData:
|
||||||
|
fmt.Fprintf(&b, " %s %s: MINTED by the mesh and not accepted — the running service already has one\n", what, name)
|
||||||
|
refusals = append(refusals, fmt.Sprintf("%s: the mesh minted a value and the service whose data was found "+
|
||||||
|
"already uses its own; %s carries the existing value in, or `--mint %s` says the service shall take "+
|
||||||
|
"the new one", name, accept, sec.Name))
|
||||||
|
default:
|
||||||
|
fmt.Fprintf(&b, " %s %s: minted by the mesh\n", what, name)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// And its settings on this machine, composed against its definition (rule 1, rule 6).
|
||||||
|
for _, layer := range c.layers {
|
||||||
|
keys := make([]string, 0, len(layer.Values))
|
||||||
|
for k := range layer.Values {
|
||||||
|
keys = append(keys, k)
|
||||||
|
}
|
||||||
|
sort.Strings(keys)
|
||||||
|
fmt.Fprintf(&b, " settings from %s: %s\n", layer.From, strings.Join(keys, ", "))
|
||||||
|
}
|
||||||
|
if c.settingsRefused != "" {
|
||||||
|
fmt.Fprintf(&b, " SETTINGS DO NOT COMPOSE with the module's definition, so the push leaves it out: %s\n", c.settingsRefused)
|
||||||
|
}
|
||||||
|
preview = strings.TrimRight(b.String(), "\n")
|
||||||
|
sum := sha256.Sum256([]byte(preview))
|
||||||
|
return preview, refusals, hex.EncodeToString(sum[:])[:12]
|
||||||
}
|
}
|
||||||
|
|
||||||
// facts is a held thing's facts as the preview reads them.
|
// facts is a held thing's facts as the preview reads them.
|
||||||
@@ -286,6 +487,13 @@ func factsOf(h inventory.Held) facts {
|
|||||||
|
|
||||||
// comparisonLines says a held thing's facts the way a person weighs them.
|
// comparisonLines says a held thing's facts the way a person weighs them.
|
||||||
func comparisonLines(h inventory.Held) []string {
|
func comparisonLines(h inventory.Held) []string {
|
||||||
|
return comparisonLinesWith(h, nil, inventory.Adoption{})
|
||||||
|
}
|
||||||
|
|
||||||
|
// comparisonLinesWith is comparisonLines knowing which found networks this machine's setting keeps
|
||||||
|
// for the container (rule 4) and what the machine reports reachable, so a published port's reach
|
||||||
|
// is said beside the port (rule 1).
|
||||||
|
func comparisonLinesWith(h inventory.Held, keeps []string, reported inventory.Adoption) []string {
|
||||||
f := factsOf(h)
|
f := factsOf(h)
|
||||||
var out []string
|
var out []string
|
||||||
if f.image != "" || f.declaredImage != "" {
|
if f.image != "" || f.declaredImage != "" {
|
||||||
@@ -311,14 +519,46 @@ func comparisonLines(h inventory.Held) []string {
|
|||||||
}
|
}
|
||||||
sort.Strings(names)
|
sort.Strings(names)
|
||||||
for _, n := range names {
|
for _, n := range names {
|
||||||
if members := f.networks[n]; len(members) > 0 {
|
members := f.networks[n]
|
||||||
out = append(out, fmt.Sprintf("on the network %s with %s, which may reach it by name and will not once it moves to the module's own network",
|
if len(members) == 0 {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if slices.Contains(keeps, n) {
|
||||||
|
out = append(out, fmt.Sprintf("on the network %s with %s — kept by this machine's setting, so they still reach it by name once taken",
|
||||||
n, strings.Join(members, ", ")))
|
n, strings.Join(members, ", ")))
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
out = append(out, fmt.Sprintf("on the network %s with %s, which may reach it by name and will not once it moves to the module's own network"+
|
||||||
|
" (`settings set %s --node <node>` with {%q: {<container>: [%q]}} keeps it)",
|
||||||
|
n, strings.Join(members, ", "), h.Module, catalogue.NetworksSetting, n))
|
||||||
|
}
|
||||||
|
for _, n := range keeps {
|
||||||
|
if _, found := f.networks[n]; !found {
|
||||||
|
out = append(out, fmt.Sprintf("keeps the network %s by this machine's setting, which the found container is not on", n))
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if len(f.ports) > 0 || len(f.declaredPorts) > 0 {
|
if len(f.ports) > 0 || len(f.declaredPorts) > 0 {
|
||||||
out = append(out, fmt.Sprintf("publishes %s; the module declares %s",
|
out = append(out, fmt.Sprintf("publishes %s; the module declares %s",
|
||||||
orNone(strings.Join(f.ports, " ")), orNone(strings.Join(f.declaredPorts, " "))))
|
orNone(strings.Join(f.ports, " ")), orNone(strings.Join(f.declaredPorts, " "))))
|
||||||
|
// How far each published port reaches now, as the machine reported it: the listener the
|
||||||
|
// runtime publishes for this container. The found firewall's and the guard's rules are
|
||||||
|
// not read; what they let through is said as what was reported reachable.
|
||||||
|
var reach []string
|
||||||
|
for _, r := range reported.Reachable {
|
||||||
|
if r.By == h.Target && r.Published {
|
||||||
|
reach = append(reach, fmt.Sprintf("%s:%d (%s, container port %d)", r.Address, r.Port, r.Protocol, r.ContainerPort))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
switch {
|
||||||
|
case len(reach) > 0:
|
||||||
|
line := "reachable now at " + strings.Join(reach, ", ")
|
||||||
|
if reported.Firewall != "" && reported.Firewall != "none" {
|
||||||
|
line += ", behind the found firewall (" + reported.Firewall + "), whose rules are not read"
|
||||||
|
}
|
||||||
|
out = append(out, line)
|
||||||
|
case len(f.ports) > 0 && len(reported.Reachable) > 0:
|
||||||
|
out = append(out, "not reported reachable on the machine")
|
||||||
|
}
|
||||||
}
|
}
|
||||||
if len(f.mounts) > 0 || len(f.declaredVolumes) > 0 {
|
if len(f.mounts) > 0 || len(f.declaredVolumes) > 0 {
|
||||||
out = append(out, fmt.Sprintf("mounts %s; the module declares %s",
|
out = append(out, fmt.Sprintf("mounts %s; the module declares %s",
|
||||||
@@ -480,7 +720,11 @@ func converge(ctx context.Context, open *stores, node string, yes bool, digest s
|
|||||||
}
|
}
|
||||||
derived := derivedFilter{rules: rules, foundation: with.Foundation, mesh: with.Mesh,
|
derived := derivedFilter{rules: rules, foundation: with.Foundation, mesh: with.Mesh,
|
||||||
outward: plan.PublicDomain != "", outwardLinks: with.OutwardLinks}
|
outward: plan.PublicDomain != "", outwardLinks: with.OutwardLinks}
|
||||||
preview, saw := previewOf(node, reported, derived, plan, taken, filter, runs[filter])
|
filtering, err := inv.FilteringOf(ctx, node)
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
preview, saw := previewOf(node, reported, filtering, derived, plan, taken, filter, runs[filter])
|
||||||
preview += "\n\n preview " + saw
|
preview += "\n\n preview " + saw
|
||||||
if !yes {
|
if !yes {
|
||||||
return preview + fmt.Sprintf("\n\nNothing has changed. Run `converge %s --yes %s` to do "+
|
return preview + fmt.Sprintf("\n\nNothing has changed. Run `converge %s --yes %s` to do "+
|
||||||
@@ -550,7 +794,7 @@ func converge(ctx context.Context, open *stores, node string, yes bool, digest s
|
|||||||
// previewOf is what converging a node will change, before it changes it, and a short digest of
|
// previewOf is what converging a node will change, before it changes it, and a short digest of
|
||||||
// what it said: every reachable thing and its fate, the modules the flip takes and the filter. The
|
// what it said: every reachable thing and its fate, the modules the flip takes and the filter. The
|
||||||
// digest is what the flip is asked to act on, so it changes whenever any of those would.
|
// digest is what the flip is asked to act on, so it changes whenever any of those would.
|
||||||
func previewOf(node string, reported inventory.Adoption, derived derivedFilter,
|
func previewOf(node string, reported inventory.Adoption, filtering inventory.Filtering, derived derivedFilter,
|
||||||
plan catalogue.Resolution, taken []string, filter string, filterAssigned bool) (string, string) {
|
plan catalogue.Resolution, taken []string, filter string, filterAssigned bool) (string, string) {
|
||||||
var said []string
|
var said []string
|
||||||
var b strings.Builder
|
var b strings.Builder
|
||||||
@@ -642,6 +886,30 @@ func previewOf(node string, reported inventory.Adoption, derived derivedFilter,
|
|||||||
fmt.Fprintf(&b, " the found firewall (%s) is disabled, never flushed: its configuration stays on disk\n", fw)
|
fmt.Fprintf(&b, " the found firewall (%s) is disabled, never flushed: its configuration stays on disk\n", fw)
|
||||||
}
|
}
|
||||||
said = append(said, fmt.Sprintf("filter %s assigned=%t firewall=%s", filter, filterAssigned, fw))
|
said = append(said, fmt.Sprintf("filter %s assigned=%t firewall=%s", filter, filterAssigned, fw))
|
||||||
|
// What filters the machine now, and the fate of each (novox/hq ADR 0168): the found firewall
|
||||||
|
// retired, the runtime's own and bans left, and what the mesh did not write left and named —
|
||||||
|
// so the reader knows before the flip that the machine will not be filtered by the mesh alone.
|
||||||
|
if len(filtering.Filters) > 0 {
|
||||||
|
b.WriteString("\n what filters the machine now, and what the flip does to each:\n")
|
||||||
|
for _, x := range filtering.Filters {
|
||||||
|
fate := "left: " + x.Owner + "'s"
|
||||||
|
switch x.Owner {
|
||||||
|
case inventory.FilterMesh:
|
||||||
|
fate = "the mesh's guard; replaced by its filter"
|
||||||
|
case inventory.FilterFoundFirewall:
|
||||||
|
fate = "the found firewall's; retired with it"
|
||||||
|
case inventory.FilterRuntime:
|
||||||
|
fate = "the container runtime's own; left"
|
||||||
|
case inventory.FilterBan:
|
||||||
|
fate = "a ban list; left"
|
||||||
|
case inventory.FilterOther:
|
||||||
|
fate = "NOT THE MESH'S; left in force — the machine is not filtered by the mesh alone until you remove it"
|
||||||
|
}
|
||||||
|
fmt.Fprintf(&b, " %-50s %s\n", x.Where, fate)
|
||||||
|
fmt.Fprintf(&b, " %-50s %s\n", "", x.Refuses)
|
||||||
|
said = append(said, "filter "+x.Owner+" "+x.Where)
|
||||||
|
}
|
||||||
|
}
|
||||||
// Sorted: the same account, reported in another order, is the same preview.
|
// Sorted: the same account, reported in another order, is the same preview.
|
||||||
sort.Strings(said)
|
sort.Strings(said)
|
||||||
sum := sha256.Sum256([]byte(strings.Join(said, "\n")))
|
sum := sha256.Sum256([]byte(strings.Join(said, "\n")))
|
||||||
@@ -767,21 +1035,29 @@ func adopt(ctx context.Context, open *stores, node string) (string, error) {
|
|||||||
// takeCommand, convergeCommand and adoptCommand are the command line's adapters to the acts above.
|
// takeCommand, convergeCommand and adoptCommand are the command line's adapters to the acts above.
|
||||||
func takeCommand(ctx context.Context, args []string) error {
|
func takeCommand(ctx context.Context, args []string) error {
|
||||||
set := flag.NewFlagSet("take", flag.ContinueOnError)
|
set := flag.NewFlagSet("take", flag.ContinueOnError)
|
||||||
yes := set.Bool("yes", false, "cut over as previewed; without it the comparison is printed and nothing is taken")
|
yes := set.Bool("yes", false, "cut over as previewed, naming the digest the preview printed after it; "+
|
||||||
|
"without it the comparison is printed and nothing is taken")
|
||||||
downgrade := set.Bool("downgrade", false, "take it although the module's image is older than the one running")
|
downgrade := set.Bool("downgrade", false, "take it although the module's image is older than the one running")
|
||||||
var replace stringList
|
var replace, mint stringList
|
||||||
set.Var(&replace, "replace", "a found file's path whose content the module may replace although it differs (repeatable; * for every one)")
|
set.Var(&replace, "replace", "a found file's path whose content the module may replace although it differs (repeatable; * for every one)")
|
||||||
|
set.Var(&mint, "mint", "a secret the service shall take the mesh's minted value for, although it already has its own (repeatable)")
|
||||||
positionals, err := parseAround(set, args)
|
positionals, err := parseAround(set, args)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
if len(positionals) != 2 {
|
if len(positionals) < 2 || len(positionals) > 3 || (len(positionals) == 3 && !*yes) {
|
||||||
return errors.New("take <node> <module> [--yes] [--downgrade] [--replace <path>]...")
|
return errors.New("take <node> <module> [--yes <digest>] [--downgrade] [--replace <path>]... [--mint <secret>]...")
|
||||||
|
}
|
||||||
|
opts := takeOptions{Yes: *yes, Downgrade: *downgrade, Replace: map[string]bool{}, Mint: map[string]bool{}}
|
||||||
|
if len(positionals) == 3 {
|
||||||
|
opts.Digest = positionals[2]
|
||||||
}
|
}
|
||||||
opts := takeOptions{Yes: *yes, Downgrade: *downgrade, Replace: map[string]bool{}}
|
|
||||||
for _, r := range replace {
|
for _, r := range replace {
|
||||||
opts.Replace[r] = true
|
opts.Replace[r] = true
|
||||||
}
|
}
|
||||||
|
for _, m := range mint {
|
||||||
|
opts.Mint[m] = true
|
||||||
|
}
|
||||||
return runAct(ctx, func(open *stores) (string, error) { return take(ctx, open, positionals[0], positionals[1], opts) })
|
return runAct(ctx, func(open *stores) (string, error) { return take(ctx, open, positionals[0], positionals[1], opts) })
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -102,7 +102,7 @@ func commands(who Authenticator) http.Handler {
|
|||||||
}))
|
}))
|
||||||
// Adoption (novox/hq ADR 0100): the same acts as `take`, `converge` and `adopt`.
|
// Adoption (novox/hq ADR 0100): the same acts as `take`, `converge` and `adopt`.
|
||||||
mux.HandleFunc("POST /take", acting(who, true, func(ctx context.Context, open *stores, in request) (string, error) {
|
mux.HandleFunc("POST /take", acting(who, true, func(ctx context.Context, open *stores, in request) (string, error) {
|
||||||
return take(ctx, open, in.Node, in.Module, takeOptions{Yes: true})
|
return take(ctx, open, in.Node, in.Module, takeOptions{Yes: in.Yes, Digest: in.Digest})
|
||||||
}))
|
}))
|
||||||
mux.HandleFunc("POST /converge", acting(who, false, func(ctx context.Context, open *stores, in request) (string, error) {
|
mux.HandleFunc("POST /converge", acting(who, false, func(ctx context.Context, open *stores, in request) (string, error) {
|
||||||
return converge(ctx, open, in.Node, in.Yes, in.Digest, in.Filter)
|
return converge(ctx, open, in.Node, in.Yes, in.Digest, in.Filter)
|
||||||
@@ -124,8 +124,8 @@ func commands(who Authenticator) http.Handler {
|
|||||||
type request struct {
|
type request struct {
|
||||||
Node string `json:"node"`
|
Node string `json:"node"`
|
||||||
Module string `json:"module"`
|
Module string `json:"module"`
|
||||||
// Yes, Digest and Filter are converge's: do it rather than preview it, the digest of the
|
// Yes, Digest and Filter are converge's and take's: do it rather than preview it, the digest
|
||||||
// preview it acts on, and which module loads the mesh's filter.
|
// of the preview it acts on, and (converge) which module loads the mesh's filter.
|
||||||
Yes bool `json:"yes,omitempty"`
|
Yes bool `json:"yes,omitempty"`
|
||||||
Digest string `json:"digest,omitempty"`
|
Digest string `json:"digest,omitempty"`
|
||||||
Filter string `json:"filter,omitempty"`
|
Filter string `json:"filter,omitempty"`
|
||||||
|
|||||||
@@ -522,6 +522,8 @@ func takeIn(ctx context.Context, inv *inventory.Inventory, result link.BuildResu
|
|||||||
recorded := inventory.Source{
|
recorded := inventory.Source{
|
||||||
Repository: result.Repository, Path: result.Path, Ref: result.Ref,
|
Repository: result.Repository, Path: result.Path, Ref: result.Ref,
|
||||||
BuiltFrom: result.Commit, Head: result.Commit,
|
BuiltFrom: result.Commit, Head: result.Commit,
|
||||||
|
// What it stood on, so registration can judge a built manifest's base (to-be 38 WP2.4).
|
||||||
|
Against: kept.Against,
|
||||||
}
|
}
|
||||||
if result.Source != nil && result.Source.Seat != "" {
|
if result.Source != nil && result.Source.Seat != "" {
|
||||||
recorded.Repository, recorded.Seat = result.Source.Repository, result.Source.Seat
|
recorded.Repository, recorded.Seat = result.Source.Repository, result.Source.Seat
|
||||||
@@ -607,6 +609,10 @@ type answers struct {
|
|||||||
// a consequence of the refusals above: a node that does not resolve is not on the network, and
|
// a consequence of the refusals above: a node that does not resolve is not on the network, and
|
||||||
// a mesh whose hub is that node has no hub.
|
// a mesh whose hub is that node has no hub.
|
||||||
network string
|
network string
|
||||||
|
// filtered is every converged machine that is not filtered by the mesh alone (novox/hq ADR
|
||||||
|
// 0168): what filters it beyond the mesh's own, the runtime's plumbing and bans, by name — a
|
||||||
|
// predecessor's chain, a found firewall in force again. Such a machine is not "all well".
|
||||||
|
filtered map[string]inventory.Filtering
|
||||||
// untaken is, per machine, each assigned module whose resources the machine is holding as it
|
// untaken is, per machine, each assigned module whose resources the machine is holding as it
|
||||||
// found them, and how many — a module that was assigned, sent, and is running none of what it
|
// found them, and how many — a module that was assigned, sent, and is running none of what it
|
||||||
// declares because nothing has taken it (novox/hq ADR 0100, 04-ISSUES/125).
|
// declares because nothing has taken it (novox/hq ADR 0100, 04-ISSUES/125).
|
||||||
|
|||||||
@@ -180,7 +180,8 @@ func usage() {
|
|||||||
api --issuer URL [--listen A] assign and unassign over http, for a surface that is not here
|
api --issuer URL [--listen A] assign and unassign over http, for a surface that is not here
|
||||||
assign <node> <module> put a module on a node
|
assign <node> <module> put a module on a node
|
||||||
unassign <node> <module> take it off
|
unassign <node> <module> take it off
|
||||||
take <node> <module> cut a module over on an adopted node, once its data has moved
|
take <node> <module> preview a module's cutover on an adopted node: what runs beside
|
||||||
|
what it declares; --yes <digest> cuts it over as previewed
|
||||||
converge <node> [--yes <digest>] [--filter nftables] preview, then make, an adopted node converged
|
converge <node> [--yes <digest>] [--filter nftables] preview, then make, an adopted node converged
|
||||||
adopt <node> return a converged node to adopted; what was taken stays taken
|
adopt <node> return a converged node to adopted; what was taken stays taken
|
||||||
settings set <module> <file> what a module's config should say, for the whole mesh
|
settings set <module> <file> what a module's config should say, for the whole mesh
|
||||||
|
|||||||
@@ -352,10 +352,14 @@ func settingsCommand(ctx context.Context, args []string) error {
|
|||||||
switch args[0] {
|
switch args[0] {
|
||||||
case "set":
|
case "set":
|
||||||
if len(positionals) != 2 {
|
if len(positionals) != 2 {
|
||||||
return errors.New("settings set <module> <settings.json> [--node <node>]")
|
return errors.New("settings set <module> <settings.json | {…}> [--node <node>]")
|
||||||
}
|
}
|
||||||
raw, err := os.ReadFile(positionals[1])
|
// A file, or the values themselves when they begin with `{` — which is how the mesh's own
|
||||||
if err != nil {
|
// `settings` tool passes them, having no file to hand over (novox/hq issue 198).
|
||||||
|
var raw []byte
|
||||||
|
if strings.HasPrefix(strings.TrimSpace(positionals[1]), "{") {
|
||||||
|
raw = []byte(positionals[1])
|
||||||
|
} else if raw, err = os.ReadFile(positionals[1]); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
var values map[string]any
|
var values map[string]any
|
||||||
@@ -553,7 +557,7 @@ func issueOnTheNewBus(ctx context.Context, inv *inventory.Inventory, m catalogue
|
|||||||
|
|
||||||
user := broker.Principal{Kind: broker.KindModule, Node: node, Module: m.Module}.Username()
|
user := broker.Principal{Kind: broker.KindModule, Node: node, Module: m.Module}.Username()
|
||||||
password, err := inv.MintBusPassword(ctx, inventory.BusUser{
|
password, err := inv.MintBusPassword(ctx, inventory.BusUser{
|
||||||
Username: user, Kind: inventory.BusModule, Node: node, Module: m.Module,
|
Username: user, Kind: busKindOf(m.Module), Node: node, Module: m.Module,
|
||||||
})
|
})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
@@ -573,6 +577,16 @@ func issueOnTheNewBus(ctx context.Context, inv *inventory.Inventory, m catalogue
|
|||||||
return issueWith(ctx, inv, m, node, busAddress, known, reachable, user, password)
|
return issueWith(ctx, inv, m, node, busAddress, known, reachable, user, password)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// busKindOf is what a module's bus user is recorded as: the node's tool runtime where the module is
|
||||||
|
// the runtime (novox/hq ADR 0175), a module otherwise. The username is the same either way — the
|
||||||
|
// runtime is issued through this same path — and the kind is what a reader of the records sees.
|
||||||
|
func busKindOf(module string) string {
|
||||||
|
if module == catalogue.RuntimeModule {
|
||||||
|
return inventory.BusNodeTools
|
||||||
|
}
|
||||||
|
return inventory.BusModule
|
||||||
|
}
|
||||||
|
|
||||||
// issueWith is the delivery half: the minted password sealed to the machine as the module's broker
|
// issueWith is the delivery half: the minted password sealed to the machine as the module's broker
|
||||||
// secret, and the module's consumer created where the bus can be reached. Split from the minting
|
// secret, and the module's consumer created where the bus can be reached. Split from the minting
|
||||||
// so the move can issue every module against a bus whose address it worked out itself
|
// so the move can issue every module against a bus whose address it worked out itself
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
package main
|
package main
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"reflect"
|
||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
"time"
|
||||||
@@ -191,7 +192,7 @@ func TestWhatAHandedOverModuleRecordsAboutItsSource(t *testing.T) {
|
|||||||
t.Fatalf("the source records as %+v", from)
|
t.Fatalf("the source records as %+v", from)
|
||||||
}
|
}
|
||||||
// A manifest with no provenance at all is legitimate: fixing something in a hurry.
|
// A manifest with no provenance at all is legitimate: fixing something in a hurry.
|
||||||
if from, err := whereItComesFrom("", "", "", "", false); err != nil || from != (inventory.Source{}) {
|
if from, err := whereItComesFrom("", "", "", "", false); err != nil || !reflect.DeepEqual(from, inventory.Source{}) {
|
||||||
t.Fatalf("a manifest handed over with no provenance was refused: %+v, %v", from, err)
|
t.Fatalf("a manifest handed over with no provenance was refused: %+v, %v", from, err)
|
||||||
}
|
}
|
||||||
for _, c := range []struct {
|
for _, c := range []struct {
|
||||||
|
|||||||
+50
-15
@@ -186,8 +186,12 @@ func planFor(ctx context.Context, open *stores, nodeName string) (catalogue.Reso
|
|||||||
// Settings for everything that resolved, including modules nobody assigned directly: a
|
// Settings for everything that resolved, including modules nobody assigned directly: a
|
||||||
// requirement pulled in by something else is still configurable, and finding out that it is
|
// requirement pulled in by something else is still configurable, and finding out that it is
|
||||||
// not only when you try would be an arbitrary line nobody could predict.
|
// not only when you try would be an arbitrary line nobody could predict.
|
||||||
|
//
|
||||||
|
// A setting that reaches nothing, or cannot compose with the definition it was stored for,
|
||||||
|
// no longer refuses the machine here: it is judged where it is stored, and a definition that
|
||||||
|
// moved under it costs that module its place in the declaration, said by name (novox/hq ADR
|
||||||
|
// 0163, rule 6 — see Compose).
|
||||||
settings := catalogue.SettingsBy{}
|
settings := catalogue.SettingsBy{}
|
||||||
var stray []string
|
|
||||||
for _, m := range resolved.Modules {
|
for _, m := range resolved.Modules {
|
||||||
layers, err := inv.SettingsFor(ctx, nodeName, m.Module)
|
layers, err := inv.SettingsFor(ctx, nodeName, m.Module)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -197,18 +201,6 @@ func planFor(ctx context.Context, open *stores, nodeName string) (catalogue.Reso
|
|||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
settings[m.Module] = layers
|
settings[m.Module] = layers
|
||||||
stray = append(stray, catalogue.UnusedSettings(m, layers)...)
|
|
||||||
}
|
|
||||||
if len(stray) > 0 {
|
|
||||||
// Somebody set something that reaches no file. Said here rather than discovered by the
|
|
||||||
// machine not behaving differently, which is the slowest way there is.
|
|
||||||
//
|
|
||||||
// Marked like a set that will not compose, and for the same reason: it is a standing fact
|
|
||||||
// about this node's own configuration, not a question the mesh could not answer. A gatherer
|
|
||||||
// passes over it as it always did — one node's stray setting must not stop every other node
|
|
||||||
// being described (novox/hq 04-ISSUES/152).
|
|
||||||
return catalogue.Resolution{}, nil, notResolvable{fmt.Errorf(
|
|
||||||
"these settings reach nothing:\n - %s", strings.Join(stray, "\n - "))}
|
|
||||||
}
|
}
|
||||||
return resolved, settings, nil
|
return resolved, settings, nil
|
||||||
}
|
}
|
||||||
@@ -404,7 +396,33 @@ func declarationWith(ctx context.Context, open *stores, node string,
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return sendable{}, err
|
return sendable{}, err
|
||||||
}
|
}
|
||||||
return sendable{Resources: composed.Resources, Adoption: adoption}, nil
|
return sendable{Resources: composed.Resources, Adoption: adoption,
|
||||||
|
Received: composed.Received, Mesh: with.Mesh,
|
||||||
|
LeftOut: sortedKeysOf(composed.LeftOut), leftOutWhy: composed.LeftOut}, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// sortedKeysOf is a map's keys, sorted — so what a declaration says it left out does not move
|
||||||
|
// for a reordering nobody made.
|
||||||
|
func sortedKeysOf(m map[string]string) []string {
|
||||||
|
if len(m) == 0 {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
out := make([]string, 0, len(m))
|
||||||
|
for k := range m {
|
||||||
|
out = append(out, k)
|
||||||
|
}
|
||||||
|
sort.Strings(out)
|
||||||
|
return out
|
||||||
|
}
|
||||||
|
|
||||||
|
// reportLeftOut says which of a machine's modules its declaration leaves out and why (novox/hq ADR
|
||||||
|
// 0163, rule 6), one line each: the machine is told everything else, and is told it was left out.
|
||||||
|
func reportLeftOut(node string, declared sendable) {
|
||||||
|
for _, m := range declared.LeftOut {
|
||||||
|
fmt.Printf("%s: %s left out — a setting stored for it cannot compose with its definition; "+
|
||||||
|
"what the machine holds for it is kept and its containers are untouched. %s\n",
|
||||||
|
node, m, declared.leftOutWhy[m])
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// renderingFor is everything a node's declaration is composed with, and the node's record.
|
// renderingFor is everything a node's declaration is composed with, and the node's record.
|
||||||
@@ -444,7 +462,10 @@ func renderingFor(ctx context.Context, open *stores, node string,
|
|||||||
for _, m := range plan.Modules {
|
for _, m := range plan.Modules {
|
||||||
g, err := catalogue.GivenPorts(m, settings[m.Module])
|
g, err := catalogue.GivenPorts(m, settings[m.Module])
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return catalogue.Rendering{}, inventory.Node{}, err
|
// A given port its definition no longer publishes: the module is left out of the
|
||||||
|
// declaration, by name, when it is composed (novox/hq ADR 0163, rule 6) — never the
|
||||||
|
// machine refused here for it.
|
||||||
|
continue
|
||||||
}
|
}
|
||||||
if g != nil {
|
if g != nil {
|
||||||
given[m.Module] = g
|
given[m.Module] = g
|
||||||
@@ -999,6 +1020,20 @@ func planCommand(ctx context.Context, args []string) error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Which modules a push would leave out, and why — said before the plan, since the plan is of
|
||||||
|
// what the machine would be told (novox/hq ADR 0163, rule 6). Judged, never composed: `plan`
|
||||||
|
// without --json allocates nothing.
|
||||||
|
if record, err := open.inventory.NodeByName(ctx, args[0]); err == nil {
|
||||||
|
left := plan.LeftOut(settings, record.Adopted)
|
||||||
|
reportLeftOut(args[0], sendable{LeftOut: sortedKeysOf(left), leftOutWhy: left})
|
||||||
|
}
|
||||||
|
// And a setting that reaches nothing — refused where it is stored, and said here for one
|
||||||
|
// stored before its definition moved from under it.
|
||||||
|
for _, m := range plan.Modules {
|
||||||
|
for _, stray := range catalogue.UnusedSettings(m, settings[m.Module]) {
|
||||||
|
fmt.Printf("%s: a setting reaches nothing — %s\n", args[0], stray)
|
||||||
|
}
|
||||||
|
}
|
||||||
fmt.Printf("%s would run:\n", args[0])
|
fmt.Printf("%s would run:\n", args[0])
|
||||||
for _, m := range plan.Modules {
|
for _, m := range plan.Modules {
|
||||||
fmt.Printf(" %-20s %s\n", m.Module, plan.Because[m.Module])
|
fmt.Printf(" %-20s %s\n", m.Module, plan.Because[m.Module])
|
||||||
|
|||||||
+42
-13
@@ -131,10 +131,17 @@ func serve(ctx context.Context) error {
|
|||||||
|
|
||||||
// And the mesh's own verbs, as the seat this control plane holds (novox/hq ADR 0154). Served
|
// And the mesh's own verbs, as the seat this control plane holds (novox/hq ADR 0154). Served
|
||||||
// from the store's row, so what the seat declares is what is answered.
|
// from the store's row, so what the seat declares is what is answered.
|
||||||
handlers, err := seatToolHandlers()
|
handlers, behind, err := seatToolHandlers()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
if len(behind) > 0 {
|
||||||
|
// Said once, loudly, and then served anyway (novox/hq ADR 0185): the mesh keeps answering
|
||||||
|
// while whatever put an older control plane here is undone.
|
||||||
|
fmt.Printf("this control plane is behind the %s row: it cannot run %s. "+
|
||||||
|
"Those answer the reason when called; everything else is served as usual\n",
|
||||||
|
catalogue.ControllerSeatName, strings.Join(behind, ", "))
|
||||||
|
}
|
||||||
bus, isNATS := server.Bus().(link.OverNATS)
|
bus, isNATS := server.Bus().(link.OverNATS)
|
||||||
if !isNATS {
|
if !isNATS {
|
||||||
return errors.New("the mesh's verbs are served over the bus, and this control plane is not on it")
|
return errors.New("the mesh's verbs are served over the bus, and this control plane is not on it")
|
||||||
@@ -353,7 +360,11 @@ func pushCommand(ctx context.Context, args []string) error {
|
|||||||
// The private network is in here with everything else. It used to be composed separately
|
// The private network is in here with everything else. It used to be composed separately
|
||||||
// and prepended, which meant every machine with an address was on it and no machine could
|
// and prepended, which meant every machine with an address was on it and no machine could
|
||||||
// be kept off. It is a module now, so it arrives the way a module does.
|
// be kept off. It is a module now, so it arrives the way a module does.
|
||||||
return declarationWith(held, open, node, plan, settings, gens, Allocating)
|
declared, err := declarationWith(held, open, node, plan, settings, gens, Allocating)
|
||||||
|
if err == nil {
|
||||||
|
reportLeftOut(node, declared)
|
||||||
|
}
|
||||||
|
return declared, err
|
||||||
})
|
})
|
||||||
|
|
||||||
sentDigest := map[string]string{}
|
sentDigest := map[string]string{}
|
||||||
@@ -389,11 +400,7 @@ func pushCommand(ctx context.Context, args []string) error {
|
|||||||
fmt.Printf("\n%d node(s) told\n", len(sending))
|
fmt.Printf("\n%d node(s) told\n", len(sending))
|
||||||
// And each machine's memberships, as every other send does (ADR 0160): a push is the one most
|
// And each machine's memberships, as every other send does (ADR 0160): a push is the one most
|
||||||
// operators run, and on 2026-10-01 it was the one path that issued none.
|
// operators run, and on 2026-10-01 it was the one path that issued none.
|
||||||
var told []string
|
if err := issueMemberships(ctx, open, server, sending); err != nil {
|
||||||
for _, s := range sending {
|
|
||||||
told = append(told, s.node)
|
|
||||||
}
|
|
||||||
if err := issueMemberships(ctx, open, server, told); err != nil {
|
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -458,7 +465,11 @@ func pushCommand(ctx context.Context, args []string) error {
|
|||||||
return sendable{}, err
|
return sendable{}, err
|
||||||
}
|
}
|
||||||
reportUnhostable(node, plan)
|
reportUnhostable(node, plan)
|
||||||
return declarationWith(held, open, node, plan, settings, gens, Allocating)
|
declared, err := declarationWith(held, open, node, plan, settings, gens, Allocating)
|
||||||
|
if err == nil {
|
||||||
|
reportLeftOut(node, declared)
|
||||||
|
}
|
||||||
|
return declared, err
|
||||||
},
|
},
|
||||||
func(s readyNode, body []byte) error {
|
func(s readyNode, body []byte) error {
|
||||||
if err := link.Declare(ctx, server.Bus(), ident, s.node, body,
|
if err := link.Declare(ctx, server.Bus(), ident, s.node, body,
|
||||||
@@ -670,6 +681,7 @@ func sendTo(ctx context.Context, open *stores, names []string) error {
|
|||||||
refusals = append(refusals, fmt.Sprintf("%s:\n%v", name, err))
|
refusals = append(refusals, fmt.Sprintf("%s:\n%v", name, err))
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
reportLeftOut(name, declared)
|
||||||
sending = append(sending, readyNode{name, declared})
|
sending = append(sending, readyNode{name, declared})
|
||||||
}
|
}
|
||||||
if len(refusals) > 0 {
|
if len(refusals) > 0 {
|
||||||
@@ -706,11 +718,15 @@ func sendTo(ctx context.Context, open *stores, names []string) error {
|
|||||||
// And every assignment on those machines its membership (novox/hq ADR 0160): composed from the
|
// And every assignment on those machines its membership (novox/hq ADR 0160): composed from the
|
||||||
// same records the bus's accounts are, so what a runtime serves and what its account may are one
|
// same records the bus's accounts are, so what a runtime serves and what its account may are one
|
||||||
// composition. Issued after the declaration, because the runtime it is for arrives with it.
|
// composition. Issued after the declaration, because the runtime it is for arrives with it.
|
||||||
return issueMemberships(ctx, open, server, names)
|
return issueMemberships(ctx, open, server, sending)
|
||||||
}
|
}
|
||||||
|
|
||||||
// issueMemberships publishes the membership of every module on the named machines.
|
// issueMemberships publishes the membership of every module on the machines just sent.
|
||||||
func issueMemberships(ctx context.Context, open *stores, server *link.Server, names []string) error {
|
//
|
||||||
|
// Each carries what its module receives and the private network's addresses, from the same
|
||||||
|
// composition as the declaration it was sent (novox/hq ADR 0167): a provider reads what it is
|
||||||
|
// given on the bus, and the file written beside it says the same thing.
|
||||||
|
func issueMemberships(ctx context.Context, open *stores, server *link.Server, sent []readyNode) error {
|
||||||
records, err := open.inventory.BusRecords(ctx)
|
records, err := open.inventory.BusRecords(ctx)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
@@ -725,9 +741,22 @@ func issueMemberships(ctx context.Context, open *stores, server *link.Server, na
|
|||||||
// the push stands, the first failure is named once, and the next push tries again.
|
// the push stands, the first failure is named once, and the next push tries again.
|
||||||
issued, failed := 0, 0
|
issued, failed := 0, 0
|
||||||
var first error
|
var first error
|
||||||
for _, node := range names {
|
for _, s := range sent {
|
||||||
|
node := s.node
|
||||||
for _, d := range records.Assigned[node] {
|
for _, d := range records.Assigned[node] {
|
||||||
body, err := json.Marshal(broker.MembershipFor(node, d, where))
|
membership := broker.MembershipFor(node, d, where)
|
||||||
|
membership.Mesh = s.declared.Mesh
|
||||||
|
for requirement, given := range s.declared.Received[d.Module] {
|
||||||
|
raw, err := json.Marshal(given)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if membership.Receives == nil {
|
||||||
|
membership.Receives = map[string]json.RawMessage{}
|
||||||
|
}
|
||||||
|
membership.Receives[requirement] = raw
|
||||||
|
}
|
||||||
|
body, err := json.Marshal(membership)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ package main
|
|||||||
import (
|
import (
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"github.com/novox/mesh-controller/internal/inventory"
|
||||||
"sort"
|
"sort"
|
||||||
"time"
|
"time"
|
||||||
)
|
)
|
||||||
@@ -66,6 +67,21 @@ type meshStatus struct {
|
|||||||
// **A document without this said an outage was a well mesh.** Read from what each machine
|
// **A document without this said an outage was a well mesh.** Read from what each machine
|
||||||
// reported, so it is the machine's account and not the mesh's take-time listing.
|
// reported, so it is the machine's account and not the mesh's take-time listing.
|
||||||
Untaken []machineUntaken `json:"untaken,omitempty"`
|
Untaken []machineUntaken `json:"untaken,omitempty"`
|
||||||
|
// Filtered is every converged machine that is not filtered by the mesh alone (novox/hq ADR
|
||||||
|
// 0168), one entry per rule set the mesh did not write — the found firewall in force again,
|
||||||
|
// or a chain nobody speaks for. Absent when every converged machine is filtered by the mesh
|
||||||
|
// alone. A document without this called a machine well while a predecessor's chain refused
|
||||||
|
// what the mesh declared open.
|
||||||
|
Filtered []machineFiltered `json:"filtered,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// machineFiltered is one rule set on a converged machine that the mesh did not write and that
|
||||||
|
// refuses traffic: where it is, whose the host reads it as, and what it refuses.
|
||||||
|
type machineFiltered struct {
|
||||||
|
Node string `json:"node"`
|
||||||
|
Where string `json:"where"`
|
||||||
|
Owner string `json:"owner"`
|
||||||
|
Refuses string `json:"refuses"`
|
||||||
}
|
}
|
||||||
|
|
||||||
// machineUntaken is one module a machine is holding rather than running, and how many resources of
|
// machineUntaken is one module a machine is holding rather than running, and how many resources of
|
||||||
@@ -173,6 +189,21 @@ func statusAsJSON(asked answers) ([]byte, error) {
|
|||||||
machineUntaken{Node: name, Module: m, Held: asked.untaken[name][m]})
|
machineUntaken{Node: name, Module: m, Held: asked.untaken[name][m]})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
filteredNodes := make([]string, 0, len(asked.filtered))
|
||||||
|
for name := range asked.filtered {
|
||||||
|
filteredNodes = append(filteredNodes, name)
|
||||||
|
}
|
||||||
|
sort.Strings(filteredNodes)
|
||||||
|
for _, name := range filteredNodes {
|
||||||
|
f := asked.filtered[name]
|
||||||
|
if fw := f.FoundFirewall; fw != nil && fw.Active {
|
||||||
|
out.Filtered = append(out.Filtered, machineFiltered{Node: name, Where: "the found firewall",
|
||||||
|
Owner: inventory.FilterFoundFirewall, Refuses: fw.Kind + " is in force again"})
|
||||||
|
}
|
||||||
|
for _, x := range f.Others() {
|
||||||
|
out.Filtered = append(out.Filtered, machineFiltered{Node: name, Where: x.Where, Owner: x.Owner, Refuses: x.Refuses})
|
||||||
|
}
|
||||||
|
}
|
||||||
for name := range asked.refused {
|
for name := range asked.refused {
|
||||||
out.Unresolved = append(out.Unresolved, machineUnresolved{
|
out.Unresolved = append(out.Unresolved, machineUnresolved{
|
||||||
Node: name, Problem: asked.refused[name]})
|
Node: name, Problem: asked.refused[name]})
|
||||||
|
|||||||
@@ -167,3 +167,46 @@ func TestAMachineFailingTheSameWayIsSaidToBeStuck(t *testing.T) {
|
|||||||
t.Fatalf("one failure is not stuck: %v", once)
|
t.Fatalf("one failure is not stuck: %v", once)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// A converged machine something other than the mesh filters is named, per rule set, and is not
|
||||||
|
// well (novox/hq ADR 0168); one filtered by the mesh alone is not in the list.
|
||||||
|
func TestAMachineNotFilteredByTheMeshAloneIsNamedAndNotWell(t *testing.T) {
|
||||||
|
alone := inventory.Filtering{Filters: []inventory.Filter{
|
||||||
|
{Where: "table inet mesh, chain input", Owner: inventory.FilterMesh, Refuses: "policy drop"},
|
||||||
|
{Where: "table ip filter, chain DOCKER", Owner: inventory.FilterRuntime, Refuses: "drop"},
|
||||||
|
{Where: "table ip filter, chain f2b-sshd", Owner: inventory.FilterBan, Refuses: "ip saddr 192.0.2.1 reject"},
|
||||||
|
}}
|
||||||
|
if !alone.Alone() {
|
||||||
|
t.Fatal("the mesh's own, the runtime's and a ban are not the mesh alone")
|
||||||
|
}
|
||||||
|
notAlone := inventory.Filtering{
|
||||||
|
Filters: append(alone.Filters, inventory.Filter{Where: "chain HAL-MESH-ONLY (iptables-legacy)",
|
||||||
|
Owner: inventory.FilterOther, Refuses: `-A HAL-MESH-ONLY -m comment --comment "not public" -j DROP`}),
|
||||||
|
FoundFirewall: &inventory.FoundFirewall{Kind: "ufw", Active: true},
|
||||||
|
}
|
||||||
|
asked := answers{nodes: []inventory.Node{{Name: "home-server"}, {Name: "laptop"}},
|
||||||
|
filtered: map[string]inventory.Filtering{"home-server": notAlone}}
|
||||||
|
if asked.well() {
|
||||||
|
t.Fatal("a machine not filtered by the mesh alone reads as well")
|
||||||
|
}
|
||||||
|
body, err := statusAsJSON(asked)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
var parsed struct {
|
||||||
|
Filtered []map[string]string `json:"filtered"`
|
||||||
|
}
|
||||||
|
if err := json.Unmarshal(body, &parsed); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if len(parsed.Filtered) != 2 {
|
||||||
|
t.Fatalf("filtered: %v", parsed.Filtered)
|
||||||
|
}
|
||||||
|
if parsed.Filtered[0]["node"] != "home-server" || parsed.Filtered[0]["owner"] != inventory.FilterFoundFirewall ||
|
||||||
|
parsed.Filtered[1]["where"] != "chain HAL-MESH-ONLY (iptables-legacy)" || parsed.Filtered[1]["owner"] != inventory.FilterOther {
|
||||||
|
t.Fatalf("filtered: %v", parsed.Filtered)
|
||||||
|
}
|
||||||
|
if body, _ := statusAsJSON(answers{nodes: asked.nodes}); strings.Contains(string(body), `"filtered"`) {
|
||||||
|
t.Fatal("a mesh filtered by itself alone carries a filtered list")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -346,7 +346,9 @@ func rolloutMint(ctx context.Context, again bool) error {
|
|||||||
}
|
}
|
||||||
machines++
|
machines++
|
||||||
|
|
||||||
case broker.KindModule:
|
case broker.KindModule, broker.KindNodeTools:
|
||||||
|
// The runtime is minted and delivered exactly as a module is (novox/hq ADR 0175): it is
|
||||||
|
// issued as the module it stands for, to that module's `broker` secret.
|
||||||
if p.Module == "mesh-controller" {
|
if p.Module == "mesh-controller" {
|
||||||
// The control plane is a module too, and its `broker` secret is the old bus's
|
// The control plane is a module too, and its `broker` secret is the old bus's
|
||||||
// credential it is still using while this runs. Writing the new bus's blob there
|
// credential it is still using while this runs. Writing the new bus's blob there
|
||||||
@@ -365,7 +367,7 @@ func rolloutMint(ctx context.Context, again bool) error {
|
|||||||
skipped++
|
skipped++
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
password, err := inv.MintBusPassword(ctx, inventory.BusUser{Username: p.Username(), Kind: inventory.BusModule, Node: p.Node, Module: p.Module})
|
password, err := inv.MintBusPassword(ctx, inventory.BusUser{Username: p.Username(), Kind: busKindOf(p.Module), Node: p.Node, Module: p.Module})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -48,6 +48,21 @@ func argvFor(verb string, args map[string]any) ([]string, error) {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
switch verb {
|
switch verb {
|
||||||
|
case "command":
|
||||||
|
// The generic verb: the command line as given, split as a shell would split it, with
|
||||||
|
// nothing added — the named verbs add flags a caller cannot reach; this one is the whole
|
||||||
|
// binary and says so in its description (novox/hq ADR 0154, 0175).
|
||||||
|
if err := need("command"); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
argv, err := splitCommandLine(str("command"))
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if len(argv) == 0 {
|
||||||
|
return nil, errors.New("command names no command")
|
||||||
|
}
|
||||||
|
return argv, nil
|
||||||
case "status":
|
case "status":
|
||||||
return []string{"status", "--json"}, nil
|
return []string{"status", "--json"}, nil
|
||||||
case "nodes":
|
case "nodes":
|
||||||
@@ -129,6 +144,33 @@ func argvFor(verb string, args map[string]any) ([]string, error) {
|
|||||||
// Half of either shape: the command says its usage, which names both shapes, and that is
|
// Half of either shape: the command says its usage, which names both shapes, and that is
|
||||||
// the answer the caller needs.
|
// the answer the caller needs.
|
||||||
return []string{"rotate"}, nil
|
return []string{"rotate"}, nil
|
||||||
|
case "settings":
|
||||||
|
// `settings set|clear` at a shell (novox/hq issue 198). The values travel as an argument
|
||||||
|
// because a tool has no file to hand the command; the command reads either.
|
||||||
|
if err := need("module"); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
argv := []string{"settings", "set", str("module")}
|
||||||
|
switch {
|
||||||
|
case str("clear") == "true":
|
||||||
|
argv = []string{"settings", "clear", str("module")}
|
||||||
|
case str("values") != "":
|
||||||
|
argv = append(argv, str("values"))
|
||||||
|
}
|
||||||
|
// Neither values nor clear: the command says its usage, which names both, and that is the
|
||||||
|
// answer the caller needs — the same as `rotate` given half of either shape.
|
||||||
|
if n := str("node"); n != "" {
|
||||||
|
argv = append(argv, "--node", n)
|
||||||
|
}
|
||||||
|
return argv, nil
|
||||||
|
case "issue":
|
||||||
|
// The same act as `module issue` at a shell (novox/hq design 25 §4): the account is minted
|
||||||
|
// into the mesh's records and delivered at the machine's next push, which is the caller's to
|
||||||
|
// ask for — so the mesh is never pushed as a side effect of a credential.
|
||||||
|
if err := need("node", "module"); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return []string{"module", "issue", str("module"), "--node", str("node")}, nil
|
||||||
case "build":
|
case "build":
|
||||||
if err := need("repository"); err != nil {
|
if err := need("repository"); err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
@@ -188,13 +230,15 @@ func runVerb(ctx context.Context, argv []string) (verbAnswer, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// seatToolHandlers are the handlers for every verb the mesh-controller seat declares, from the
|
// seatToolHandlers are the handlers for every verb the mesh-controller seat declares, from the
|
||||||
// store's row, so a verb the row does not carry is not served and a verb it carries that this binary
|
// store's row, so a verb the row does not carry is not served. A verb it carries that this binary
|
||||||
// cannot run is said at start rather than at the first call.
|
// cannot run is named at start and answers the reason when called — never a refusal to serve, which
|
||||||
func seatToolHandlers() (map[string]link.ToolHandler, error) {
|
// would take the whole control plane down for one word (novox/hq ADR 0185).
|
||||||
|
func seatToolHandlers() (map[string]link.ToolHandler, []string, error) {
|
||||||
seat, known := catalogue.SeatNamed(catalogue.ControllerSeatName)
|
seat, known := catalogue.SeatNamed(catalogue.ControllerSeatName)
|
||||||
if !known {
|
if !known {
|
||||||
return nil, fmt.Errorf("this mesh defines no %s seat", catalogue.ControllerSeatName)
|
return nil, nil, fmt.Errorf("this mesh defines no %s seat", catalogue.ControllerSeatName)
|
||||||
}
|
}
|
||||||
|
var behind []string
|
||||||
handlers := map[string]link.ToolHandler{}
|
handlers := map[string]link.ToolHandler{}
|
||||||
for _, v := range seat.Serves {
|
for _, v := range seat.Serves {
|
||||||
verb := v.Name
|
verb := v.Name
|
||||||
@@ -205,8 +249,27 @@ func seatToolHandlers() (map[string]link.ToolHandler, error) {
|
|||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
if _, err := argvFor(verb, sampleArguments(v)); err != nil {
|
if _, err := argvFor(verb, sampleArguments(v)); err != nil {
|
||||||
return nil, fmt.Errorf("the %s seat's row declares %q, which this control plane cannot run: %w",
|
// **A row ahead of this binary is not a reason to go silent.**
|
||||||
catalogue.ControllerSeatName, verb, err)
|
//
|
||||||
|
// The row is the store's and a control plane follows it (novox/hq ADR 0154), so a verb
|
||||||
|
// this build does not know means the row was widened by a newer one — the ordinary
|
||||||
|
// state of a roll-out, and of a push that put an older control plane back. Refusing to
|
||||||
|
// serve at all made that transient fatal: on 2026-10-02 one unknown verb took the whole
|
||||||
|
// mesh off the bus for ten minutes, and the way back was a human running the binary by
|
||||||
|
// hand, because the thing that would have repaired it is the thing that was down
|
||||||
|
// (novox/hq 04-ISSUES/201, ADR 0185).
|
||||||
|
//
|
||||||
|
// So the verbs this binary knows are served, and this one answers the reason instead of
|
||||||
|
// nothing: a caller gets a sentence naming the fault, and everything else keeps working
|
||||||
|
// — including the push that replaces this binary with the one whose verb it is.
|
||||||
|
behind = append(behind, verb)
|
||||||
|
reason := err
|
||||||
|
handlers[verb] = func(context.Context, json.RawMessage) (any, error) {
|
||||||
|
return nil, fmt.Errorf("%s is in this mesh's %s row and the control plane running "+
|
||||||
|
"here cannot run it: %w. It is a verb of a newer build; this one is behind",
|
||||||
|
verb, catalogue.ControllerSeatName, reason)
|
||||||
|
}
|
||||||
|
continue
|
||||||
}
|
}
|
||||||
handlers[verb] = func(ctx context.Context, raw json.RawMessage) (any, error) {
|
handlers[verb] = func(ctx context.Context, raw json.RawMessage) (any, error) {
|
||||||
args := map[string]any{}
|
args := map[string]any{}
|
||||||
@@ -222,7 +285,7 @@ func seatToolHandlers() (map[string]link.ToolHandler, error) {
|
|||||||
return runVerb(ctx, argv)
|
return runVerb(ctx, argv)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
return handlers, nil
|
return handlers, behind, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// seatTools is what `tools` answers: every seat with a protocol, and the tools each serves, from the
|
// seatTools is what `tools` answers: every seat with a protocol, and the tools each serves, from the
|
||||||
@@ -262,3 +325,57 @@ func sampleArguments(v catalogue.Verb) map[string]any {
|
|||||||
}
|
}
|
||||||
return sample
|
return sample
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// splitCommandLine splits a command line into words the way a POSIX shell does for the simple
|
||||||
|
// cases a controller command needs: spaces separate, single or double quotes group, a backslash
|
||||||
|
// escapes the next character inside double quotes or outside any. No expansion of anything.
|
||||||
|
func splitCommandLine(line string) ([]string, error) {
|
||||||
|
var words []string
|
||||||
|
var cur strings.Builder
|
||||||
|
inWord := false
|
||||||
|
quote := rune(0)
|
||||||
|
runes := []rune(line)
|
||||||
|
for i := 0; i < len(runes); i++ {
|
||||||
|
r := runes[i]
|
||||||
|
switch {
|
||||||
|
case quote == '\'':
|
||||||
|
if r == '\'' {
|
||||||
|
quote = 0
|
||||||
|
} else {
|
||||||
|
cur.WriteRune(r)
|
||||||
|
}
|
||||||
|
case quote == '"':
|
||||||
|
if r == '"' {
|
||||||
|
quote = 0
|
||||||
|
} else if r == '\\' && i+1 < len(runes) {
|
||||||
|
i++
|
||||||
|
cur.WriteRune(runes[i])
|
||||||
|
} else {
|
||||||
|
cur.WriteRune(r)
|
||||||
|
}
|
||||||
|
case r == '\'' || r == '"':
|
||||||
|
quote = r
|
||||||
|
inWord = true
|
||||||
|
case r == '\\' && i+1 < len(runes):
|
||||||
|
i++
|
||||||
|
cur.WriteRune(runes[i])
|
||||||
|
inWord = true
|
||||||
|
case r == ' ' || r == '\t' || r == '\n':
|
||||||
|
if inWord {
|
||||||
|
words = append(words, cur.String())
|
||||||
|
cur.Reset()
|
||||||
|
inWord = false
|
||||||
|
}
|
||||||
|
default:
|
||||||
|
cur.WriteRune(r)
|
||||||
|
inWord = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if quote != 0 {
|
||||||
|
return nil, fmt.Errorf("command has an unclosed %c quote", quote)
|
||||||
|
}
|
||||||
|
if inWord {
|
||||||
|
words = append(words, cur.String())
|
||||||
|
}
|
||||||
|
return words, nil
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
package main
|
package main
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"context"
|
||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
@@ -73,6 +74,38 @@ func TestRotateTakesAProvisionOrAnOwnSecret(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// `settings` is `settings set|clear` at a shell, with the values passed inline (novox/hq issue 198).
|
||||||
|
func TestSettingsSetsOrClearsALayer(t *testing.T) {
|
||||||
|
argv, err := argvFor("settings", map[string]any{"module": "dnsmasq", "values": `{"a":1}`, "node": "ace"})
|
||||||
|
if err != nil || strings.Join(argv, " ") != `settings set dnsmasq {"a":1} --node ace` {
|
||||||
|
t.Fatalf("set on a machine: %v %v", argv, err)
|
||||||
|
}
|
||||||
|
argv, _ = argvFor("settings", map[string]any{"module": "dnsmasq", "clear": "true"})
|
||||||
|
if strings.Join(argv, " ") != "settings clear dnsmasq" {
|
||||||
|
t.Fatalf("clear for the mesh: %v", argv)
|
||||||
|
}
|
||||||
|
argv, _ = argvFor("settings", map[string]any{"module": "dnsmasq"})
|
||||||
|
if strings.Join(argv, " ") != "settings set dnsmasq" {
|
||||||
|
t.Fatalf("a set with no values falls to the command's usage: %v", argv)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// `issue` is `module issue` at a shell: the module and the machine, and nothing that would push. A
|
||||||
|
// module's bus account was mintable only from the controller's command line, so an agent working
|
||||||
|
// through the tools could not finish a rollout that gave a module one (novox/hq issue 191).
|
||||||
|
func TestIssueGivesAModuleItsAccountOnAMachine(t *testing.T) {
|
||||||
|
argv, err := argvFor("issue", map[string]any{"node": "ace", "module": "route-proxy"})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if strings.Join(argv, " ") != "module issue route-proxy --node ace" {
|
||||||
|
t.Fatalf("issue runs %v", argv)
|
||||||
|
}
|
||||||
|
if _, err := argvFor("issue", map[string]any{"module": "route-proxy"}); err == nil {
|
||||||
|
t.Error("an account was issued without saying which machine reads it")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// A required argument missing is refused in the verb's own words, before anything runs.
|
// A required argument missing is refused in the verb's own words, before anything runs.
|
||||||
func TestAVerbMissingWhatItNeedsIsRefused(t *testing.T) {
|
func TestAVerbMissingWhatItNeedsIsRefused(t *testing.T) {
|
||||||
if _, err := argvFor("node", map[string]any{}); err == nil || !strings.Contains(err.Error(), `node needs "node"`) {
|
if _, err := argvFor("node", map[string]any{}); err == nil || !strings.Contains(err.Error(), `node needs "node"`) {
|
||||||
@@ -98,10 +131,13 @@ func TestActsDoNotBlockTheCall(t *testing.T) {
|
|||||||
|
|
||||||
// What `tools` answers is the seats' records, with each verb's schema.
|
// What `tools` answers is the seats' records, with each verb's schema.
|
||||||
func TestToolsAnswersTheSeatsRecords(t *testing.T) {
|
func TestToolsAnswersTheSeatsRecords(t *testing.T) {
|
||||||
handlers, err := seatToolHandlers()
|
handlers, behind, err := seatToolHandlers()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
if len(behind) != 0 {
|
||||||
|
t.Fatalf("this build cannot run %v of its own seat's verbs", behind)
|
||||||
|
}
|
||||||
if len(handlers) != len(catalogue.ControllerVerbs) {
|
if len(handlers) != len(catalogue.ControllerVerbs) {
|
||||||
t.Fatalf("%d handlers for %d verbs", len(handlers), len(catalogue.ControllerVerbs))
|
t.Fatalf("%d handlers for %d verbs", len(handlers), len(catalogue.ControllerVerbs))
|
||||||
}
|
}
|
||||||
@@ -139,3 +175,77 @@ func TestAJSONVerbsAnswerIsItsStandardOutput(t *testing.T) {
|
|||||||
t.Fatalf("stderr and stdout are both what the command said: %s", answer.Output)
|
t.Fatalf("stderr and stdout are both what the command said: %s", answer.Output)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// `command` is the generic verb: the command line as given, split as a shell would, nothing added —
|
||||||
|
// so an operator's `node account g14 jochen` is one call through the console rather than a shell on
|
||||||
|
// the control node (novox/hq ADR 0154, ADR 0175).
|
||||||
|
func TestCommandRunsTheLineAsGiven(t *testing.T) {
|
||||||
|
argv, err := argvFor("command", map[string]any{"command": "node account g14 jochen"})
|
||||||
|
if err != nil || strings.Join(argv, " ") != "node account g14 jochen" {
|
||||||
|
t.Fatalf("a plain line: %v %v", argv, err)
|
||||||
|
}
|
||||||
|
argv, err = argvFor("command", map[string]any{"command": `settings set dnsmasq '{"a": "b c"}' --node ace`})
|
||||||
|
if err != nil || len(argv) != 6 || argv[3] != `{"a": "b c"}` {
|
||||||
|
t.Fatalf("a quoted word stays one word: %q %v", argv, err)
|
||||||
|
}
|
||||||
|
argv, err = argvFor("command", map[string]any{"command": `node add "the box" --adopted`})
|
||||||
|
if err != nil || len(argv) != 4 || argv[2] != "the box" {
|
||||||
|
t.Fatalf("double quotes group: %q %v", argv, err)
|
||||||
|
}
|
||||||
|
if _, err := argvFor("command", map[string]any{"command": " "}); err == nil {
|
||||||
|
t.Fatal("an empty line was accepted")
|
||||||
|
}
|
||||||
|
if _, err := argvFor("command", map[string]any{"command": `node "unclosed`}); err == nil {
|
||||||
|
t.Fatal("an unclosed quote was accepted")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A verb in the row that this binary cannot run does not take the control plane off the bus: the
|
||||||
|
// rest are served, the unknown one answers the reason, and the start-up names it (novox/hq ADR
|
||||||
|
// 0185). One unknown word cost the mesh ten minutes of silence on 2026-10-02, recoverable only by
|
||||||
|
// a person running the binary by hand — the push that would have repaired it needs the control
|
||||||
|
// plane that was down.
|
||||||
|
func TestARowAheadOfThisBuildIsServedAnyway(t *testing.T) {
|
||||||
|
seat, known := catalogue.SeatNamed(catalogue.ControllerSeatName)
|
||||||
|
if !known {
|
||||||
|
t.Fatal("no controller seat")
|
||||||
|
}
|
||||||
|
// The row as a newer control plane would have written it: every verb this build knows, and one
|
||||||
|
// it does not.
|
||||||
|
widened := seat
|
||||||
|
widened.Serves = append(append([]catalogue.Verb{}, seat.Serves...),
|
||||||
|
catalogue.Verb{Name: "teleport", Description: "a verb from a build that does not exist yet"})
|
||||||
|
rows := catalogue.DefaultSeats()
|
||||||
|
for i := range rows {
|
||||||
|
if rows[i].Name == catalogue.ControllerSeatName {
|
||||||
|
rows[i] = widened
|
||||||
|
}
|
||||||
|
}
|
||||||
|
catalogue.UseSeats(rows)
|
||||||
|
t.Cleanup(func() { catalogue.UseSeats(catalogue.DefaultSeats()) })
|
||||||
|
|
||||||
|
handlers, behind, err := seatToolHandlers()
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("a row with one unknown verb refused to serve at all: %v", err)
|
||||||
|
}
|
||||||
|
if len(behind) != 1 || behind[0] != "teleport" {
|
||||||
|
t.Fatalf("the verbs this build cannot run were reported as %v", behind)
|
||||||
|
}
|
||||||
|
if len(handlers) != len(widened.Serves) {
|
||||||
|
t.Fatalf("%d handlers for %d verbs in the row", len(handlers), len(widened.Serves))
|
||||||
|
}
|
||||||
|
for _, known := range []string{"status", "nodes", "push"} {
|
||||||
|
if handlers[known] == nil {
|
||||||
|
t.Errorf("%s is not served although this build knows it", known)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
_, err = handlers["teleport"](context.Background(), nil)
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("the unknown verb answered as though it had run")
|
||||||
|
}
|
||||||
|
for _, want := range []string{"teleport", "cannot run it", "behind"} {
|
||||||
|
if !strings.Contains(err.Error(), want) {
|
||||||
|
t.Errorf("the answer does not say %q: %v", want, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -25,6 +25,20 @@ type sendable struct {
|
|||||||
// Adoption is nil for a converged node, and then the body is byte for byte what it was before
|
// Adoption is nil for a converged node, and then the body is byte for byte what it was before
|
||||||
// adoption existed: an older host parses the envelope strictly and would refuse the key.
|
// adoption existed: an older host parses the envelope strictly and would refuse the key.
|
||||||
Adoption *adoptionEnvelope
|
Adoption *adoptionEnvelope
|
||||||
|
|
||||||
|
// Received and Mesh are not sent in the declaration. They are what this machine's memberships
|
||||||
|
// are issued with on the bus (novox/hq ADR 0167): each module's received contributions, from
|
||||||
|
// the same composition as its received files, and every machine's private-network address.
|
||||||
|
Received map[string]map[string][]catalogue.Contribution
|
||||||
|
Mesh []string
|
||||||
|
// LeftOut is every module of the machine's set left out of this declaration because a stored
|
||||||
|
// setting cannot compose with its definition (novox/hq ADR 0163, rule 6), sorted. The host
|
||||||
|
// keeps that module's held things and touches none of its containers; a machine is told
|
||||||
|
// everything or nothing about what it IS told, and what it is not told is said. Absent from
|
||||||
|
// the body when empty, so a declaration that leaves nothing out is byte for byte what it was.
|
||||||
|
LeftOut []string
|
||||||
|
// leftOutWhy is why each was, for push and plan to say; never on the wire.
|
||||||
|
leftOutWhy map[string]string
|
||||||
}
|
}
|
||||||
|
|
||||||
// adoptionEnvelope is what an adopted node is told about its mode. Taken is every module taken on
|
// adoptionEnvelope is what an adopted node is told about its mode. Taken is every module taken on
|
||||||
@@ -45,6 +59,9 @@ func (s sendable) Body() ([]byte, error) {
|
|||||||
if s.Sequence > 0 {
|
if s.Sequence > 0 {
|
||||||
envelope["sequence"] = s.Sequence
|
envelope["sequence"] = s.Sequence
|
||||||
}
|
}
|
||||||
|
if len(s.LeftOut) > 0 {
|
||||||
|
envelope["left_out"] = s.LeftOut
|
||||||
|
}
|
||||||
// An empty declaration is deliberate here — the node owns nothing the mesh put there
|
// An empty declaration is deliberate here — the node owns nothing the mesh put there
|
||||||
// (novox/hq issue 127) — and the host refuses an empty body unless it is told the emptiness
|
// (novox/hq issue 127) — and the host refuses an empty body unless it is told the emptiness
|
||||||
// is meant, so a truncated or mis-composed body is never mistaken for "own nothing".
|
// is meant, so a truncated or mis-composed body is never mistaken for "own nothing".
|
||||||
|
|||||||
@@ -382,3 +382,62 @@ func TestAnEmptyDeclarationSaysOwnsNothing(t *testing.T) {
|
|||||||
t.Fatalf("a non-empty declaration must not mark owns_nothing; got %v", env)
|
t.Fatalf("a non-empty declaration must not mark owns_nothing; got %v", env)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// A setting is judged where it is stored, and an impossible one costs a module, not a machine
|
||||||
|
// (novox/hq ADR 0163, rule 6): stored while it composed, a setting whose definition then moved from
|
||||||
|
// under it leaves that module out of the declaration — said in the envelope, so the host keeps the
|
||||||
|
// module's things — and the machine is told everything else.
|
||||||
|
func TestADefinitionMovingUnderAStoredSettingLeavesThatModuleOutNotTheMachine(t *testing.T) {
|
||||||
|
open := aMesh(t)
|
||||||
|
ctx := t.Context()
|
||||||
|
web := helloWeb()
|
||||||
|
web.Resources[1]["ports"] = []any{"8080"}
|
||||||
|
register(t, open, web)
|
||||||
|
register(t, open, catalogue.Manifest{Module: "notes", Version: "1",
|
||||||
|
Resources: []map[string]any{{"id": "conf", "type": "file", "path": "/etc/notes.conf", "content": "x"}}})
|
||||||
|
for _, m := range []string{"hello-web", "notes"} {
|
||||||
|
if _, err := assign(ctx, open, "laptop", m); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// Judged where it is stored: a port the module does not publish is refused by name.
|
||||||
|
err := open.inventory.SetSettings(ctx, "laptop", "hello-web",
|
||||||
|
map[string]any{catalogue.PortsSetting: map[string]any{"9999": 10000}})
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "hello-web on laptop") || !strings.Contains(err.Error(), "9999") {
|
||||||
|
t.Fatalf("an impossible setting was stored: %v", err)
|
||||||
|
}
|
||||||
|
if err := open.inventory.SetSettings(ctx, "laptop", "hello-web",
|
||||||
|
map[string]any{catalogue.PortsSetting: map[string]any{"8080": 10000}}); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if declared := composed(t, open, "laptop"); len(declared.LeftOut) != 0 {
|
||||||
|
t.Fatalf("a setting that composes left a module out: %v", declared.LeftOut)
|
||||||
|
}
|
||||||
|
|
||||||
|
// The definition moves: the container publishes another port now.
|
||||||
|
web.Version = "2"
|
||||||
|
web.Resources[1]["ports"] = []any{"9090"}
|
||||||
|
register(t, open, web)
|
||||||
|
declared := composed(t, open, "laptop")
|
||||||
|
if len(declared.LeftOut) != 1 || declared.LeftOut[0] != "hello-web" {
|
||||||
|
t.Fatalf("hello-web is not left out: %v", declared.LeftOut)
|
||||||
|
}
|
||||||
|
if !strings.Contains(declared.leftOutWhy["hello-web"], "no container of its publishes 8080") {
|
||||||
|
t.Fatalf("why it was left out is not said: %v", declared.leftOutWhy)
|
||||||
|
}
|
||||||
|
if hasID(declared.Resources, "hello-web.server") || !hasID(declared.Resources, "notes.conf") {
|
||||||
|
t.Fatalf("the machine was not told everything else: %v", declared.Resources)
|
||||||
|
}
|
||||||
|
body, err := declared.Body()
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
var env map[string]any
|
||||||
|
if err := json.Unmarshal(body, &env); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
left, _ := env["left_out"].([]any)
|
||||||
|
if len(left) != 1 || left[0] != "hello-web" {
|
||||||
|
t.Fatalf("the envelope does not say what was left out: %v", env)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -227,6 +227,28 @@ func printStatus(asked answers) error {
|
|||||||
" not readable from a commit; that needs a version the host reports as ordered\n\n")
|
" not readable from a commit; that needs a version the host reports as ordered\n\n")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if len(asked.filtered) > 0 {
|
||||||
|
// A converged machine is filtered by the mesh alone, and the mesh says truthfully which
|
||||||
|
// (novox/hq ADR 0168). One that is not — a predecessor's chain still refusing, a found
|
||||||
|
// firewall in force again — is said here, and is not well.
|
||||||
|
machines := make([]string, 0, len(asked.filtered))
|
||||||
|
for name := range asked.filtered {
|
||||||
|
machines = append(machines, name)
|
||||||
|
}
|
||||||
|
sort.Strings(machines)
|
||||||
|
fmt.Printf("%d converged machine(s) are not filtered by the mesh alone:\n", len(machines))
|
||||||
|
for _, name := range machines {
|
||||||
|
f := asked.filtered[name]
|
||||||
|
if fw := f.FoundFirewall; fw != nil && fw.Active {
|
||||||
|
fmt.Printf(" %-12s the found firewall (%s) is in force again; the next apply retires it\n", name, fw.Kind)
|
||||||
|
}
|
||||||
|
for _, x := range f.Others() {
|
||||||
|
fmt.Printf(" %-12s %s (%s): %s\n", name, x.Where, x.Owner, x.Refuses)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
fmt.Printf("\n the mesh wrote none of these and removes none; `node show <node>` lists every filter with its owner\n\n")
|
||||||
|
}
|
||||||
|
|
||||||
if len(asked.untaken) > 0 {
|
if len(asked.untaken) > 0 {
|
||||||
// **Before the adopted line, and it breaks "all well".** An adopted machine is a state
|
// **Before the adopted line, and it breaks "all well".** An adopted machine is a state
|
||||||
// somebody chose and can leave alone; a module assigned to one and never taken is work
|
// somebody chose and can leave alone; a module assigned to one and never taken is work
|
||||||
@@ -357,6 +379,13 @@ func theThreeQuestions(ctx context.Context, open *stores) (answers, error) {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return answers{}, err
|
return answers{}, err
|
||||||
}
|
}
|
||||||
|
// And which converged machines something other than the mesh filters (novox/hq ADR 0168), as
|
||||||
|
// each last reported — the account that was missing when a predecessor's chain refused what the
|
||||||
|
// mesh declared open for eleven hours (04-ISSUES/144, 145).
|
||||||
|
out.filtered, err = filteredMachines(ctx, inv, out.nodes)
|
||||||
|
if err != nil {
|
||||||
|
return answers{}, err
|
||||||
|
}
|
||||||
out.plans, err = inv.RecentPlans(ctx, 5)
|
out.plans, err = inv.RecentPlans(ctx, 5)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return answers{}, err
|
return answers{}, err
|
||||||
@@ -406,6 +435,30 @@ func theThreeQuestions(ctx context.Context, open *stores) (answers, error) {
|
|||||||
//
|
//
|
||||||
// A machine that reports no holds contributes nothing, so a converged mesh answers an empty map and
|
// A machine that reports no holds contributes nothing, so a converged mesh answers an empty map and
|
||||||
// the caller prints nothing.
|
// the caller prints nothing.
|
||||||
|
// filteredMachines is every converged machine not filtered by the mesh alone, with what it last said
|
||||||
|
// filters it (novox/hq ADR 0168). An adopted machine keeps its found firewall by design and is not
|
||||||
|
// counted; a machine that has not said is not said to be filtered by anything.
|
||||||
|
func filteredMachines(ctx context.Context, inv *inventory.Inventory, nodes []inventory.Node) (
|
||||||
|
map[string]inventory.Filtering, error) {
|
||||||
|
out := map[string]inventory.Filtering{}
|
||||||
|
for _, n := range nodes {
|
||||||
|
if n.Adopted {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
f, err := inv.FilteringOf(ctx, n.Name)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("what filters %s cannot be read: %w", n.Name, err)
|
||||||
|
}
|
||||||
|
if len(f.Filters) == 0 && f.FoundFirewall == nil {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if !f.Alone() {
|
||||||
|
out[n.Name] = f
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return out, nil
|
||||||
|
}
|
||||||
|
|
||||||
func untakenModules(ctx context.Context, inv *inventory.Inventory, nodes []inventory.Node) (
|
func untakenModules(ctx context.Context, inv *inventory.Inventory, nodes []inventory.Node) (
|
||||||
map[string]map[string]int, error) {
|
map[string]map[string]int, error) {
|
||||||
|
|
||||||
@@ -442,7 +495,8 @@ func untakenModules(ctx context.Context, inv *inventory.Inventory, nodes []inven
|
|||||||
// read as success for the whole of the edge cut-over outage (novox/hq 04-ISSUES/125).
|
// read as success for the whole of the edge cut-over outage (novox/hq 04-ISSUES/125).
|
||||||
func (a answers) well() bool {
|
func (a answers) well() bool {
|
||||||
return len(a.wrong) == 0 && len(a.quiet) == 0 && len(a.behind) == 0 &&
|
return len(a.wrong) == 0 && len(a.quiet) == 0 && len(a.behind) == 0 &&
|
||||||
len(a.waiting) == 0 && len(a.refused) == 0 && a.network == "" && len(a.untaken) == 0
|
len(a.waiting) == 0 && len(a.refused) == 0 && a.network == "" && len(a.untaken) == 0 &&
|
||||||
|
len(a.filtered) == 0
|
||||||
}
|
}
|
||||||
|
|
||||||
// hostSplit is which machines report which host version, for every version more than one machine
|
// hostSplit is which machines report which host version, for every version more than one machine
|
||||||
|
|||||||
@@ -4,26 +4,42 @@ import (
|
|||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
|
"github.com/novox/mesh-controller/internal/catalogue"
|
||||||
"github.com/novox/mesh-controller/internal/inventory"
|
"github.com/novox/mesh-controller/internal/inventory"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
// What the forge's take compares, as a machine would report it.
|
||||||
|
func aForgeComparison() comparison {
|
||||||
|
return comparison{reported: inventory.Adoption{
|
||||||
|
Firewall: "ufw",
|
||||||
|
Held: []inventory.Held{
|
||||||
|
{ID: "forge.server", Module: "forge", Kind: "container", Target: "forge", Facts: map[string]any{
|
||||||
|
"image": "forge:1.27.3", "image_created": "2026-09-17T10:00:00Z",
|
||||||
|
"declared_image": "forge:1.22.6", "declared_image_created": "2026-08-20T10:00:00Z", "downgrade": true,
|
||||||
|
"networks": map[string]any{"predecessor_default": []any{"office", "db"}},
|
||||||
|
"ports": []any{"3000/tcp>0.0.0.0:3000"}, "declared_ports": []any{"3000:3000"},
|
||||||
|
}},
|
||||||
|
{ID: "forge.config", Module: "forge", Kind: "file", Target: "/etc/forge/app.ini", Kept: "/var/lib/mesh/kept/app.ini",
|
||||||
|
Facts: map[string]any{"differs": true, "difference": []any{"- private scope: local", "+ upstream: public"}}},
|
||||||
|
{ID: "other.server", Module: "other", Kind: "container", Target: "other"},
|
||||||
|
},
|
||||||
|
Reachable: []inventory.Reach{
|
||||||
|
{Protocol: "tcp", Address: "0.0.0.0", Port: 3000, By: "forge", Published: true, ContainerPort: 3000},
|
||||||
|
{Protocol: "tcp", Address: "0.0.0.0", Port: 22, By: "sshd"},
|
||||||
|
},
|
||||||
|
}}
|
||||||
|
}
|
||||||
|
|
||||||
// A take is a comparison (novox/hq ADR 0163): the preview puts what runs beside what the module
|
// A take is a comparison (novox/hq ADR 0163): the preview puts what runs beside what the module
|
||||||
// declares, and an older image or a differing file refuses unless named.
|
// declares, and an older image or a differing file refuses unless named.
|
||||||
func TestATakePreviewsTheComparisonAndRefusesWhatIsNotNamed(t *testing.T) {
|
func TestATakePreviewsTheComparisonAndRefusesWhatIsNotNamed(t *testing.T) {
|
||||||
held := []inventory.Held{
|
c := aForgeComparison()
|
||||||
{ID: "forge.server", Module: "forge", Kind: "container", Target: "forge", Facts: map[string]any{
|
preview, refusals, saw := comparisonOf("forge", c, takeOptions{})
|
||||||
"image": "forge:1.27.3", "image_created": "2026-09-17T10:00:00Z",
|
|
||||||
"declared_image": "forge:1.22.6", "declared_image_created": "2026-08-20T10:00:00Z", "downgrade": true,
|
|
||||||
"networks": map[string]any{"predecessor_default": []any{"office", "db"}},
|
|
||||||
"ports": []any{"3000/tcp>0.0.0.0:3000"}, "declared_ports": []any{"3000:3000"},
|
|
||||||
}},
|
|
||||||
{ID: "forge.config", Module: "forge", Kind: "file", Target: "/etc/forge/app.ini", Kept: "/var/lib/mesh/kept/app.ini",
|
|
||||||
Facts: map[string]any{"differs": true, "difference": []any{"- private scope: local", "+ upstream: public"}}},
|
|
||||||
{ID: "other.server", Module: "other", Kind: "container", Target: "other"},
|
|
||||||
}
|
|
||||||
preview, refusals := comparisonOf(held, "forge", takeOptions{})
|
|
||||||
for _, want := range []string{"runs forge:1.27.3 (made 2026-09-17)", "declares forge:1.22.6 (made 2026-08-20)", "DOWNGRADE",
|
for _, want := range []string{"runs forge:1.27.3 (made 2026-09-17)", "declares forge:1.22.6 (made 2026-08-20)", "DOWNGRADE",
|
||||||
"on the network predecessor_default with office, db", "publishes 3000/tcp>0.0.0.0:3000; the module declares 3000:3000",
|
"on the network predecessor_default with office, db", "will not once it moves to the module's own network",
|
||||||
|
"publishes 3000/tcp>0.0.0.0:3000; the module declares 3000:3000",
|
||||||
|
// How far the port reaches now, as the machine reported it (rule 1).
|
||||||
|
"reachable now at 0.0.0.0:3000 (tcp, container port 3000), behind the found firewall (ufw)",
|
||||||
"- private scope: local", "original kept at /var/lib/mesh/kept/app.ini"} {
|
"- private scope: local", "original kept at /var/lib/mesh/kept/app.ini"} {
|
||||||
if !strings.Contains(preview, want) {
|
if !strings.Contains(preview, want) {
|
||||||
t.Errorf("the preview lacks %q:\n%s", want, preview)
|
t.Errorf("the preview lacks %q:\n%s", want, preview)
|
||||||
@@ -35,15 +51,93 @@ func TestATakePreviewsTheComparisonAndRefusesWhatIsNotNamed(t *testing.T) {
|
|||||||
if len(refusals) != 2 || !strings.Contains(refusals[0], "--downgrade") || !strings.Contains(refusals[1], "--replace /etc/forge/app.ini") {
|
if len(refusals) != 2 || !strings.Contains(refusals[0], "--downgrade") || !strings.Contains(refusals[1], "--replace /etc/forge/app.ini") {
|
||||||
t.Fatalf("the downgrade and the differing file refuse, each naming its override: %v", refusals)
|
t.Fatalf("the downgrade and the differing file refuse, each naming its override: %v", refusals)
|
||||||
}
|
}
|
||||||
|
if len(saw) != 12 {
|
||||||
|
t.Fatalf("the preview's digest is %q", saw)
|
||||||
|
}
|
||||||
// Named, they pass.
|
// Named, they pass.
|
||||||
if _, refusals := comparisonOf(held, "forge", takeOptions{Downgrade: true, Replace: map[string]bool{"/etc/forge/app.ini": true}}); len(refusals) != 0 {
|
if _, refusals, _ := comparisonOf("forge", c, takeOptions{Downgrade: true, Replace: map[string]bool{"/etc/forge/app.ini": true}}); len(refusals) != 0 {
|
||||||
t.Fatalf("named differences still refused: %v", refusals)
|
t.Fatalf("named differences still refused: %v", refusals)
|
||||||
}
|
}
|
||||||
if _, refusals := comparisonOf(held, "forge", takeOptions{Downgrade: true, Replace: map[string]bool{"*": true}}); len(refusals) != 0 {
|
if _, refusals, _ := comparisonOf("forge", c, takeOptions{Downgrade: true, Replace: map[string]bool{"*": true}}); len(refusals) != 0 {
|
||||||
t.Fatalf("replace * did not cover the file: %v", refusals)
|
t.Fatalf("replace * did not cover the file: %v", refusals)
|
||||||
}
|
}
|
||||||
// A held thing with no facts yet — a host older than this — refuses nothing and says what it can.
|
// A held thing with no facts yet — a host older than this — refuses nothing and says what it can.
|
||||||
if preview, refusals := comparisonOf(held, "other", takeOptions{}); len(refusals) != 0 || !strings.Contains(preview, "container other") {
|
if preview, refusals, _ := comparisonOf("other", c, takeOptions{}); len(refusals) != 0 || !strings.Contains(preview, "container other") {
|
||||||
t.Fatalf("a factless hold: %q %v", preview, refusals)
|
t.Fatalf("a factless hold: %q %v", preview, refusals)
|
||||||
}
|
}
|
||||||
|
// The digest is of what the preview says: a fact changing changes it.
|
||||||
|
c.reported.Held[0].Facts["image"] = "forge:1.27.4"
|
||||||
|
if _, _, again := comparisonOf("forge", c, takeOptions{}); again == saw {
|
||||||
|
t.Fatal("the found image changed and the digest did not")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A secret the mesh minted for a service whose data was found refuses: the running service already
|
||||||
|
// has a value (rule 2). Accepted, it is carried in; `--mint` says the service shall take the new one.
|
||||||
|
func TestAMintedSecretForFoundDataRefusesUnlessAcceptedOrMinted(t *testing.T) {
|
||||||
|
c := aForgeComparison()
|
||||||
|
c.secrets = []inventory.SecretState{
|
||||||
|
{Name: "admin", Origin: inventory.OriginMade},
|
||||||
|
{Name: "postgres-database", Origin: inventory.OriginMade, Provider: "anchor"},
|
||||||
|
{Name: "broker", Origin: inventory.OriginAccepted},
|
||||||
|
}
|
||||||
|
preview, refusals, _ := comparisonOf("forge", c, takeOptions{Downgrade: true, Replace: map[string]bool{"*": true}})
|
||||||
|
for _, want := range []string{
|
||||||
|
"own secret admin: MINTED by the mesh and not accepted",
|
||||||
|
"secret from anchor postgres-database: MINTED by the mesh and not accepted",
|
||||||
|
"own secret broker: accepted from a person, carried in as it is",
|
||||||
|
} {
|
||||||
|
if !strings.Contains(preview, want) {
|
||||||
|
t.Errorf("the preview lacks %q:\n%s", want, preview)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if len(refusals) != 2 {
|
||||||
|
t.Fatalf("two minted secrets refuse: %v", refusals)
|
||||||
|
}
|
||||||
|
if !strings.Contains(refusals[0], "`secret accept <node> forge admin`") || !strings.Contains(refusals[0], "`--mint admin`") {
|
||||||
|
t.Errorf("the own secret's refusal names accepting it and minting it: %s", refusals[0])
|
||||||
|
}
|
||||||
|
if !strings.Contains(refusals[1], "`secret accept <node> forge postgres-database --provider anchor`") {
|
||||||
|
t.Errorf("the required secret's refusal names its provider: %s", refusals[1])
|
||||||
|
}
|
||||||
|
preview, refusals, _ = comparisonOf("forge", c, takeOptions{Downgrade: true, Replace: map[string]bool{"*": true},
|
||||||
|
Mint: map[string]bool{"admin": true, "postgres-database": true}})
|
||||||
|
if len(refusals) != 0 || !strings.Contains(preview, "admin: minted by the mesh; the service takes the new value, as --mint said") {
|
||||||
|
t.Fatalf("--mint did not pass the minted secrets: %v\n%s", refusals, preview)
|
||||||
|
}
|
||||||
|
// With no found data — only a file held — the service has no value of its own, and a minted
|
||||||
|
// secret is simply said.
|
||||||
|
c.reported.Held = c.reported.Held[1:2]
|
||||||
|
if _, refusals, _ := comparisonOf("forge", c, takeOptions{Replace: map[string]bool{"*": true}}); len(refusals) != 0 {
|
||||||
|
t.Fatalf("a minted secret refused with no data found: %v", refusals)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A found network a per-machine setting keeps is named in the preview (rule 4), and the module's
|
||||||
|
// settings are said with where each came from, composed or not (rules 1 and 6).
|
||||||
|
func TestTheKeptNetworkAndTheSettingsAreInThePreview(t *testing.T) {
|
||||||
|
c := aForgeComparison()
|
||||||
|
c.keeps = map[string][]string{"forge.server": {"predecessor_default"}}
|
||||||
|
c.layers = []catalogue.Layer{
|
||||||
|
{From: catalogue.MeshWideLayer, Values: map[string]any{"site": "x"}},
|
||||||
|
{From: "anchor", Values: map[string]any{catalogue.NetworksSetting: map[string]any{"server": []any{"predecessor_default"}}}},
|
||||||
|
}
|
||||||
|
preview, _, _ := comparisonOf("forge", c, takeOptions{Downgrade: true, Replace: map[string]bool{"*": true}})
|
||||||
|
for _, want := range []string{
|
||||||
|
"on the network predecessor_default with office, db — kept by this machine's setting, so they still reach it by name once taken",
|
||||||
|
"settings from the mesh: site",
|
||||||
|
"settings from anchor: networks",
|
||||||
|
} {
|
||||||
|
if !strings.Contains(preview, want) {
|
||||||
|
t.Errorf("the preview lacks %q:\n%s", want, preview)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if strings.Contains(preview, "will not once it moves") {
|
||||||
|
t.Errorf("a kept network is still said to be lost:\n%s", preview)
|
||||||
|
}
|
||||||
|
c.settingsRefused = "forge: ports is a { port: machine-port } map"
|
||||||
|
preview, _, _ = comparisonOf("forge", c, takeOptions{Downgrade: true, Replace: map[string]bool{"*": true}})
|
||||||
|
if !strings.Contains(preview, "SETTINGS DO NOT COMPOSE with the module's definition, so the push leaves it out: forge: ports") {
|
||||||
|
t.Errorf("settings that cannot compose are not said:\n%s", preview)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -10,7 +10,10 @@
|
|||||||
# The client is copied from the vendor's own image rather than installed from a distribution:
|
# The client is copied from the vendor's own image rather than installed from a distribution:
|
||||||
# `apk add mc` on Alpine installs Midnight Commander, which is a different program with the same
|
# `apk add mc` on Alpine installs Midnight Commander, which is a different program with the same
|
||||||
# name, and the failure would be a provisioner that starts cleanly and cannot do anything.
|
# name, and the failure would be a provisioner that starts cleanly and cannot do anything.
|
||||||
FROM golang:1.25-alpine AS build
|
# The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the
|
||||||
|
# build machine alike; the default only serves a hand build, and matches go.mod.
|
||||||
|
ARG GO_BASE=golang:1.26-alpine
|
||||||
|
FROM ${GO_BASE} AS build
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|||||||
@@ -3,7 +3,10 @@
|
|||||||
# Built here so a machine can be given it by the mesh rather than by somebody putting a binary on
|
# Built here so a machine can be given it by the mesh rather than by somebody putting a binary on
|
||||||
# it. Static and FROM scratch for the same reason the control plane's image is: it is fetched by
|
# it. Static and FROM scratch for the same reason the control plane's image is: it is fetched by
|
||||||
# digest and run on a machine, and everything in it is something a person would have to audit.
|
# digest and run on a machine, and everything in it is something a person would have to audit.
|
||||||
FROM golang:1.25-alpine AS build
|
# The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the
|
||||||
|
# build machine alike; the default only serves a hand build, and matches go.mod.
|
||||||
|
ARG GO_BASE=golang:1.26-alpine
|
||||||
|
FROM ${GO_BASE} AS build
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|||||||
@@ -2,7 +2,10 @@
|
|||||||
#
|
#
|
||||||
# FROM scratch, like the postgres one and unlike the bucket one: it speaks the store's own wire
|
# FROM scratch, like the postgres one and unlike the bucket one: it speaks the store's own wire
|
||||||
# protocol directly and needs no client in the image.
|
# protocol directly and needs no client in the image.
|
||||||
FROM golang:1.25-alpine AS build
|
# The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the
|
||||||
|
# build machine alike; the default only serves a hand build, and matches go.mod.
|
||||||
|
ARG GO_BASE=golang:1.26-alpine
|
||||||
|
FROM ${GO_BASE} AS build
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|||||||
@@ -2,7 +2,10 @@
|
|||||||
#
|
#
|
||||||
# Static and FROM scratch like the control plane's image, and for the same reason: it is fetched
|
# Static and FROM scratch like the control plane's image, and for the same reason: it is fetched
|
||||||
# by digest and run on a machine, so everything in it is something a person would have to audit.
|
# by digest and run on a machine, so everything in it is something a person would have to audit.
|
||||||
FROM golang:1.25-alpine AS build
|
# The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the
|
||||||
|
# build machine alike; the default only serves a hand build, and matches go.mod.
|
||||||
|
ARG GO_BASE=golang:1.26-alpine
|
||||||
|
FROM ${GO_BASE} AS build
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|||||||
@@ -0,0 +1,132 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
"log"
|
||||||
|
"os"
|
||||||
|
"strings"
|
||||||
|
"sync/atomic"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/nats-io/nats.go"
|
||||||
|
|
||||||
|
"github.com/novox/mesh-controller/internal/broker"
|
||||||
|
)
|
||||||
|
|
||||||
|
// What the mesh issued this proxy, read on the bus (novox/hq ADR 0160, ADR 0167).
|
||||||
|
//
|
||||||
|
// **The proxy is told, not left to work it out.** Its membership carries the routes it is given —
|
||||||
|
// the same contributions its file is written from — and every machine's address on the private
|
||||||
|
// network, which is who may be served an internal name. Read once at connect and followed, so a
|
||||||
|
// route added or a machine joining reaches a running proxy without a restart.
|
||||||
|
|
||||||
|
// credential is the bus account the mesh delivered as this module's own secret named broker.
|
||||||
|
type credential struct {
|
||||||
|
URL string `json:"url"`
|
||||||
|
Fingerprint string `json:"fingerprint"`
|
||||||
|
Node string `json:"node"`
|
||||||
|
Module string `json:"module"`
|
||||||
|
User string `json:"user"`
|
||||||
|
Password string `json:"password"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// followMembership connects with the credential in path and applies every membership the mesh
|
||||||
|
// issues this proxy. It retries the first connection for as long as it takes: a proxy that started
|
||||||
|
// before the bus keeps serving the file, and takes the bus when it answers.
|
||||||
|
func followMembership(path string, held *table, fromBus *atomic.Bool) {
|
||||||
|
for {
|
||||||
|
err := followOnce(path, held, fromBus)
|
||||||
|
if err == nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
log.Printf("cannot follow this proxy's membership, serving the file meanwhile: %v", err)
|
||||||
|
time.Sleep(30 * time.Second)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func followOnce(path string, held *table, fromBus *atomic.Bool) error {
|
||||||
|
raw, err := os.ReadFile(path)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
var cred credential
|
||||||
|
if err := json.Unmarshal(raw, &cred); err != nil {
|
||||||
|
return fmt.Errorf("the broker credential is not one: %w", err)
|
||||||
|
}
|
||||||
|
if cred.Node == "" || cred.Module == "" {
|
||||||
|
return fmt.Errorf("the broker credential names no node or module, so it has no membership")
|
||||||
|
}
|
||||||
|
|
||||||
|
opts := []nats.Option{
|
||||||
|
nats.Name(cred.Node + "." + cred.Module),
|
||||||
|
nats.UserInfo(cred.User, cred.Password),
|
||||||
|
// Its own inbox, and nothing wider: every principal is granted `_INBOX.<its user>.>` alone.
|
||||||
|
nats.CustomInboxPrefix("_INBOX." + cred.User),
|
||||||
|
// The bus being restarted is an upgrade, not a reason to stop following.
|
||||||
|
nats.MaxReconnects(-1),
|
||||||
|
}
|
||||||
|
if strings.TrimSpace(cred.Fingerprint) != "" {
|
||||||
|
opts = append(opts, nats.Secure(broker.PinnedToFingerprint(cred.Fingerprint)))
|
||||||
|
}
|
||||||
|
conn, err := nats.Connect(cred.URL, opts...)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("connecting to the bus at %s: %w", broker.BareAddress(cred.URL), err)
|
||||||
|
}
|
||||||
|
|
||||||
|
subject := broker.MembershipSubject(cred.Node, cred.Module)
|
||||||
|
apply := func(body []byte) {
|
||||||
|
var issued broker.Membership
|
||||||
|
if err := json.Unmarshal(body, &issued); err != nil {
|
||||||
|
log.Printf("a membership arrived that is not one: %v", err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if took := applyMembership(issued, held); took && !fromBus.Swap(true) {
|
||||||
|
log.Printf("routes now come from this proxy's membership on %s", subject)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Followed first, read second: an issue landing between the two is applied, not missed.
|
||||||
|
if _, err := conn.Subscribe(subject, func(m *nats.Msg) { apply(m.Data) }); err != nil {
|
||||||
|
conn.Close()
|
||||||
|
return fmt.Errorf("cannot follow %s: %w", subject, err)
|
||||||
|
}
|
||||||
|
// The subject-addressed direct get: the one request this account may make of the stream.
|
||||||
|
got, err := conn.Request("$JS.API.DIRECT.GET."+broker.AssignmentsStream+"."+subject, nil, 5*time.Second)
|
||||||
|
switch {
|
||||||
|
case err != nil:
|
||||||
|
log.Printf("cannot read the membership issued on %s yet (%v); following it", subject, err)
|
||||||
|
case got.Header.Get("Status") != "" || len(got.Data) == 0:
|
||||||
|
log.Printf("no membership issued on %s yet; serving the file until one is", subject)
|
||||||
|
default:
|
||||||
|
apply(got.Data)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// applyMembership serves what a membership says, and says whether it said anything about routes.
|
||||||
|
//
|
||||||
|
// A membership with no routes in it is one from a controller older than ADR 0167, and the file stays
|
||||||
|
// the source rather than every route being withdrawn because a field was absent.
|
||||||
|
func applyMembership(issued broker.Membership, held *table) bool {
|
||||||
|
raw, carries := issued.Receives["route"]
|
||||||
|
if !carries {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
var contributions []contribution
|
||||||
|
if err := json.Unmarshal(raw, &contributions); err != nil {
|
||||||
|
log.Printf("the routes in this proxy's membership are not contributions, keeping what is served: %v", err)
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
inside, err := sourcesOf(issued.Mesh)
|
||||||
|
if err != nil {
|
||||||
|
log.Printf("the mesh in this proxy's membership is unreadable, keeping what is served: %v", err)
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
routes, public := routesOf(contributions)
|
||||||
|
held.set(routes, public)
|
||||||
|
held.setInside(inside)
|
||||||
|
log.Printf("serving %d route(s) from the membership, internal names to %d machine(s): %s",
|
||||||
|
len(routes), len(inside), strings.Join(held.names(), ", "))
|
||||||
|
return true
|
||||||
|
}
|
||||||
@@ -61,6 +61,7 @@ import (
|
|||||||
"sort"
|
"sort"
|
||||||
"strings"
|
"strings"
|
||||||
"sync"
|
"sync"
|
||||||
|
"sync/atomic"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"golang.org/x/crypto/acme"
|
"golang.org/x/crypto/acme"
|
||||||
@@ -197,77 +198,44 @@ type table struct {
|
|||||||
// pass ACME's own validation (it has no public DNS to prove it against), so asking for it is
|
// pass ACME's own validation (it has no public DNS to prove it against), so asking for it is
|
||||||
// not merely pointless but the failing order onlyWhatTheMeshSaid exists to prevent.
|
// not merely pointless but the failing order onlyWhatTheMeshSaid exists to prevent.
|
||||||
public map[string]bool
|
public map[string]bool
|
||||||
// inside is the private network's range, where a request must come from to be served a name
|
// inside is where a request must come from to be served a name that is only internal: every
|
||||||
// that is only internal. Set once at start, never replaced with the routes: it is what the
|
// machine's address on the private network, as the mesh issued it in this proxy's membership
|
||||||
// private network is, not what is routed on it.
|
// (novox/hq ADR 0167). Empty until it is issued, and then only the machine itself is inside.
|
||||||
inside sources
|
inside sources
|
||||||
// bridges is the machine's own container networks, read from its interfaces and refreshed with
|
|
||||||
// the routes, since a compose network can appear at any time.
|
|
||||||
bridges sources
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// sources is the private network, as address ranges. The machine itself is always inside it —
|
// sources is who may be served an internal name: the private network's addresses as the mesh
|
||||||
// anything on a machine may call anything on it (novox/hq ADR 0144) — so loopback needs no range.
|
// issued them. The machine itself is always inside — anything on a machine may call anything on it
|
||||||
|
// (novox/hq ADR 0144) — so loopback needs no entry.
|
||||||
type sources []netip.Prefix
|
type sources []netip.Prefix
|
||||||
|
|
||||||
// sourcesFrom reads the ranges the mesh wrote, separated by commas or spaces. A range that does not
|
// sourcesOf reads the addresses the mesh issued, each a single address or a range. One that does
|
||||||
// parse is an error, not a range skipped: the proxy would otherwise serve internal names to fewer
|
// not parse is an error, not an entry skipped: the proxy would otherwise serve internal names to
|
||||||
// machines than the mesh said, or start believing a typo.
|
// fewer machines than the mesh said, and say nothing.
|
||||||
func sourcesFrom(text string) (sources, error) {
|
func sourcesOf(mesh []string) (sources, error) {
|
||||||
var out sources
|
var out sources
|
||||||
for _, field := range strings.FieldsFunc(text, func(r rune) bool { return r == ',' || r == ' ' || r == '\n' || r == '\t' }) {
|
for _, entry := range mesh {
|
||||||
prefix, err := netip.ParsePrefix(field)
|
entry = strings.TrimSpace(entry)
|
||||||
if err != nil {
|
if prefix, err := netip.ParsePrefix(entry); err == nil {
|
||||||
return nil, fmt.Errorf("%q is not an address range: %w", field, err)
|
out = append(out, prefix.Masked())
|
||||||
|
continue
|
||||||
}
|
}
|
||||||
out = append(out, prefix.Masked())
|
addr, err := netip.ParseAddr(entry)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("%q is not an address on the private network", entry)
|
||||||
|
}
|
||||||
|
addr = addr.Unmap()
|
||||||
|
out = append(out, netip.PrefixFrom(addr, addr.BitLen()))
|
||||||
}
|
}
|
||||||
return out, nil
|
return out, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// bridgesFrom is the address ranges of the machine's container bridges — the same interfaces the
|
// holds says whether a request from this remote address came from the mesh or the machine itself.
|
||||||
// mesh's guard names as the machine itself (docker0, and the br-* a compose network gets), so the
|
|
||||||
// proxy and the guard agree on what "this machine" is (novox/hq ADR 0144).
|
|
||||||
func bridgesFrom(interfaces map[string][]net.Addr) sources {
|
|
||||||
var out sources
|
|
||||||
for name, addrs := range interfaces {
|
|
||||||
if name != "docker0" && !strings.HasPrefix(name, "br-") {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
for _, a := range addrs {
|
|
||||||
if ipnet, ok := a.(*net.IPNet); ok {
|
|
||||||
if prefix, err := netip.ParsePrefix(ipnet.String()); err == nil {
|
|
||||||
out = append(out, prefix.Masked())
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return out
|
|
||||||
}
|
|
||||||
|
|
||||||
// theseBridges reads this machine's interfaces for bridgesFrom. An interface that cannot be read
|
|
||||||
// contributes nothing: fewer callers inside, never more.
|
|
||||||
func theseBridges() sources {
|
|
||||||
interfaces, err := net.Interfaces()
|
|
||||||
if err != nil {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
named := map[string][]net.Addr{}
|
|
||||||
for _, i := range interfaces {
|
|
||||||
if addrs, err := i.Addrs(); err == nil {
|
|
||||||
named[i.Name] = addrs
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return bridgesFrom(named)
|
|
||||||
}
|
|
||||||
|
|
||||||
// holds says whether a request from this remote address came from inside these ranges, or from
|
|
||||||
// the machine itself.
|
|
||||||
//
|
//
|
||||||
// **By source, which the guard deliberately is not** — it names interfaces because a source
|
// **By source, which the mesh's guard deliberately is not** — it names interfaces, because a source
|
||||||
// address can be claimed by whoever sends the packet. The proxy cannot see the interface a request
|
// address can be claimed by whoever sends the packet. The proxy cannot see the interface a request
|
||||||
// arrived on, and here the claim does not carry: a connection needs its replies, and replies to a
|
// arrived on, and here the claim does not carry: a connection needs its replies, and replies to a
|
||||||
// mesh or container address leave by the tunnel or a local bridge, never back to the claimant.
|
// mesh address leave by the tunnel, never back to the claimant.
|
||||||
func (s sources) holds(remote string) bool {
|
func (s sources) holds(remote string) bool {
|
||||||
host := remote
|
host := remote
|
||||||
if h, _, err := net.SplitHostPort(remote); err == nil {
|
if h, _, err := net.SplitHostPort(remote); err == nil {
|
||||||
@@ -418,13 +386,13 @@ func (t *table) hiddenFrom(host, remote string) bool {
|
|||||||
}
|
}
|
||||||
t.mu.RLock()
|
t.mu.RLock()
|
||||||
defer t.mu.RUnlock()
|
defer t.mu.RUnlock()
|
||||||
return !t.inside.holds(remote) && !t.bridges.holds(remote)
|
return !t.inside.holds(remote)
|
||||||
}
|
}
|
||||||
|
|
||||||
// setBridges replaces the machine's container networks.
|
// setInside replaces who the mesh is, as the membership said.
|
||||||
func (t *table) setBridges(bridges sources) {
|
func (t *table) setInside(inside sources) {
|
||||||
t.mu.Lock()
|
t.mu.Lock()
|
||||||
t.bridges = bridges
|
t.inside = inside
|
||||||
t.mu.Unlock()
|
t.mu.Unlock()
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -469,19 +437,20 @@ func run() error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
held := newTable()
|
held := newTable()
|
||||||
// Unset means only this machine and its containers are inside, which serves an internal-only
|
// **The bus first, the file until it has spoken** (novox/hq ADR 0167). The membership carries
|
||||||
// name to nobody else — refused rather than served to everyone, which is what the proxy did
|
// the routes and who the mesh is; the file carries the routes alone, so while the proxy reads
|
||||||
// before it knew.
|
// it an internal name is served to this machine and to nobody else — refused, never opened.
|
||||||
inside, err := sourcesFrom(os.Getenv("INTERNAL_SOURCES"))
|
fromBus := &atomic.Bool{}
|
||||||
if err != nil {
|
if credential := strings.TrimSpace(os.Getenv("MESH_BROKER_FILE")); credential != "" {
|
||||||
return fmt.Errorf("INTERNAL_SOURCES: %w", err)
|
go followMembership(credential, held, fromBus)
|
||||||
|
} else {
|
||||||
|
log.Printf("MESH_BROKER_FILE is not set: routes come from %s alone, and a name that is only "+
|
||||||
|
"internal is served to this machine alone", path)
|
||||||
}
|
}
|
||||||
if len(inside) == 0 {
|
|
||||||
log.Printf("INTERNAL_SOURCES is not set: a name that is only internal is served to this machine " +
|
|
||||||
"and its containers alone")
|
|
||||||
}
|
|
||||||
held.inside = inside
|
|
||||||
read := func() {
|
read := func() {
|
||||||
|
if fromBus.Load() {
|
||||||
|
return
|
||||||
|
}
|
||||||
routes, public, err := routesFrom(path)
|
routes, public, err := routesFrom(path)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
// Kept serving what it had. A file being rewritten is momentarily unreadable, and
|
// Kept serving what it had. A file being rewritten is momentarily unreadable, and
|
||||||
@@ -491,7 +460,6 @@ func run() error {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
held.set(routes, public)
|
held.set(routes, public)
|
||||||
held.setBridges(theseBridges())
|
|
||||||
log.Printf("serving %d route(s): %s", len(routes), strings.Join(held.names(), ", "))
|
log.Printf("serving %d route(s): %s", len(routes), strings.Join(held.names(), ", "))
|
||||||
}
|
}
|
||||||
read()
|
read()
|
||||||
@@ -764,6 +732,11 @@ func handler(held *table) http.Handler {
|
|||||||
// And since a host may now be routed only on some paths, those are a third thing:
|
// And since a host may now be routed only on some paths, those are a third thing:
|
||||||
// saying "no route for this name" while listing that very name as served is a
|
// saying "no route for this name" while listing that very name as served is a
|
||||||
// contradiction an operator would have to disbelieve the proxy to get past.
|
// contradiction an operator would have to disbelieve the proxy to get past.
|
||||||
|
// **Said in the log as well as to the client.** A name this mesh does not serve, asked
|
||||||
|
// for from outside, is what a scanner does, and the machine's intrusion prevention reads
|
||||||
|
// this proxy's log for exactly that line (novox/hq ADR 0179): the address last, as the
|
||||||
|
// jail's filter expects it.
|
||||||
|
log.Printf("refused: no route for %q, asked from %s", r.Host, r.RemoteAddr)
|
||||||
w.Header().Set("Content-Type", "text/plain; charset=utf-8")
|
w.Header().Set("Content-Type", "text/plain; charset=utf-8")
|
||||||
w.WriteHeader(http.StatusNotFound)
|
w.WriteHeader(http.StatusNotFound)
|
||||||
if !hidden && held.routed(r.Host) {
|
if !hidden && held.routed(r.Host) {
|
||||||
@@ -886,10 +859,16 @@ func routesFrom(path string) (map[string][]rule, map[string]bool, error) {
|
|||||||
if err := json.Unmarshal(raw, &said); err != nil {
|
if err := json.Unmarshal(raw, &said); err != nil {
|
||||||
return nil, nil, err
|
return nil, nil, err
|
||||||
}
|
}
|
||||||
|
routes, public := routesOf(said.Given)
|
||||||
|
return routes, public, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// routesOf turns what the mesh gave into host → the rules for that host, and which hosts are public
|
||||||
|
// names — the same whether the contributions came in the file or in the membership.
|
||||||
|
func routesOf(contributions []contribution) (map[string][]rule, map[string]bool) {
|
||||||
out := map[string][]rule{}
|
out := map[string][]rule{}
|
||||||
public := map[string]bool{}
|
public := map[string]bool{}
|
||||||
for _, c := range said.Given {
|
for _, c := range contributions {
|
||||||
name, _ := c.Values["name"].(string)
|
name, _ := c.Values["name"].(string)
|
||||||
name = strings.TrimSpace(name)
|
name = strings.TrimSpace(name)
|
||||||
internal, _ := c.Values["internal-name"].(string)
|
internal, _ := c.Values["internal-name"].(string)
|
||||||
@@ -994,7 +973,7 @@ func routesFrom(path string) (map[string][]rule, map[string]bool, error) {
|
|||||||
out[strings.ToLower(internal)] = append(out[strings.ToLower(internal)], made)
|
out[strings.ToLower(internal)] = append(out[strings.ToLower(internal)], made)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
return out, public, nil
|
return out, public
|
||||||
}
|
}
|
||||||
|
|
||||||
// asWhole is any whole number the mesh wrote, whatever its magnitude.
|
// asWhole is any whole number the mesh wrote, whatever its magnitude.
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ package main
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"crypto/tls"
|
"crypto/tls"
|
||||||
|
"encoding/json"
|
||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
"net"
|
"net"
|
||||||
@@ -10,11 +11,13 @@ import (
|
|||||||
"net/url"
|
"net/url"
|
||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
|
"github.com/novox/mesh-controller/internal/broker"
|
||||||
)
|
)
|
||||||
|
|
||||||
// behind is a workload the proxy can send to, and a table routing one public name and one
|
// behind is a workload the proxy can send to, and a table routing one public name and one
|
||||||
// internal-only name to it, with the private network set to inside.
|
// internal-only name to it, with the mesh's machines as the membership would issue them.
|
||||||
func behind(t *testing.T, inside string) *table {
|
func behind(t *testing.T, mesh ...string) *table {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
workload := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
workload := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
io.WriteString(w, "the workload")
|
io.WriteString(w, "the workload")
|
||||||
@@ -33,10 +36,11 @@ func behind(t *testing.T, inside string) *table {
|
|||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
held := newTable()
|
held := newTable()
|
||||||
held.inside, err = sourcesFrom(inside)
|
inside, err := sourcesOf(mesh)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
held.setInside(inside)
|
||||||
held.set(routes, public)
|
held.set(routes, public)
|
||||||
return held
|
return held
|
||||||
}
|
}
|
||||||
@@ -54,7 +58,7 @@ func askFrom(held *table, host, remote string) (int, string) {
|
|||||||
// 0138, issue 191). The proxy answers public names on the same listeners, so without this a name
|
// 0138, issue 191). The proxy answers public names on the same listeners, so without this a name
|
||||||
// being internal kept nobody out: a request from the internet only had to carry it.
|
// being internal kept nobody out: a request from the internet only had to carry it.
|
||||||
func TestAnInternalOnlyNameIsServedOnlyInsideThePrivateNetwork(t *testing.T) {
|
func TestAnInternalOnlyNameIsServedOnlyInsideThePrivateNetwork(t *testing.T) {
|
||||||
held := behind(t, "10.10.0.0/24")
|
held := behind(t, "10.10.0.1", "10.10.0.7")
|
||||||
|
|
||||||
if code, body := askFrom(held, "admin.anchor.internal", "10.10.0.7:51000"); code != http.StatusOK ||
|
if code, body := askFrom(held, "admin.anchor.internal", "10.10.0.7:51000"); code != http.StatusOK ||
|
||||||
body != "the workload" {
|
body != "the workload" {
|
||||||
@@ -83,7 +87,7 @@ func TestAnInternalOnlyNameIsServedOnlyInsideThePrivateNetwork(t *testing.T) {
|
|||||||
// an outsider only under the public name. Nothing is lost — the outsider has the public name — and a
|
// an outsider only under the public name. Nothing is lost — the outsider has the public name — and a
|
||||||
// name stays one thing whichever route it came from.
|
// name stays one thing whichever route it came from.
|
||||||
func TestAnInternalAliasOfAPublicRouteIsServedInsideOnly(t *testing.T) {
|
func TestAnInternalAliasOfAPublicRouteIsServedInsideOnly(t *testing.T) {
|
||||||
held := behind(t, "10.10.0.0/24")
|
held := behind(t, "10.10.0.1", "10.10.0.7")
|
||||||
if code, body := askFrom(held, "app.anchor.internal", "10.10.0.7:51000"); code != http.StatusOK {
|
if code, body := askFrom(held, "app.anchor.internal", "10.10.0.7:51000"); code != http.StatusOK {
|
||||||
t.Errorf("the internal alias stopped answering the private network: %d %q", code, body)
|
t.Errorf("the internal alias stopped answering the private network: %d %q", code, body)
|
||||||
}
|
}
|
||||||
@@ -95,32 +99,10 @@ func TestAnInternalAliasOfAPublicRouteIsServedInsideOnly(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// A container on this machine reaches the proxy from its bridge's range, and is the machine itself
|
// Before a membership has said who the mesh is, only the machine itself is inside — refused to
|
||||||
// (novox/hq ADR 0144): inside, though it is neither loopback nor the mesh.
|
// everyone else, never served to everyone.
|
||||||
func TestAContainerOnThisMachineIsInside(t *testing.T) {
|
func TestUntilTheMeshIsIssuedAnInternalOnlyNameIsServedToTheMachineAlone(t *testing.T) {
|
||||||
held := behind(t, "10.10.0.0/24")
|
held := behind(t)
|
||||||
_, bridge, _ := net.ParseCIDR("172.18.0.1/16")
|
|
||||||
bridge.IP = net.ParseIP("172.18.0.1")
|
|
||||||
_, other, _ := net.ParseCIDR("192.168.1.20/24")
|
|
||||||
other.IP = net.ParseIP("192.168.1.20")
|
|
||||||
held.setBridges(bridgesFrom(map[string][]net.Addr{
|
|
||||||
"br-0123456789ab": {bridge},
|
|
||||||
"eth0": {other},
|
|
||||||
}))
|
|
||||||
|
|
||||||
if code, _ := askFrom(held, "admin.anchor.internal", "172.18.0.5:51000"); code != http.StatusOK {
|
|
||||||
t.Errorf("a container on this machine was refused: %d", code)
|
|
||||||
}
|
|
||||||
// The machine's own network is not a container bridge: a neighbour there is not the machine.
|
|
||||||
if code, _ := askFrom(held, "admin.anchor.internal", "192.168.1.30:51000"); code != http.StatusNotFound {
|
|
||||||
t.Errorf("a neighbour on the machine's network was served an internal-only name: %d", code)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// With no private network said, only the machine itself is inside — refused to everyone else,
|
|
||||||
// never served to everyone.
|
|
||||||
func TestWithNoPrivateNetworkSaidAnInternalOnlyNameIsServedToTheMachineAlone(t *testing.T) {
|
|
||||||
held := behind(t, "")
|
|
||||||
if code, _ := askFrom(held, "admin.anchor.internal", "10.10.0.7:51000"); code != http.StatusNotFound {
|
if code, _ := askFrom(held, "admin.anchor.internal", "10.10.0.7:51000"); code != http.StatusNotFound {
|
||||||
t.Errorf("an internal-only name was served with no private network said: %d", code)
|
t.Errorf("an internal-only name was served with no private network said: %d", code)
|
||||||
}
|
}
|
||||||
@@ -139,7 +121,7 @@ func (c from) RemoteAddr() net.Addr { return c.remote }
|
|||||||
// The handshake refuses an internal-only name to an outsider too: the certificate would name it,
|
// The handshake refuses an internal-only name to an outsider too: the certificate would name it,
|
||||||
// and serving it would answer the question the routing refuses to.
|
// and serving it would answer the question the routing refuses to.
|
||||||
func TestTheHandshakeRefusesAnInternalOnlyNameToAnOutsider(t *testing.T) {
|
func TestTheHandshakeRefusesAnInternalOnlyNameToAnOutsider(t *testing.T) {
|
||||||
held := behind(t, "10.10.0.0/24")
|
held := behind(t, "10.10.0.1", "10.10.0.7")
|
||||||
served := &tls.Certificate{}
|
served := &tls.Certificate{}
|
||||||
pick := certificateFor(held, func(*tls.ClientHelloInfo) (*tls.Certificate, error) { return served, nil }, nil)
|
pick := certificateFor(held, func(*tls.ClientHelloInfo) (*tls.Certificate, error) { return served, nil }, nil)
|
||||||
hello := func(name, remote string) *tls.ClientHelloInfo {
|
hello := func(name, remote string) *tls.ClientHelloInfo {
|
||||||
@@ -158,26 +140,67 @@ func TestTheHandshakeRefusesAnInternalOnlyNameToAnOutsider(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// A range the proxy cannot read stops it, rather than serving internal names to fewer machines
|
// The mesh is issued as machines' addresses; a range is read as well. One that does not parse is
|
||||||
// than the mesh said, or to a typo.
|
// refused rather than skipped, so a typo never quietly narrows or widens who is inside.
|
||||||
func TestAPrivateNetworkThatDoesNotParseIsRefused(t *testing.T) {
|
func TestTheMeshIsReadAsAddressesAndRanges(t *testing.T) {
|
||||||
if _, err := sourcesFrom("10.10.0.0/24, not-a-range"); err == nil {
|
if _, err := sourcesOf([]string{"10.10.0.1", "not-an-address"}); err == nil {
|
||||||
t.Error("a range that does not parse was accepted")
|
t.Error("an entry that is not an address was accepted")
|
||||||
}
|
}
|
||||||
inside, err := sourcesFrom("10.10.0.0/24 fd00::/8")
|
inside, err := sourcesOf([]string{"10.10.0.1", "fd00::1", "10.20.0.0/24"})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
for remote, want := range map[string]bool{
|
for remote, want := range map[string]bool{
|
||||||
"10.10.0.200:1": true,
|
"10.10.0.1:1": true,
|
||||||
"[::ffff:10.10.0.3]:1": true,
|
"[::ffff:10.10.0.1]:1": true,
|
||||||
"[fd00::1]:1": true,
|
"[fd00::1]:1": true,
|
||||||
"10.11.0.1:1": false,
|
"10.20.0.200:1": true,
|
||||||
|
"10.10.0.2:1": false,
|
||||||
"192.168.1.10:1": false,
|
"192.168.1.10:1": false,
|
||||||
"not-an-address": false,
|
"not-an-address": false,
|
||||||
} {
|
} {
|
||||||
if inside.holds(remote) != want {
|
if inside.holds(remote) != want {
|
||||||
t.Errorf("%s inside the private network: got %v, want %v", remote, !want, want)
|
t.Errorf("%s inside the mesh: got %v, want %v", remote, !want, want)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// What the mesh issues is what is served: the routes in the membership, internal names to the
|
||||||
|
// machines it names (novox/hq ADR 0167).
|
||||||
|
func TestAMembershipIsServedAsIssued(t *testing.T) {
|
||||||
|
held := newTable()
|
||||||
|
took := applyMembership(broker.Membership{
|
||||||
|
Receives: map[string]json.RawMessage{"route": json.RawMessage(`[
|
||||||
|
{"from":"admin","node":"anchor","at":"anchor.internal",
|
||||||
|
"values":{"internal-name":"admin.anchor.internal","port":8080}}]`)},
|
||||||
|
Mesh: []string{"10.10.0.7"},
|
||||||
|
}, held)
|
||||||
|
if !took {
|
||||||
|
t.Fatal("a membership carrying routes was not applied")
|
||||||
|
}
|
||||||
|
if code, _ := askFrom(held, "admin.anchor.internal", "10.10.0.7:1"); code == http.StatusNotFound {
|
||||||
|
t.Error("a machine the membership names was refused the internal-only route")
|
||||||
|
}
|
||||||
|
if code, _ := askFrom(held, "admin.anchor.internal", "10.10.0.9:1"); code != http.StatusNotFound {
|
||||||
|
t.Errorf("a machine the membership does not name was served the internal-only route: %d", code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A membership that says nothing about routes is one from a controller that does not issue them,
|
||||||
|
// and changes nothing: the file stays the source rather than every route being withdrawn.
|
||||||
|
func TestAMembershipWithoutRoutesLeavesTheFileServing(t *testing.T) {
|
||||||
|
held := behind(t, "10.10.0.7")
|
||||||
|
before := held.names()
|
||||||
|
if applyMembership(broker.Membership{Mesh: []string{"10.10.0.7"}}, held) {
|
||||||
|
t.Error("a membership without routes was taken as the source of routes")
|
||||||
|
}
|
||||||
|
if got := held.names(); strings.Join(got, ",") != strings.Join(before, ",") {
|
||||||
|
t.Errorf("a membership without routes changed what is served: %v, was %v", got, before)
|
||||||
|
}
|
||||||
|
if applyMembership(broker.Membership{
|
||||||
|
Receives: map[string]json.RawMessage{"route": json.RawMessage(`[]`)},
|
||||||
|
Mesh: []string{"not-an-address"},
|
||||||
|
}, held) {
|
||||||
|
t.Error("a membership whose mesh cannot be read was applied")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -234,3 +234,13 @@ func admitsSubject(pattern, subject []string) bool {
|
|||||||
}
|
}
|
||||||
return len(pattern) == len(subject)
|
return len(pattern) == len(subject)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The two packages name the runtime module separately — the broker's types stay free of the
|
||||||
|
// catalogue's on purpose — so this is what holds them to one string. A rename that reached only one
|
||||||
|
// side would compose a runtime principal for a module nobody assigns, silently, and leave the one
|
||||||
|
// that is assigned with a module's own grants.
|
||||||
|
func TestTheBrokerAndTheCatalogueAgreeOnTheRuntimeModule(t *testing.T) {
|
||||||
|
if RuntimeModule != catalogue.RuntimeModule {
|
||||||
|
t.Fatalf("the broker calls the runtime %q and the catalogue %q", RuntimeModule, catalogue.RuntimeModule)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
+16
-15
@@ -144,12 +144,18 @@ func ConsumerFor(p Principal) (Consumer, bool) {
|
|||||||
}, true
|
}, true
|
||||||
}
|
}
|
||||||
|
|
||||||
// HolderConsumerFor is the worker a seat's holder gets on that seat's work queue.
|
// HolderConsumerFor is the worker a seat's holders share on that seat's work queue.
|
||||||
//
|
//
|
||||||
// **A queue group even though the seat guarantees one holder.** The seat is *authority* — who may
|
// **One worker for every holder, and each holder pulls one ask when it is idle** (novox/hq ADR
|
||||||
// be the telegram sender — and the queue group is *delivery*. Tie delivery to the seat and the
|
// 0190). The seat is *authority* — who may be the telegram sender — and the worker is *delivery*,
|
||||||
// day somebody allows two holders for throughput, every message is processed twice with nothing
|
// kept separate so that relaxing one changes nothing about the other: a node-scoped seat has a
|
||||||
// reporting it. Kept separate, relaxing one changes nothing about the other.
|
// holder per machine, and all of them take from this one consumer, so the work is shared without
|
||||||
|
// any holder knowing about the others. Pulled rather than pushed because a push consumer hands the
|
||||||
|
// next ask to whichever subscriber the server picks, busy or not, and a pulled one is asked for by
|
||||||
|
// a holder that has just become free. Which is also what ends the race issue 186 describes — asks
|
||||||
|
// delivered behind the one being worked, expiring unacknowledged and dropped after the fifth
|
||||||
|
// redelivery: nothing is delivered that nobody asked for. A long build keeps its own ask alive
|
||||||
|
// (stillWorking); the ack wait is for a holder that died.
|
||||||
func HolderConsumerFor(node, module string, seat DeclaredSeat) (Consumer, bool) {
|
func HolderConsumerFor(node, module string, seat DeclaredSeat) (Consumer, bool) {
|
||||||
if len(seat.Accepts) == 0 {
|
if len(seat.Accepts) == 0 {
|
||||||
return Consumer{}, false
|
return Consumer{}, false
|
||||||
@@ -158,18 +164,13 @@ func HolderConsumerFor(node, module string, seat DeclaredSeat) (Consumer, bool)
|
|||||||
Name: "SEAT_" + upperSnake(seat.Name) + "_worker",
|
Name: "SEAT_" + upperSnake(seat.Name) + "_worker",
|
||||||
Stream: seatStreamName(seat.Name),
|
Stream: seatStreamName(seat.Name),
|
||||||
Filters: []string{"mesh.seat." + seat.Name + ".accept.>"},
|
Filters: []string{"mesh.seat." + seat.Name + ".accept.>"},
|
||||||
Queue: "holders",
|
|
||||||
AckWaitSeconds: 60,
|
AckWaitSeconds: 60,
|
||||||
MaxDeliver: 5,
|
MaxDeliver: 5,
|
||||||
// **One in flight.** A holder works one ask at a time, so the server hands it one at a
|
// As many in flight as there are holders working, which pulling bounds by itself: a holder
|
||||||
// time: with the default of many, every ask behind the one being worked was delivered,
|
// fetches one and fetches again only after it acknowledged. The server's default stands.
|
||||||
// left unacknowledged for the length of the work, redelivered after the ack wait, and
|
Why: fmt.Sprintf("%s on %s holds %s; every holder pulls one ask at a time from this worker "+
|
||||||
// after the fifth time dropped — on 2026-10-01 twenty-six of forty-three builds asked in
|
"and acknowledges after the work is done, so a crash mid-work redelivers rather than "+
|
||||||
// two minutes were never built, and the queue read as empty (novox/hq issue 186).
|
"loses and an idle holder is the one that takes the next ask", module, node, seat.Name),
|
||||||
MaxAckPending: 1,
|
|
||||||
Why: fmt.Sprintf("%s on %s holds %s; it acknowledges after the work is done, so a "+
|
|
||||||
"crash mid-work redelivers rather than loses; one in flight, so a queue of asks is a "+
|
|
||||||
"queue and not a race against the ack wait", module, node, seat.Name),
|
|
||||||
}, true
|
}, true
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -88,15 +88,20 @@ func TestAModuleThatConsumesNothingGetsNoConsumer(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// The seat is authority and the queue group is delivery. Tie them together and the day somebody
|
// The seat is authority and the worker is delivery (novox/hq ADR 0190): one worker per seat, shared
|
||||||
// allows two holders, every message is processed twice with nothing reporting it.
|
// by every holder and pulled from, so a second holder takes the next ask rather than a copy of the
|
||||||
func TestAHoldersWorkerUsesAQueueGroupAnyway(t *testing.T) {
|
// same one — which is what a queue group used to guard, and what pulling one durable gives outright.
|
||||||
|
func TestAHoldersWorkerIsOneSharedByItsHolders(t *testing.T) {
|
||||||
c, ok := HolderConsumerFor("one", "telegram", telegramSeat())
|
c, ok := HolderConsumerFor("one", "telegram", telegramSeat())
|
||||||
if !ok {
|
if !ok {
|
||||||
t.Fatal("the holder of a seat with inbound work got no worker")
|
t.Fatal("the holder of a seat with inbound work got no worker")
|
||||||
}
|
}
|
||||||
if c.Queue == "" {
|
two, _ := HolderConsumerFor("two", "telegram", telegramSeat())
|
||||||
t.Fatal("the worker is not in a queue group, so a second holder would double-process")
|
if c.Name != two.Name || c.Stream != two.Stream {
|
||||||
|
t.Fatal("two holders got two workers, so each would process every ask")
|
||||||
|
}
|
||||||
|
if c.Push || c.Queue != "" {
|
||||||
|
t.Fatal("the worker is pushed, so the server would hand an ask to a busy holder")
|
||||||
}
|
}
|
||||||
if c.Stream != "SEAT_TELEGRAM_SENDER" {
|
if c.Stream != "SEAT_TELEGRAM_SENDER" {
|
||||||
t.Fatalf("the worker reads %q, not the seat's own stream", c.Stream)
|
t.Fatalf("the worker reads %q, not the seat's own stream", c.Stream)
|
||||||
@@ -154,15 +159,23 @@ func TestANodesDeclarationConsumerIsWhatItsOwnGrantAllows(t *testing.T) {
|
|||||||
has(t, perms.Subscribe, c.Filters[0])
|
has(t, perms.Subscribe, c.Filters[0])
|
||||||
}
|
}
|
||||||
|
|
||||||
// A holder works one ask at a time, so the server hands it one at a time (novox/hq issue 186):
|
// Every holder of a seat shares one worker and pulls from it (novox/hq ADR 0190): no queue group
|
||||||
// asks queued behind the one being worked wait in the stream rather than being delivered,
|
// and no delivery subject, because a push consumer hands the next ask to whichever subscriber the
|
||||||
// left to expire and dropped after the fifth redelivery.
|
// server picks, busy or not; and no cap of one in flight, because pulling bounds the asks in flight
|
||||||
func TestAHoldersWorkerTakesOneAskAtATime(t *testing.T) {
|
// by the holders that are free — which is what ended the race of issue 186, where asks delivered
|
||||||
c, found := HolderConsumerFor("anchor", "builder", DeclaredSeat{Name: "mesh-build-machine", Accepts: []string{"build"}})
|
// behind the one being worked expired and were dropped.
|
||||||
|
func TestAHoldersWorkerIsPulledByEveryHolder(t *testing.T) {
|
||||||
|
c, found := HolderConsumerFor("anchor", "build-agent", DeclaredSeat{Name: "node-build-agent", Accepts: []string{"build"}})
|
||||||
if !found {
|
if !found {
|
||||||
t.Fatal("a seat that accepts work has no worker")
|
t.Fatal("a seat that accepts work has no worker")
|
||||||
}
|
}
|
||||||
if c.MaxAckPending != 1 {
|
if c.Queue != "" || c.Push {
|
||||||
t.Fatalf("the worker may have %d asks in flight; one, so a queue is a queue", c.MaxAckPending)
|
t.Fatalf("the worker is pushed (queue %q, push %v); a holder pulls when it is free", c.Queue, c.Push)
|
||||||
|
}
|
||||||
|
if c.MaxAckPending != 0 {
|
||||||
|
t.Fatalf("the worker caps asks in flight at %d; pulling bounds them by the holders working", c.MaxAckPending)
|
||||||
|
}
|
||||||
|
if c.Name != "SEAT_NODE_BUILD_AGENT_worker" || c.Stream != "SEAT_NODE_BUILD_AGENT" {
|
||||||
|
t.Fatalf("the worker is %s on %s; one per seat, shared by its holders", c.Name, c.Stream)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
package broker
|
package broker
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"encoding/json"
|
||||||
"sort"
|
"sort"
|
||||||
"strings"
|
"strings"
|
||||||
)
|
)
|
||||||
@@ -33,6 +34,17 @@ type Membership struct {
|
|||||||
Reaches map[string][]string `json:"reaches,omitempty"`
|
Reaches map[string][]string `json:"reaches,omitempty"`
|
||||||
// Tools is where this instance answers what it serves — the runtime's one verb of its own.
|
// Tools is where this instance answers what it serves — the runtime's one verb of its own.
|
||||||
Tools string `json:"tools"`
|
Tools string `json:"tools"`
|
||||||
|
// Receives is what this assignment is given for each requirement it receives, by requirement:
|
||||||
|
// the contributions of every module that asked for it, as the catalogue composed them (novox/hq
|
||||||
|
// ADR 0167). The same list its received file is written from, so the two cannot disagree; a
|
||||||
|
// requirement nobody contributed to is an empty list, never absent. Kept as JSON because the
|
||||||
|
// catalogue owns the shape of a contribution and the bus only carries it.
|
||||||
|
Receives map[string]json.RawMessage `json:"receives,omitempty"`
|
||||||
|
// Mesh is every machine's address on the private network — what a rule saying "from the mesh"
|
||||||
|
// resolves to in the packet filter, issued here from the same list (novox/hq ADR 0167). A
|
||||||
|
// module that must tell the mesh from the world, the route proxy serving an internal name, reads
|
||||||
|
// it here rather than keeping a definition of its own.
|
||||||
|
Mesh []string `json:"mesh,omitempty"`
|
||||||
}
|
}
|
||||||
|
|
||||||
// Served is one address a tool is answered on.
|
// Served is one address a tool is answered on.
|
||||||
|
|||||||
@@ -73,3 +73,37 @@ func TestAnAccountMayReadItsOwnMembershipAndNoOthers(t *testing.T) {
|
|||||||
has(t, perms.Publish, "$JS.API.DIRECT.GET.ASSIGNMENTS.mesh.assignment.anchor.postgres")
|
has(t, perms.Publish, "$JS.API.DIRECT.GET.ASSIGNMENTS.mesh.assignment.anchor.postgres")
|
||||||
hasNot(t, perms.Subscribe, "mesh.assignment.>")
|
hasNot(t, perms.Subscribe, "mesh.assignment.>")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The runtime arriving on a machine changes nothing about what each module is issued (to-be 38 WP2):
|
||||||
|
// the memberships are composed as before and the runtime reads several of them. What the machine's
|
||||||
|
// user list gains is one runtime principal, and loses nothing but the runtime module's own.
|
||||||
|
func TestTheRuntimeArrivingLeavesEveryMembershipAsItWas(t *testing.T) {
|
||||||
|
filter := Seat{Name: "node-packet-filter", Scope: "node", Serves: []string{"rules", "reload"}}
|
||||||
|
three := []Declared{
|
||||||
|
{Module: "nftables", Holds: []Seat{filter}, Serves: []string{"firewall_rules"}},
|
||||||
|
{Module: "zsh", Serves: []string{"execute"}},
|
||||||
|
{Module: "systemd", Serves: []string{"units"}},
|
||||||
|
}
|
||||||
|
before := Records{Nodes: []string{"anchor"}, Assigned: map[string][]Declared{"anchor": three}}
|
||||||
|
after := Records{Nodes: []string{"anchor"}, Assigned: map[string][]Declared{
|
||||||
|
"anchor": append(append([]Declared{}, three...), Declared{Module: RuntimeModule}),
|
||||||
|
}}
|
||||||
|
for _, d := range three {
|
||||||
|
was := MembershipFor("anchor", d, PlacementsOf(before, nil))
|
||||||
|
is := MembershipFor("anchor", d, PlacementsOf(after, nil))
|
||||||
|
if !reflect.DeepEqual(was, is) {
|
||||||
|
t.Errorf("%s's membership changed when the runtime arrived:\n%+v\n%+v", d.Module, was, is)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
users, err := Users(after)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
kinds := map[Kind]int{}
|
||||||
|
for _, p := range users {
|
||||||
|
kinds[p.Kind]++
|
||||||
|
}
|
||||||
|
if kinds[KindNodeTools] != 1 || kinds[KindModule] != 3 || kinds[KindNode] != 1 || kinds[KindController] != 1 {
|
||||||
|
t.Errorf("the machine's users are %v; one runtime, the three modules, the host and the controller", kinds)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
+99
-10
@@ -34,8 +34,20 @@ const (
|
|||||||
// authority is a list of tools and nothing else — not control, not declarations, not builds,
|
// authority is a list of tools and nothing else — not control, not declarations, not builds,
|
||||||
// and no ability to answer anything, because a person asks.
|
// and no ability to answer anything, because a person asks.
|
||||||
KindPerson Kind = "person"
|
KindPerson Kind = "person"
|
||||||
|
// KindNodeTools is a machine's tool runtime (novox/hq ADR 0175, to-be 38): one process per
|
||||||
|
// node, on the host side, serving every assigned module's tools and every held seat's verbs.
|
||||||
|
// Its authority is the union of what the modules it carries would each have had for their
|
||||||
|
// tools — and nothing of what they consume, because tools are what it runs, not reactions.
|
||||||
|
KindNodeTools Kind = "node-tools"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
// RuntimeModule is the module that IS the node's tool runtime (novox/hq ADR 0175). Where it is
|
||||||
|
// assigned, the mesh composes one runtime principal for the machine in place of that module's own,
|
||||||
|
// and the per-module containers that served tools until then stop being the way tools reach a node.
|
||||||
|
// Mirrored in the catalogue package, which the agreement test holds to the same string; one
|
||||||
|
// constant, so a rename is one edit and the two packages cannot drift.
|
||||||
|
const RuntimeModule = "node-tools"
|
||||||
|
|
||||||
// Seat is a role on the bus as a principal relates to it: the subjects it accepts, and those it
|
// Seat is a role on the bus as a principal relates to it: the subjects it accepts, and those it
|
||||||
// emits (novox/hq ADR 0118, design 29 §5).
|
// emits (novox/hq ADR 0118, design 29 §5).
|
||||||
type Seat struct {
|
type Seat struct {
|
||||||
@@ -74,6 +86,13 @@ type Principal struct {
|
|||||||
// a namespace no such module owns. Every service started and the graph stayed empty.
|
// a namespace no such module owns. Every service started and the graph stayed empty.
|
||||||
Watches []Seat
|
Watches []Seat
|
||||||
|
|
||||||
|
// Carries are the modules whose tools this principal serves, for a KindNodeTools principal
|
||||||
|
// (novox/hq ADR 0175): every module assigned to its node, as each declares itself. Its
|
||||||
|
// serving authority is the union of theirs — each module's own tool namespace and each held
|
||||||
|
// seat's verbs on this node — derived from the same declarations the modules' own principals
|
||||||
|
// are, so the runtime can serve nothing a module could not have served for itself.
|
||||||
|
Carries []Declared
|
||||||
|
|
||||||
// Invokes are the tools this principal may call, as `<module>.<tool>`; a single `*` is every
|
// Invokes are the tools this principal may call, as `<module>.<tool>`; a single `*` is every
|
||||||
// tool. A person's whole authority (design 25 §7), and a module's only if its manifest says so
|
// tool. A person's whole authority (design 25 §7), and a module's only if its manifest says so
|
||||||
// (novox/hq ADR 0152) — the console's does, and nothing else's.
|
// (novox/hq ADR 0152) — the console's does, and nothing else's.
|
||||||
@@ -91,10 +110,10 @@ type Principal struct {
|
|||||||
PasswordHash string
|
PasswordHash string
|
||||||
}
|
}
|
||||||
|
|
||||||
// meshSeatsTheControllerUses are the roles the mesh's own flows submit work to. Named rather than
|
// seatsTheControllerAsks are the roles the mesh's own flows submit work to. Named rather than
|
||||||
// derived from the seat set: the controller is not a module and declares no `uses`, so its side of a
|
// derived from the seat set: the controller is not a module and declares no `uses`, so its side of a
|
||||||
// seat has to be stated, and a list is what makes "which roles does the mesh itself talk to" answerable.
|
// seat has to be stated, and a list is what makes "which roles does the mesh itself talk to" answerable.
|
||||||
var meshSeatsTheControllerUses = []string{"mesh-build-machine"}
|
var seatsTheControllerAsks = []string{"node-build-agent"}
|
||||||
|
|
||||||
// enrolmentPrefix is the space every enrolling node's user and inbox live under, so the one place the
|
// enrolmentPrefix is the space every enrolling node's user and inbox live under, so the one place the
|
||||||
// controller may answer an enrolment is derived from the same constant the user is named from.
|
// controller may answer an enrolment is derived from the same constant the user is named from.
|
||||||
@@ -112,7 +131,10 @@ func (p Principal) Username() string {
|
|||||||
switch p.Kind {
|
switch p.Kind {
|
||||||
case KindPerson:
|
case KindPerson:
|
||||||
return "person." + p.Module
|
return "person." + p.Module
|
||||||
case KindModule:
|
case KindModule, KindNodeTools:
|
||||||
|
// The runtime is named exactly as the module it stands for would have been: the mesh
|
||||||
|
// issues its credential through the same path a module's takes (`module issue`), and
|
||||||
|
// that path knows the node and the module, not the kind.
|
||||||
return p.Node + "." + p.Module
|
return p.Node + "." + p.Module
|
||||||
case KindNode:
|
case KindNode:
|
||||||
return "node." + p.Node
|
return "node." + p.Node
|
||||||
@@ -186,7 +208,9 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
|||||||
// Work the mesh's own flows submit to a role, and the outcomes they wait on (ADR 0121). A
|
// Work the mesh's own flows submit to a role, and the outcomes they wait on (ADR 0121). A
|
||||||
// build is the one today: the controller asks, and reads the answer from the seat's event
|
// build is the one today: the controller asks, and reads the answer from the seat's event
|
||||||
// like the catalogue does — which is why no holder needs to publish into anybody's inbox.
|
// like the catalogue does — which is why no holder needs to publish into anybody's inbox.
|
||||||
for _, seat := range meshSeatsTheControllerUses {
|
// A node-scoped seat's work subject carries no node (novox/hq ADR 0190): the ask goes to
|
||||||
|
// the role, and whichever machine holding it is idle takes it.
|
||||||
|
for _, seat := range seatsTheControllerAsks {
|
||||||
pub = append(pub, "mesh.seat."+seat+".accept.>")
|
pub = append(pub, "mesh.seat."+seat+".accept.>")
|
||||||
}
|
}
|
||||||
// **And what the mesh says it did** (novox/hq ADR 0134). The control plane states its own
|
// **And what the mesh says it did** (novox/hq ADR 0134). The control plane states its own
|
||||||
@@ -346,13 +370,17 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
|||||||
|
|
||||||
// 3. Seats it holds: full participation.
|
// 3. Seats it holds: full participation.
|
||||||
for _, s := range p.Holds {
|
for _, s := range p.Holds {
|
||||||
// Taking work from the role's queue: the worker consumer it binds (asked about,
|
// Taking work from the role's queue: the worker consumer every holder shares (asked
|
||||||
// delivered on, acknowledged), each on the seat's own stream. The first machine to
|
// about, pulled from, acknowledged), on the seat's own stream (novox/hq ADR 0190). A
|
||||||
// take work over the new bus was refused the asking (2026-09-28).
|
// holder pulls — asks the consumer for its next message, answered on its own inbox —
|
||||||
|
// so what it needs is MSG.NEXT on that worker and nothing delivered to it. The first
|
||||||
|
// machine to take work over the new bus was refused the asking (2026-09-28).
|
||||||
worker := "SEAT_" + upperSnake(s.Name) + "_worker"
|
worker := "SEAT_" + upperSnake(s.Name) + "_worker"
|
||||||
stream := seatStreamName(s.Name)
|
stream := seatStreamName(s.Name)
|
||||||
sub = append(sub, "_DELIVER."+worker, "_DELIVER."+worker+".>")
|
pub = append(pub,
|
||||||
pub = append(pub, "$JS.API.CONSUMER.INFO."+stream+"."+worker, "$JS.ACK."+stream+"."+worker+".>")
|
"$JS.API.CONSUMER.INFO."+stream+"."+worker,
|
||||||
|
"$JS.API.CONSUMER.MSG.NEXT."+stream+"."+worker,
|
||||||
|
"$JS.ACK."+stream+"."+worker+".>")
|
||||||
for _, a := range s.Accepts {
|
for _, a := range s.Accepts {
|
||||||
sub = append(sub, seatSubject(s, "accept", a))
|
sub = append(sub, seatSubject(s, "accept", a))
|
||||||
}
|
}
|
||||||
@@ -375,6 +403,48 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
|||||||
pub = append(pub, seatToolSubject(s, t, "*"))
|
pub = append(pub, seatToolSubject(s, t, "*"))
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
case KindNodeTools:
|
||||||
|
// **One process serves what every module on the machine would have served for itself**
|
||||||
|
// (novox/hq ADR 0175). Each carried module's whole tool namespace — the same grant that
|
||||||
|
// module's own principal has, for the same reason: the tools a module serves are what its
|
||||||
|
// code answers, and a list here would be a second copy of it. Each held seat's verbs on
|
||||||
|
// this node, as the holder's own principal would be granted them.
|
||||||
|
for _, d := range p.Carries {
|
||||||
|
if !safeSubject.MatchString(d.Module) {
|
||||||
|
return Permissions{}, fmt.Errorf(
|
||||||
|
"%q cannot be part of a subject: a permission is a subject pattern, and this would widen it", d.Module)
|
||||||
|
}
|
||||||
|
own := "mesh.mod." + d.Module
|
||||||
|
sub = append(sub, own+".tool.>")
|
||||||
|
// A tool that emits an event is the module's code and emits under the module's name
|
||||||
|
// (ADR 0042); the runtime carrying that code may publish what the module declared it
|
||||||
|
// emits, and nothing it did not.
|
||||||
|
for _, e := range d.Emits {
|
||||||
|
pub = append(pub, own+".event."+e)
|
||||||
|
}
|
||||||
|
for _, s := range d.Holds {
|
||||||
|
for _, t := range s.Serves {
|
||||||
|
sub = append(sub, seatToolSubject(s, t, p.Node))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// Every assigned module's membership on this node (ADR 0160): one per module, read
|
||||||
|
// directly from the stream and followed live. This node's and no other's — the one token
|
||||||
|
// that varies is the module, so the pattern is the machine's own assignments.
|
||||||
|
sub = append(sub, "mesh.assignment."+p.Node+".*")
|
||||||
|
pub = append(pub, "$JS.API.DIRECT.GET."+AssignmentsStream+".mesh.assignment."+p.Node+".*")
|
||||||
|
// And every tool on the mesh (ADR 0175, decision 5): any node may call any tool on any
|
||||||
|
// node, as the console already could — the runtime is the console's serving mode.
|
||||||
|
invoked, err := invokedSubjects([]string{"*"})
|
||||||
|
if err != nil {
|
||||||
|
return Permissions{}, err
|
||||||
|
}
|
||||||
|
pub = append(pub, invoked...)
|
||||||
|
// Nothing about consumers: it consumes nothing. A module's reactions to events are its
|
||||||
|
// own long-lived process, which ADR 0175 leaves where it is; what moves here is tools.
|
||||||
|
sub = unique(sub)
|
||||||
|
pub = unique(pub)
|
||||||
}
|
}
|
||||||
|
|
||||||
if p.Kind == KindPerson {
|
if p.Kind == KindPerson {
|
||||||
@@ -382,6 +452,11 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
|||||||
// consumer, because nothing is delivered to a person — they ask and are answered.
|
// consumer, because nothing is delivered to a person — they ask and are answered.
|
||||||
sub = append(sub, p.inbox())
|
sub = append(sub, p.inbox())
|
||||||
}
|
}
|
||||||
|
if p.Kind == KindNodeTools {
|
||||||
|
// Its reply space, so the answers to what its tools call come back to it. No ack subject
|
||||||
|
// for the same reason a person has none: nothing is delivered to it.
|
||||||
|
sub = append(sub, p.inbox())
|
||||||
|
}
|
||||||
|
|
||||||
if p.Kind == KindModule || p.Kind == KindNode || p.Kind == KindController {
|
if p.Kind == KindModule || p.Kind == KindNode || p.Kind == KindController {
|
||||||
// Its own reply space, and nothing wider.
|
// Its own reply space, and nothing wider.
|
||||||
@@ -403,7 +478,7 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
|||||||
// A module answers what it was asked — a tool call reaches it on its own namespace, so the
|
// A module answers what it was asked — a tool call reaches it on its own namespace, so the
|
||||||
// authority is bounded by having been asked — and so does the controller. A node and a
|
// authority is bounded by having been asked — and so does the controller. A node and a
|
||||||
// person are never asked anything, and are granted nothing here.
|
// person are never asked anything, and are granted nothing here.
|
||||||
AllowResponses: p.Kind == KindModule || p.Kind == KindController,
|
AllowResponses: p.Kind == KindModule || p.Kind == KindController || p.Kind == KindNodeTools,
|
||||||
}, nil
|
}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -625,6 +700,20 @@ func ComposeAccounts(principals []Principal) (string, error) {
|
|||||||
return b.String(), nil
|
return b.String(), nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// unique is a sorted list with each subject once. Two carried modules holding seats with the same
|
||||||
|
// verb, or the runtime module itself carried beside the others, would otherwise write a grant twice
|
||||||
|
// — harmless to the server, and noise in a file that is read as the mesh's authority model.
|
||||||
|
func unique(values []string) []string {
|
||||||
|
sort.Strings(values)
|
||||||
|
out := values[:0]
|
||||||
|
for i, v := range values {
|
||||||
|
if i == 0 || v != values[i-1] {
|
||||||
|
out = append(out, v)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return out
|
||||||
|
}
|
||||||
|
|
||||||
func quoted(values []string) string {
|
func quoted(values []string) string {
|
||||||
if len(values) == 0 {
|
if len(values) == 0 {
|
||||||
return ""
|
return ""
|
||||||
|
|||||||
@@ -371,3 +371,94 @@ func TestAModulePullsItsOwnConsumerAndNoOthers(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The runtime's authority is the union of what the modules it carries would have been granted for
|
||||||
|
// their tools (novox/hq ADR 0175): every carried module's tool namespace, every held seat's verbs
|
||||||
|
// on this node, every module's membership on this node, and a call to anything. Nothing it
|
||||||
|
// consumes, because it reacts to nothing.
|
||||||
|
func TestTheRuntimeServesTheUnionAndConsumesNothing(t *testing.T) {
|
||||||
|
filter := Seat{Name: "node-packet-filter", Scope: "node", Serves: []string{"rules", "reload"}}
|
||||||
|
p := Principal{Kind: KindNodeTools, Node: "anchor", Module: RuntimeModule, Carries: []Declared{
|
||||||
|
{Module: "nftables", Holds: []Seat{filter}, Serves: []string{"firewall_rules"}},
|
||||||
|
{Module: "zsh", Emits: []string{"shell.opened"}, Consumes: []string{"shop.order.placed"}},
|
||||||
|
{Module: RuntimeModule},
|
||||||
|
}}
|
||||||
|
perms, err := PermissionsFor(p)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
for _, want := range []string{
|
||||||
|
"mesh.mod.nftables.tool.>", "mesh.mod.zsh.tool.>", "mesh.mod." + RuntimeModule + ".tool.>",
|
||||||
|
"mesh.seat.node-packet-filter.tool.rules.anchor", "mesh.seat.node-packet-filter.tool.reload.anchor",
|
||||||
|
"mesh.assignment.anchor.*",
|
||||||
|
"_INBOX.anchor." + RuntimeModule + ".>",
|
||||||
|
} {
|
||||||
|
if !contains(perms.Subscribe, want) {
|
||||||
|
t.Errorf("the runtime may not subscribe %s: %v", want, perms.Subscribe)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
for _, want := range []string{
|
||||||
|
"mesh.mod.*.tool.>", "mesh.seat.*.tool.>",
|
||||||
|
"$JS.API.DIRECT.GET.ASSIGNMENTS.mesh.assignment.anchor.*",
|
||||||
|
"mesh.mod.zsh.event.shell.opened",
|
||||||
|
} {
|
||||||
|
if !contains(perms.Publish, want) {
|
||||||
|
t.Errorf("the runtime may not publish %s: %v", want, perms.Publish)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// Nothing of what a carried module consumes, and no consumer of its own to ack.
|
||||||
|
for _, s := range perms.Subscribe {
|
||||||
|
if strings.Contains(s, ".event.") || strings.HasPrefix(s, "_DELIVER.") {
|
||||||
|
t.Errorf("the runtime was granted a delivery it has no consumer for: %s", s)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
for _, s := range perms.Publish {
|
||||||
|
if strings.HasPrefix(s, "$JS.ACK.") || strings.Contains(s, "CONSUMER") {
|
||||||
|
t.Errorf("the runtime was granted a consumer's subject and has no consumer: %s", s)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !perms.AllowResponses {
|
||||||
|
t.Error("the runtime answers what it is asked, and may not reply")
|
||||||
|
}
|
||||||
|
if _, needed := ConsumerFor(p); needed {
|
||||||
|
t.Error("a consumer would be made for the runtime, which consumes nothing")
|
||||||
|
}
|
||||||
|
// Each subject once: the file is read as the mesh's authority model.
|
||||||
|
seen := map[string]bool{}
|
||||||
|
for _, s := range append(append([]string{}, perms.Subscribe...), perms.Publish...) {
|
||||||
|
if seen[s] {
|
||||||
|
t.Errorf("%s is granted twice", s)
|
||||||
|
}
|
||||||
|
seen[s] = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func contains(list []string, want string) bool {
|
||||||
|
for _, s := range list {
|
||||||
|
if s == want {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
// A node-scoped seat's work is shared (novox/hq ADR 0190): its holder on any machine subscribes the
|
||||||
|
// seat's one work subject, with no node in it, so holders on several machines read one queue. The
|
||||||
|
// node token belongs to a seat's tools, which are asked of one machine (design 33 §4), not to its work.
|
||||||
|
func TestANodeSeatsWorkSubjectCarriesNoNode(t *testing.T) {
|
||||||
|
seat := Seat{Name: "node-build-agent", Scope: "node", Accepts: []string{"build"}, Serves: []string{"status"}}
|
||||||
|
perms, err := PermissionsFor(Principal{Kind: KindModule, Node: "anchor", Module: "build-agent", Holds: []Seat{seat}})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
has(t, perms.Subscribe, "mesh.seat.node-build-agent.accept.build")
|
||||||
|
hasNot(t, perms.Subscribe, "mesh.seat.node-build-agent.accept.build.anchor")
|
||||||
|
// And its tools still carry the machine.
|
||||||
|
has(t, perms.Subscribe, "mesh.seat.node-build-agent.tool.status.anchor")
|
||||||
|
// The controller asks the role, not a machine.
|
||||||
|
controller, err := PermissionsFor(Principal{Kind: KindController})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
has(t, controller.Publish, "mesh.seat.node-build-agent.accept.>")
|
||||||
|
}
|
||||||
|
|||||||
@@ -217,7 +217,7 @@ var ControllerFollows = []string{
|
|||||||
// A build's outcome, which is the build-machine role's own event now (ADR 0121) rather than a
|
// A build's outcome, which is the build-machine role's own event now (ADR 0121) rather than a
|
||||||
// message on the control branch. Same three audiences, one publish: whoever asked, this, and the
|
// message on the control branch. Same three audiences, one publish: whoever asked, this, and the
|
||||||
// catalogue.
|
// catalogue.
|
||||||
seatEventSubject("mesh-build-machine", "built"),
|
seatEventSubject("node-build-agent", "built"),
|
||||||
// The forge's merges: what moved a source, so the mesh builds what that source produces
|
// The forge's merges: what moved a source, so the mesh builds what that source produces
|
||||||
// without anybody telling it (novox/hq 04-ISSUES/131). Appended, because the index is a name.
|
// without anybody telling it (novox/hq 04-ISSUES/131). Appended, because the index is a name.
|
||||||
moduleEventSubject("gitea", "pull.merged"),
|
moduleEventSubject("gitea", "pull.merged"),
|
||||||
|
|||||||
+4
-4
@@ -24,8 +24,8 @@ accounts {
|
|||||||
jetstream: enabled
|
jetstream: enabled
|
||||||
users = [
|
users = [
|
||||||
{ user: "controller", password: "$2a$11$cccccccccccccccccccccc", permissions: {
|
{ user: "controller", password: "$2a$11$cccccccccccccccccccccc", permissions: {
|
||||||
publish: { allow: ["$JS.ACK.CONTROL.controller.>", "$JS.ACK.EVENTS.controller.>", "$JS.API.>", "_INBOX.enrol.>", "mesh.assignment.>", "mesh.control.>", "mesh.mod.*.tool.>", "mesh.node.>", "mesh.seat.mesh-build-machine.accept.>", "mesh.seat.mesh-controller.event.applied", "mesh.seat.mesh-controller.event.built-before", "mesh.seat.mesh-controller.event.refused"] }
|
publish: { allow: ["$JS.ACK.CONTROL.controller.>", "$JS.ACK.EVENTS.controller.>", "$JS.API.>", "_INBOX.enrol.>", "mesh.assignment.>", "mesh.control.>", "mesh.mod.*.tool.>", "mesh.node.>", "mesh.seat.mesh-controller.event.applied", "mesh.seat.mesh-controller.event.built-before", "mesh.seat.mesh-controller.event.refused", "mesh.seat.node-build-agent.accept.>"] }
|
||||||
subscribe: { allow: ["$JS.API.>", "_DELIVER.controller", "_DELIVER.controller.>", "_INBOX.controller.>", "mesh.control.>", "mesh.mod.gitea.event.pull.merged", "mesh.mod.mesh-catalog.event.catching-up", "mesh.mod.mesh-catalog.event.upgraded", "mesh.seat.mesh-build-machine.event.built", "mesh.seat.mesh-controller.tool.>"] }
|
subscribe: { allow: ["$JS.API.>", "_DELIVER.controller", "_DELIVER.controller.>", "_INBOX.controller.>", "mesh.control.>", "mesh.mod.gitea.event.pull.merged", "mesh.mod.mesh-catalog.event.catching-up", "mesh.mod.mesh-catalog.event.upgraded", "mesh.seat.mesh-controller.tool.>", "mesh.seat.node-build-agent.event.built"] }
|
||||||
allow_responses: { max: 1, ttl: "1m" }
|
allow_responses: { max: 1, ttl: "1m" }
|
||||||
} }
|
} }
|
||||||
{ user: "enrol.one", password: "$2a$11$eeeeeeeeeeeeeeeeeeeeee", permissions: {
|
{ user: "enrol.one", password: "$2a$11$eeeeeeeeeeeeeeeeeeeeee", permissions: {
|
||||||
@@ -37,8 +37,8 @@ accounts {
|
|||||||
subscribe: { allow: ["_DELIVER.one", "_DELIVER.one.>", "_INBOX.node.one.>", "mesh.node.one.declare"] }
|
subscribe: { allow: ["_DELIVER.one", "_DELIVER.one.>", "_INBOX.node.one.>", "mesh.node.one.declare"] }
|
||||||
} }
|
} }
|
||||||
{ user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: {
|
{ user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: {
|
||||||
publish: { allow: ["$JS.ACK.EVENTS.one_telegram.>", "$JS.ACK.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker.>", "$JS.API.CONSUMER.INFO.EVENTS.one_telegram", "$JS.API.CONSUMER.INFO.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker", "$JS.API.CONSUMER.MSG.NEXT.EVENTS.one_telegram", "$JS.API.DIRECT.GET.ASSIGNMENTS.mesh.assignment.one.telegram", "mesh.seat.telegram-sender.event.delivered", "mesh.seat.telegram-sender.event.failed"] }
|
publish: { allow: ["$JS.ACK.EVENTS.one_telegram.>", "$JS.ACK.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker.>", "$JS.API.CONSUMER.INFO.EVENTS.one_telegram", "$JS.API.CONSUMER.INFO.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker", "$JS.API.CONSUMER.MSG.NEXT.EVENTS.one_telegram", "$JS.API.CONSUMER.MSG.NEXT.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker", "$JS.API.DIRECT.GET.ASSIGNMENTS.mesh.assignment.one.telegram", "mesh.seat.telegram-sender.event.delivered", "mesh.seat.telegram-sender.event.failed"] }
|
||||||
subscribe: { allow: ["_DELIVER.SEAT_TELEGRAM_SENDER_worker", "_DELIVER.SEAT_TELEGRAM_SENDER_worker.>", "_INBOX.one.telegram.>", "mesh.assignment.one.telegram", "mesh.mod.telegram.tool.>", "mesh.seat.telegram-sender.accept.send"] }
|
subscribe: { allow: ["_INBOX.one.telegram.>", "mesh.assignment.one.telegram", "mesh.mod.telegram.tool.>", "mesh.seat.telegram-sender.accept.send"] }
|
||||||
allow_responses: { max: 1, ttl: "1m" }
|
allow_responses: { max: 1, ttl: "1m" }
|
||||||
} }
|
} }
|
||||||
{ user: "two.audit", password: "$2a$11$aaaaaaaaaaaaaaaaaaaaaa", permissions: {
|
{ user: "two.audit", password: "$2a$11$aaaaaaaaaaaaaaaaaaaaaa", permissions: {
|
||||||
|
|||||||
@@ -62,13 +62,33 @@ func Users(r Records) ([]Principal, error) {
|
|||||||
|
|
||||||
for _, node := range sortedCopy(r.Nodes) {
|
for _, node := range sortedCopy(r.Nodes) {
|
||||||
out = append(out, Principal{Kind: KindNode, Node: node})
|
out = append(out, Principal{Kind: KindNode, Node: node})
|
||||||
|
// **Where the runtime is assigned, the machine gets one runtime principal in place of the
|
||||||
|
// runtime module's own** (novox/hq ADR 0175, to-be 38). It carries every module on the
|
||||||
|
// node: its serving grants are the union of theirs. Every other module keeps its own
|
||||||
|
// principal — a module still serving tools from its own container holds its own
|
||||||
|
// credential until it moves, and the two serve side by side in the meantime.
|
||||||
|
runtimeHere := false
|
||||||
for _, d := range r.Assigned[node] {
|
for _, d := range r.Assigned[node] {
|
||||||
|
if d.Module == RuntimeModule {
|
||||||
|
runtimeHere = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
for _, d := range r.Assigned[node] {
|
||||||
|
if runtimeHere && d.Module == RuntimeModule {
|
||||||
|
continue
|
||||||
|
}
|
||||||
out = append(out, Principal{
|
out = append(out, Principal{
|
||||||
Kind: KindModule, Node: node, Module: d.Module,
|
Kind: KindModule, Node: node, Module: d.Module,
|
||||||
Emits: d.Emits, Consumes: d.Consumes, Serves: d.Serves,
|
Emits: d.Emits, Consumes: d.Consumes, Serves: d.Serves,
|
||||||
Holds: d.Holds, Uses: d.Uses, Watches: d.Watches, Invokes: d.Invokes,
|
Holds: d.Holds, Uses: d.Uses, Watches: d.Watches, Invokes: d.Invokes,
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
if runtimeHere {
|
||||||
|
out = append(out, Principal{
|
||||||
|
Kind: KindNodeTools, Node: node, Module: RuntimeModule,
|
||||||
|
Carries: append([]Declared(nil), r.Assigned[node]...),
|
||||||
|
})
|
||||||
|
}
|
||||||
}
|
}
|
||||||
for _, node := range sortedCopy(r.Enrolling) {
|
for _, node := range sortedCopy(r.Enrolling) {
|
||||||
out = append(out, Principal{Kind: KindEnrolment, Node: node})
|
out = append(out, Principal{Kind: KindEnrolment, Node: node})
|
||||||
|
|||||||
@@ -245,3 +245,54 @@ func TestAUserListIsComposedBeforeAnythingMovesOntoTheBus(t *testing.T) {
|
|||||||
t.Errorf("the composed list does not contain the machine running the bus")
|
t.Errorf("the composed list does not contain the machine running the bus")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Where the runtime module is assigned, the machine gets one runtime principal in place of the
|
||||||
|
// runtime module's own (novox/hq ADR 0175, to-be 38). Every other module keeps its own: a module
|
||||||
|
// still serving tools from its own container holds its own credential until it moves.
|
||||||
|
func TestTheRuntimeModuleBecomesTheMachinesRuntimePrincipal(t *testing.T) {
|
||||||
|
r := someRecords()
|
||||||
|
r.Assigned["one"] = append(r.Assigned["one"], Declared{Module: RuntimeModule})
|
||||||
|
users, err := Users(r)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
var runtime *Principal
|
||||||
|
for i := range users {
|
||||||
|
p := &users[i]
|
||||||
|
if p.Node == "one" && p.Module == RuntimeModule {
|
||||||
|
if p.Kind == KindModule {
|
||||||
|
t.Fatalf("%s on one was composed as an ordinary module beside the runtime", RuntimeModule)
|
||||||
|
}
|
||||||
|
runtime = p
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if runtime == nil || runtime.Kind != KindNodeTools {
|
||||||
|
t.Fatalf("one runs %s and got no runtime principal: %v", RuntimeModule, namesOf(t, r))
|
||||||
|
}
|
||||||
|
if runtime.Username() != "one."+RuntimeModule {
|
||||||
|
t.Errorf("the runtime is named %q; `module issue` names it as the module it stands for", runtime.Username())
|
||||||
|
}
|
||||||
|
carried := map[string]bool{}
|
||||||
|
for _, d := range runtime.Carries {
|
||||||
|
carried[d.Module] = true
|
||||||
|
}
|
||||||
|
if !carried["telegram"] || !carried[RuntimeModule] {
|
||||||
|
t.Errorf("the runtime carries %v; it carries every module on its node", carried)
|
||||||
|
}
|
||||||
|
// And the other node, where the runtime is not assigned, is exactly as before.
|
||||||
|
for _, p := range users {
|
||||||
|
if p.Node == "two" && p.Kind == KindNodeTools {
|
||||||
|
t.Fatal("two runs no runtime and was given a runtime principal")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// A module serving its own tools beside the runtime keeps its own principal.
|
||||||
|
found := false
|
||||||
|
for _, p := range users {
|
||||||
|
if p.Kind == KindModule && p.Node == "one" && p.Module == "telegram" {
|
||||||
|
found = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !found {
|
||||||
|
t.Error("telegram lost its own principal when the runtime arrived on its node")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -968,6 +968,26 @@ func compile(ctx context.Context, run Runner, tree string, chain Toolchain,
|
|||||||
if _, err := run(ctx, tree, "docker", invocation...); err != nil {
|
if _, err := run(ctx, tree, "docker", invocation...); err != nil {
|
||||||
return "", err
|
return "", err
|
||||||
}
|
}
|
||||||
|
if chain.Dependencies != "" {
|
||||||
|
// **What the bundle runs with, from the image it was compiled in** (Toolchain.Dependencies).
|
||||||
|
// A second run in the same image rather than a shell wrapped around the compiler: the
|
||||||
|
// compile line stays a plain command a reader can run by hand, and the copy is one more
|
||||||
|
// plain command beside it. Refused by name when the image carries no such directory — an
|
||||||
|
// older toolchain image — because a bundle packed without its dependencies starts nowhere
|
||||||
|
// and says so three layers away from here.
|
||||||
|
copying := []string{
|
||||||
|
"run", "--rm",
|
||||||
|
"--volume", tree + ":" + within,
|
||||||
|
"--workdir", within,
|
||||||
|
base,
|
||||||
|
"sh", "-c",
|
||||||
|
`test -d "$1" || { echo "the toolchain image carries no $1: it predates the mesh shipping a bundle's dependencies, rebuild $2 first" >&2; exit 1; }; cp -a "$1/." "$3/"`,
|
||||||
|
"dependencies", chain.Dependencies, chain.Base, out,
|
||||||
|
}
|
||||||
|
if _, err := run(ctx, tree, "docker", copying...); err != nil {
|
||||||
|
return "", fmt.Errorf("copying the %s dependencies a bundle runs with: %w", chain.Language, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
return filepath.Join(tree, out), nil
|
return filepath.Join(tree, out), nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -82,6 +82,41 @@ func TestABundleIsCompiledAndPackedWithNoDockerfile(t *testing.T) {
|
|||||||
if !strings.HasPrefix(digest, "sha256:") {
|
if !strings.HasPrefix(digest, "sha256:") {
|
||||||
t.Fatalf("the bundle was not pinned: %v", got.Manifest.Resources[0])
|
t.Fatalf("the bundle was not pinned: %v", got.Manifest.Resources[0])
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// **And what it runs with, from the image it was compiled in** (novox/hq to-be 38 WP3). A
|
||||||
|
// second run in the same toolchain image copies the toolchain's runtime directory — the
|
||||||
|
// `"type": "module"` package.json and the pruned node_modules — into the output's root, and
|
||||||
|
// refuses by name when the image carries none rather than packing a bundle that starts nowhere.
|
||||||
|
var copied string
|
||||||
|
for _, line := range r.ran {
|
||||||
|
if strings.HasPrefix(line, "docker run") && strings.Contains(line, "/app/runtime") {
|
||||||
|
copied = line
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if copied == "" {
|
||||||
|
t.Fatalf("the bundle's dependencies were not copied in after the compile:\n%s", strings.Join(r.ran, "\n"))
|
||||||
|
}
|
||||||
|
if !strings.Contains(copied, "mesh-tools/build@sha256:") || !strings.Contains(copied, "predates") ||
|
||||||
|
!strings.Contains(copied, Out("code")) {
|
||||||
|
t.Fatalf("the copy does not run in the same toolchain, refuse an older image by name, or land in the artifact's output: %s", copied)
|
||||||
|
}
|
||||||
|
if strings.Index(strings.Join(r.ran, "\n"), "--outDir") > strings.Index(strings.Join(r.ran, "\n"), "/app/runtime") {
|
||||||
|
t.Fatal("the dependencies were copied before the compile wrote its output")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A language whose bundle carries its own dependencies copies nothing in: a Go binary is static.
|
||||||
|
func TestOnlyALanguageWithARuntimeDirectoryCopiesDependenciesIn(t *testing.T) {
|
||||||
|
ts, _ := ToolchainFor("typescript")
|
||||||
|
if ts.Dependencies != "/app/runtime" {
|
||||||
|
t.Fatalf("typescript bundles run with %q", ts.Dependencies)
|
||||||
|
}
|
||||||
|
for _, language := range []string{"go", "python"} {
|
||||||
|
chain, _ := ToolchainFor(language)
|
||||||
|
if chain.Dependencies != "" {
|
||||||
|
t.Fatalf("%s copies %q into every bundle, and its bundles carry their own", language, chain.Dependencies)
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// **Refused before anything is built, naming what to build first.** A base the mesh has not built
|
// **Refused before anything is built, naming what to build first.** A base the mesh has not built
|
||||||
@@ -145,9 +180,13 @@ func TestTwoBundlesInOneModuleArePackedSeparately(t *testing.T) {
|
|||||||
t.Fatalf("a module with two bundles did not build: %v", err)
|
t.Fatalf("a module with two bundles did not build: %v", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Compiled into two different places.
|
// Compiled into two different places. Only the compile lines: the copy of each bundle's
|
||||||
|
// dependencies names the same directory again, deliberately.
|
||||||
var outputs []string
|
var outputs []string
|
||||||
for _, line := range r.ran {
|
for _, line := range r.ran {
|
||||||
|
if !strings.Contains(line, "--outDir") {
|
||||||
|
continue
|
||||||
|
}
|
||||||
for _, part := range strings.Fields(line) {
|
for _, part := range strings.Fields(line) {
|
||||||
if strings.HasPrefix(part, ".mesh-build/") {
|
if strings.HasPrefix(part, ".mesh-build/") {
|
||||||
outputs = append(outputs, part)
|
outputs = append(outputs, part)
|
||||||
|
|||||||
@@ -57,6 +57,23 @@ type Toolchain struct {
|
|||||||
// carrying its debug info. The mistake was believing a comment rather than reading the file it
|
// carrying its debug info. The mistake was believing a comment rather than reading the file it
|
||||||
// produced (novox/hq 04-ISSUES/161).
|
// produced (novox/hq 04-ISSUES/161).
|
||||||
LinkerFlags []string
|
LinkerFlags []string
|
||||||
|
// Dependencies is a directory inside the toolchain image whose contents a bundle in this
|
||||||
|
// language runs with, copied whole into the compiled output's root after the compile.
|
||||||
|
//
|
||||||
|
// **A bundle that compiles is not yet a bundle that runs.** The compiler resolves `import
|
||||||
|
// "nats"` from the toolchain image's own node_modules and the pack takes only what the compiler
|
||||||
|
// wrote, so what a machine unpacked could not find a single dependency — and no TypeScript bundle
|
||||||
|
// had ever run live to show it (novox/hq to-be 38 WP3). For TypeScript the directory holds a
|
||||||
|
// `package.json` saying `"type": "module"` — Node reads a bare `.js` as CommonJS otherwise, so a
|
||||||
|
// bundle with its dependencies and without that line still fails to start — and the pruned,
|
||||||
|
// production-only node_modules the runtime itself ships with: the SDK's and the runtime's
|
||||||
|
// dependencies, and nothing module-specific yet (novox/hq ADR 0188 §5: a skeleton; a module's
|
||||||
|
// own npm dependencies are a later step). Empty for a language whose bundle carries its own —
|
||||||
|
// a Go binary is static, a Python bundle is installed with its dependencies.
|
||||||
|
//
|
||||||
|
// A toolchain image without the directory fails the build by name rather than packing a bundle
|
||||||
|
// that starts nowhere: the image predates this and must be rebuilt first.
|
||||||
|
Dependencies string
|
||||||
// SystemStamp is the variable this language's linker fills with the artifact's declared system,
|
// SystemStamp is the variable this language's linker fills with the artifact's declared system,
|
||||||
// for a language whose binaries are pinned to one at link time (novox/hq ADR 0005).
|
// for a language whose binaries are pinned to one at link time (novox/hq ADR 0005).
|
||||||
//
|
//
|
||||||
@@ -107,14 +124,21 @@ var toolchains = []Toolchain{
|
|||||||
// symlinks to a launcher that requires its library relatively — and the base image's own
|
// symlinks to a launcher that requires its library relatively — and the base image's own
|
||||||
// assembly resolves them away, leaving a launcher whose relative require points nowhere.
|
// assembly resolves them away, leaving a launcher whose relative require points nowhere.
|
||||||
// Every module's hand-written Dockerfile had to know this. Now none of them does.
|
// Every module's hand-written Dockerfile had to know this. Now none of them does.
|
||||||
|
// **Rooted at the module, so an entrypoint lands where it is named.** Without a root the
|
||||||
|
// compiler takes the common directory of the files it is given: a module compiling only
|
||||||
|
// `tools/index.ts` had its output at `index.js`, and the entrypoint it declared —
|
||||||
|
// `tools/index.js`, "named as it will be found" — named a file the bundle did not
|
||||||
|
// contain. The runtime that loads bundles by their declared entrypoints (novox/hq ADR
|
||||||
|
// 0175) is what made this visible.
|
||||||
Compile: []string{
|
Compile: []string{
|
||||||
"node", "/app/node_modules/typescript/bin/tsc",
|
"node", "/app/node_modules/typescript/bin/tsc",
|
||||||
"--module", "NodeNext", "--moduleResolution", "NodeNext",
|
"--module", "NodeNext", "--moduleResolution", "NodeNext",
|
||||||
"--target", "ES2022",
|
"--target", "ES2022", "--rootDir", ".",
|
||||||
},
|
},
|
||||||
OutputFlag: "--outDir",
|
OutputFlag: "--outDir",
|
||||||
Unit: UnitSources,
|
Unit: UnitSources,
|
||||||
SourceExt: ".ts",
|
SourceExt: ".ts",
|
||||||
|
Dependencies: "/app/runtime",
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
Language: "go",
|
Language: "go",
|
||||||
|
|||||||
@@ -67,6 +67,31 @@ func (m Manifest) Resolve(built []Built) (Manifest, error) {
|
|||||||
out := m
|
out := m
|
||||||
out.Build = nil
|
out.Build = nil
|
||||||
out.Resources = nil
|
out.Resources = nil
|
||||||
|
// What the build compiled, kept on the resolved manifest (novox/hq ADR 0175): a tools bundle is
|
||||||
|
// named by no resource of the module's own — the node's runtime loads it — so this is the only
|
||||||
|
// place the mesh would otherwise not have it. In artifact order, so two resolutions of one
|
||||||
|
// build compare equal.
|
||||||
|
out.Bundles = nil
|
||||||
|
if m.Build != nil {
|
||||||
|
for _, a := range m.Build.Artifacts {
|
||||||
|
if a.Kind != ArtifactBundle {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
made := by[a.Name]
|
||||||
|
// What the runtime loads: what the artifact said, else every entrypoint of a module
|
||||||
|
// that declares tools, else nothing (the field's own rule; see Artifact.Loads).
|
||||||
|
loads := append([]string(nil), a.Loads...)
|
||||||
|
if a.Loads == nil && len(m.Tools) > 0 {
|
||||||
|
loads = append([]string(nil), a.Entrypoints...)
|
||||||
|
}
|
||||||
|
out.Bundles = append(out.Bundles, Bundle{
|
||||||
|
Name: a.Name, Source: made.Reference, Digest: made.Digest,
|
||||||
|
Language: a.Language, Entrypoints: append([]string(nil), a.Entrypoints...),
|
||||||
|
Loads: loads,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
sort.Slice(out.Bundles, func(i, j int) bool { return out.Bundles[i].Name < out.Bundles[j].Name })
|
||||||
|
}
|
||||||
for _, r := range m.Resources {
|
for _, r := range m.Resources {
|
||||||
named, _ := r["artifact"].(string)
|
named, _ := r["artifact"].(string)
|
||||||
if named == "" {
|
if named == "" {
|
||||||
@@ -191,6 +216,20 @@ func (b *Build) problems(module string) []string {
|
|||||||
"%s: %q is a bundle and says no language, so nothing can choose a compiler "+
|
"%s: %q is a bundle and says no language, so nothing can choose a compiler "+
|
||||||
"for it", module, a.Name))
|
"for it", module, a.Name))
|
||||||
}
|
}
|
||||||
|
// What the runtime loads is among what was compiled (ADR 0175): a name here that is
|
||||||
|
// not an entrypoint is a file the bundle does not contain, and the runtime would
|
||||||
|
// fail to import it on every machine rather than here.
|
||||||
|
for _, load := range a.Loads {
|
||||||
|
found := false
|
||||||
|
for _, e := range a.Entrypoints {
|
||||||
|
found = found || e == load
|
||||||
|
}
|
||||||
|
if !found {
|
||||||
|
problems = append(problems, fmt.Sprintf(
|
||||||
|
"%s: %q says the runtime loads %q, which is not among its entrypoints — "+
|
||||||
|
"what is loaded is compiled, so it is named there too", module, a.Name, load))
|
||||||
|
}
|
||||||
|
}
|
||||||
// **A system, for a language that compiles to a binary** (novox/hq ADR 0142). A binary
|
// **A system, for a language that compiles to a binary** (novox/hq ADR 0142). A binary
|
||||||
// is pinned to one operating system at link time so a host refuses to touch a machine
|
// is pinned to one operating system at link time so a host refuses to touch a machine
|
||||||
// it was not built for (novox/hq ADR 0005); an artifact that says nothing would be
|
// it was not built for (novox/hq ADR 0005); an artifact that says nothing would be
|
||||||
|
|||||||
@@ -241,15 +241,40 @@ func (r Resolution) Declaration(with Rendering) ([]map[string]any, error) {
|
|||||||
// Owner is kept beside the resources because a resource id cannot be split back into its module:
|
// Owner is kept beside the resources because a resource id cannot be split back into its module:
|
||||||
// a module's name may itself contain a dot. What the mesh adds of its own — an opening, the guard —
|
// a module's name may itself contain a dot. What the mesh adds of its own — an opening, the guard —
|
||||||
// has no owner.
|
// has no owner.
|
||||||
|
//
|
||||||
|
// Received is what each module on the machine is given for each requirement it receives — the same
|
||||||
|
// contributions its received file is written from, kept beside it so the mesh can also issue them
|
||||||
|
// on the bus in the module's membership (novox/hq ADR 0167). By module, then requirement.
|
||||||
type Composed struct {
|
type Composed struct {
|
||||||
Resources []map[string]any
|
Resources []map[string]any
|
||||||
Owner map[string]string
|
Owner map[string]string
|
||||||
|
Received map[string]map[string][]Contribution
|
||||||
|
// LeftOut is every module of this machine's set that was left out of its declaration, and
|
||||||
|
// why (novox/hq ADR 0163, rule 6): a setting stored for it that its definition can no longer
|
||||||
|
// compose. Its held things are kept and its containers untouched — the machine is told so —
|
||||||
|
// and it is told everything else.
|
||||||
|
LeftOut map[string]string
|
||||||
|
}
|
||||||
|
|
||||||
|
// LeftOut is which of this machine's modules a declaration composed with these settings leaves
|
||||||
|
// out, and why (novox/hq ADR 0163, rule 6): each whose stored settings its definition can no longer
|
||||||
|
// compose. Empty when every module composes. The same judgement SetSettings makes before storing.
|
||||||
|
func (r Resolution) LeftOut(settings SettingsBy, adopted bool) map[string]string {
|
||||||
|
out := map[string]string{}
|
||||||
|
for _, m := range r.Modules {
|
||||||
|
if err := JudgeSettings(m, settings[m.Module], adopted); err != nil {
|
||||||
|
out[m.Module] = err.Error()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return out
|
||||||
}
|
}
|
||||||
|
|
||||||
// Compose is Declaration with the owner of every resource said.
|
// Compose is Declaration with the owner of every resource said.
|
||||||
func (r Resolution) Compose(with Rendering) (Composed, error) {
|
func (r Resolution) Compose(with Rendering) (Composed, error) {
|
||||||
owner := map[string]string{}
|
owner := map[string]string{}
|
||||||
resources, err := r.compose(with, owner)
|
received := map[string]map[string][]Contribution{}
|
||||||
|
leftOut := map[string]string{}
|
||||||
|
resources, err := r.compose(with, owner, received, leftOut)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return Composed{}, err
|
return Composed{}, err
|
||||||
}
|
}
|
||||||
@@ -261,7 +286,7 @@ func (r Resolution) Compose(with Rendering) (Composed, error) {
|
|||||||
"sealed": with.BusMembership, "mode": "0600",
|
"sealed": with.BusMembership, "mode": "0600",
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
return Composed{Resources: resources, Owner: owner}, nil
|
return Composed{Resources: resources, Owner: owner, Received: received, LeftOut: leftOut}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// BusMembershipID names the resource carrying a machine's membership for the new bus, and
|
// BusMembershipID names the resource carrying a machine's membership for the new bus, and
|
||||||
@@ -270,7 +295,26 @@ func BusMembershipID() string { return "bus-membership" }
|
|||||||
|
|
||||||
const BusMembershipPath = "/var/lib/mesh/membership-next.json"
|
const BusMembershipPath = "/var/lib/mesh/membership-next.json"
|
||||||
|
|
||||||
func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[string]any, error) {
|
func (r Resolution) compose(with Rendering, owner map[string]string,
|
||||||
|
received map[string]map[string][]Contribution, leftOut map[string]string) ([]map[string]any, error) {
|
||||||
|
// **A setting is judged where it is stored, and an impossible one costs a module, not a
|
||||||
|
// machine** (novox/hq ADR 0163, rule 6). A definition that moved under a stored setting makes
|
||||||
|
// this module uncomposable; it is left out of the declaration — its held things kept, its
|
||||||
|
// containers untouched, the machine told so by name — and the machine is told everything else.
|
||||||
|
// Before placing, because a placement is a setting too.
|
||||||
|
left := r.LeftOut(with.Settings, with.Adopted)
|
||||||
|
kept := make([]Manifest, 0, len(r.Modules))
|
||||||
|
for _, m := range r.Modules {
|
||||||
|
if why, isLeft := left[m.Module]; isLeft {
|
||||||
|
if leftOut != nil {
|
||||||
|
leftOut[m.Module] = why
|
||||||
|
}
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
kept = append(kept, m)
|
||||||
|
}
|
||||||
|
r.Modules = kept
|
||||||
|
|
||||||
// Every manifest is placed first (novox/hq ADR 0112): the maps naming where its bindings,
|
// Every manifest is placed first (novox/hq ADR 0112): the maps naming where its bindings,
|
||||||
// credentials and contributions land are resolved against this node's directories, so every
|
// credentials and contributions land are resolved against this node's directories, so every
|
||||||
// reader below — the binding files, the sealed secrets, the grant paths a contribution
|
// reader below — the binding files, the sealed secrets, the grant paths a contribution
|
||||||
@@ -464,10 +508,27 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
|||||||
return nil, fmt.Errorf(
|
return nil, fmt.Errorf(
|
||||||
"%s needs a secret called %q and none was made for it", m.Module, name)
|
"%s needs a secret called %q and none was made for it", m.Module, name)
|
||||||
}
|
}
|
||||||
first = append(first, ownedBy(m.SecretsOwner, map[string]any{
|
// The runtime's credential belongs to the account the runtime runs as (novox/hq ADR 0175,
|
||||||
|
// to-be 38 WP3): its process is composed `user: <account>` where the node has one, and a
|
||||||
|
// root-owned 0600 file is one that process cannot read. Composed here rather than said in
|
||||||
|
// the manifest, because a manifest cannot say ${machine:account} safely — a node with no
|
||||||
|
// account has nothing to resolve it to, and then the runtime runs as root and the file
|
||||||
|
// stays root's.
|
||||||
|
owner := m.SecretsOwner
|
||||||
|
if m.Module == RuntimeModule && r.Account != "" {
|
||||||
|
owner = r.Account
|
||||||
|
}
|
||||||
|
first = append(first, ownedBy(owner, map[string]any{
|
||||||
"id": NeedID(name), "type": "file", "path": m.OwnSecrets[name].Path, "sealed": sealed,
|
"id": NeedID(name), "type": "file", "path": m.OwnSecrets[name].Path, "sealed": sealed,
|
||||||
}))
|
}))
|
||||||
}
|
}
|
||||||
|
// This module's tools bundles, where the machine runs the node's tool runtime (novox/hq
|
||||||
|
// ADR 0175, to-be 38 WP2). Mesh-computed like everything above it, and before the module's
|
||||||
|
// own resources for the same reason: the runtime's process names the files inside these
|
||||||
|
// and is restarted when one changes, so they are on the machine before it is.
|
||||||
|
if r.runtimeHere() {
|
||||||
|
first = append(first, bundleArchives(m)...)
|
||||||
|
}
|
||||||
// Operator-owned paths this module is granted use of (novox/hq ADR 0051). Written before
|
// Operator-owned paths this module is granted use of (novox/hq ADR 0051). Written before
|
||||||
// the module's own resources, and so before the container that mounts them: the host must
|
// the module's own resources, and so before the container that mounts them: the host must
|
||||||
// find each present — refusing clearly if the operator has not provided it — before it
|
// find each present — refusing clearly if the operator has not provided it — before it
|
||||||
@@ -596,6 +657,12 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
first = append(first, file)
|
first = append(first, file)
|
||||||
|
if received[m.Module] == nil {
|
||||||
|
received[m.Module] = map[string][]Contribution{}
|
||||||
|
}
|
||||||
|
// Empty rather than absent when nobody contributed, for the reason the file is
|
||||||
|
// written empty: "nothing asked" and "never told" want different responses.
|
||||||
|
received[m.Module][to] = append([]Contribution{}, given[to]...)
|
||||||
}
|
}
|
||||||
if m.Keeps != "" && with.Kept != nil {
|
if m.Keeps != "" && with.Kept != nil {
|
||||||
file, err := keptFile(m.Keeps, with.Kept)
|
file, err := keptFile(m.Keeps, with.Kept)
|
||||||
@@ -693,6 +760,10 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
|||||||
// Which of this module's resources its preparation runs before, if it prepares anything.
|
// Which of this module's resources its preparation runs before, if it prepares anything.
|
||||||
prepareBefore := preparationTarget(m)
|
prepareBefore := preparationTarget(m)
|
||||||
|
|
||||||
|
// Which found networks this machine's setting keeps for each of its containers (novox/hq
|
||||||
|
// ADR 0163, rule 4); judged above, so an invalid one is not here.
|
||||||
|
keptNetworks, _ := KeptNetworks(m, with.Settings[m.Module], with.Adopted)
|
||||||
|
|
||||||
for _, unsettled := range resources {
|
for _, unsettled := range resources {
|
||||||
resource, err := ApplySettings(unsettled, with.Settings[m.Module])
|
resource, err := ApplySettings(unsettled, with.Settings[m.Module])
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -702,6 +773,16 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
|||||||
for k, v := range resource {
|
for k, v := range resource {
|
||||||
copied[k] = v
|
copied[k] = v
|
||||||
}
|
}
|
||||||
|
if networks, keeps := keptNetworks[fmt.Sprint(copied["id"])]; keeps {
|
||||||
|
// The container also joins the found network the setting names, so a neighbour
|
||||||
|
// that resolves it there keeps resolving it. Passed to the host as its own field,
|
||||||
|
// which it joins after the container is made.
|
||||||
|
joins := make([]any, 0, len(networks))
|
||||||
|
for _, n := range networks {
|
||||||
|
joins = append(joins, n)
|
||||||
|
}
|
||||||
|
copied["networks"] = joins
|
||||||
|
}
|
||||||
if err := refuseSecretsInEnvironment(copied, secretFiles, m.Module); err != nil {
|
if err := refuseSecretsInEnvironment(copied, secretFiles, m.Module); err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
@@ -821,6 +902,17 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
|||||||
out = append(out, fact)
|
out = append(out, fact)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
// The node's tool runtime, last (novox/hq ADR 0175, to-be 38 WP2.3): one process loading every
|
||||||
|
// bundle delivered above and holding the credential sealed above, so both exist before it starts
|
||||||
|
// — the order written here is the order the machine applies.
|
||||||
|
if r.runtimeHere() {
|
||||||
|
process, err := r.runtimeProcess(with)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
owner[fmt.Sprint(process["id"])] = RuntimeModule
|
||||||
|
out = append(out, process)
|
||||||
|
}
|
||||||
if with.Adopted {
|
if with.Adopted {
|
||||||
// First, before anything a module declares: what the mesh needs reachable, then its guard.
|
// First, before anything a module declares: what the mesh needs reachable, then its guard.
|
||||||
// The order a machine applies is the order written here.
|
// The order a machine applies is the order written here.
|
||||||
@@ -947,8 +1039,15 @@ func (r Resolution) filtersHere() string {
|
|||||||
// computed for this machine, and each module's per-node exposure. The same answer whether the node
|
// computed for this machine, and each module's per-node exposure. The same answer whether the node
|
||||||
// is adopted or converged — the one loads it as a filter, the other declares it as openings.
|
// is adopted or converged — the one loads it as a filter, the other declares it as openings.
|
||||||
func (r Resolution) Rules(with Rendering) ([]Rule, error) {
|
func (r Resolution) Rules(with Rendering) ([]Rule, error) {
|
||||||
|
// A module whose settings cannot compose is left out of the declaration (novox/hq ADR 0163,
|
||||||
|
// rule 6), and out of the filter with it: nothing of it is declared, so nothing of it is let
|
||||||
|
// through.
|
||||||
|
left := r.LeftOut(with.Settings, with.Adopted)
|
||||||
exposure := map[string]map[int]string{}
|
exposure := map[string]map[int]string{}
|
||||||
for _, m := range r.Modules {
|
for _, m := range r.Modules {
|
||||||
|
if _, isLeft := left[m.Module]; isLeft {
|
||||||
|
continue
|
||||||
|
}
|
||||||
e, err := Exposure(m, with.Settings[m.Module])
|
e, err := Exposure(m, with.Settings[m.Module])
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
|
|||||||
@@ -444,6 +444,18 @@ func AsNftables(rules []Rule, mesh []string, outward bool, foundation []int,
|
|||||||
b.WriteString("\t\t# this machine's own guests reaching outward: not a port opened to anybody\n")
|
b.WriteString("\t\t# this machine's own guests reaching outward: not a port opened to anybody\n")
|
||||||
b.WriteString(fmt.Sprintf("\t\tiifname != { %s } accept\n", inward))
|
b.WriteString(fmt.Sprintf("\t\tiifname != { %s } accept\n", inward))
|
||||||
}
|
}
|
||||||
|
// **The mesh passing through, not arriving.** A machine the mesh routes through — the hub, for
|
||||||
|
// every path between machines that are not co-located (novox/hq ADR 0007) — relays a packet that
|
||||||
|
// came in on the tunnel and leaves on it again, addressed to another machine of the mesh. That is
|
||||||
|
// no port of this machine's: the machine it is for filters it against its own rules. Without
|
||||||
|
// this, the chain below judged a relayed packet by this machine's own published ports, so two
|
||||||
|
// machines behind the hub reached each other only on ports the hub happened to publish for itself
|
||||||
|
// (novox/hq issue 196). In and out on the tunnel both: a packet off the tunnel for this machine's
|
||||||
|
// own containers leaves by a bridge, and still meets the rules below.
|
||||||
|
if tunnel != "" {
|
||||||
|
b.WriteString("\t\t# the mesh passing through to another of its machines, which filters it itself\n")
|
||||||
|
b.WriteString(fmt.Sprintf("\t\tiifname %q oifname %q accept\n", tunnel, tunnel))
|
||||||
|
}
|
||||||
|
|
||||||
if len(rules) > 0 {
|
if len(rules) > 0 {
|
||||||
b.WriteString("\n")
|
b.WriteString("\n")
|
||||||
|
|||||||
@@ -887,3 +887,34 @@ func TestAPublicPortNeedsNoGuestLine(t *testing.T) {
|
|||||||
t.Fatalf("a public port was given a guest line it does not need:\n%s", nft)
|
t.Fatalf("a public port was given a guest line it does not need:\n%s", nft)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// **The hub relays the mesh** (novox/hq ADR 0007, issue 196). Two machines that are not co-located
|
||||||
|
// reach each other through the hub, so the hub forwards a packet that arrives on the tunnel and
|
||||||
|
// leaves on it. The forward chain judged that packet by the hub's own published ports, and two
|
||||||
|
// machines behind the hub reached each other only on the ports the hub happened to publish.
|
||||||
|
//
|
||||||
|
// Measured: from one home machine to another through the hub, 17 of 55 ports answered, and they
|
||||||
|
// were exactly the hub's own; the SYN for the rest never left the hub.
|
||||||
|
func TestTheMeshPassingThroughIsRelayedNotJudgedAsThisMachines(t *testing.T) {
|
||||||
|
nft := AsNftables(nil, []string{"10.42.0.1", "10.42.0.2"}, false, nil, []string{"eth0"}, "mesh0")
|
||||||
|
relay := `iifname "mesh0" oifname "mesh0" accept`
|
||||||
|
if !strings.Contains(chainBody(t, nft, "forward"), relay) {
|
||||||
|
t.Errorf("the forward chain does not relay the mesh through this machine:\n%s", chainBody(t, nft, "forward"))
|
||||||
|
}
|
||||||
|
// Relaying is not receiving: nothing in the input chain opens because of it.
|
||||||
|
if strings.Contains(chainBody(t, nft, "input"), "oifname") {
|
||||||
|
t.Errorf("the input chain names an outgoing interface, which no packet for this machine has:\n%s",
|
||||||
|
chainBody(t, nft, "input"))
|
||||||
|
}
|
||||||
|
// And off the tunnel into this machine's own containers is still judged: the tunnel is not
|
||||||
|
// accepted wholesale, only in and out on it.
|
||||||
|
if strings.Contains(chainBody(t, nft, "forward"), `iifname "mesh0" accept`) {
|
||||||
|
t.Errorf("the forward chain accepts everything off the tunnel:\n%s", chainBody(t, nft, "forward"))
|
||||||
|
}
|
||||||
|
|
||||||
|
// A machine with no tunnel relays nothing, and names no interface it does not have.
|
||||||
|
alone := AsNftables(nil, nil, false, nil, []string{"eth0"}, "")
|
||||||
|
if strings.Contains(alone, "oifname") {
|
||||||
|
t.Errorf("a machine with no tunnel was given a relay rule:\n%s", alone)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -102,8 +102,11 @@ func accountHomeOf(account, home string) string {
|
|||||||
func machineInto(resource map[string]any, facts map[string]string, module string) error {
|
func machineInto(resource map[string]any, facts map[string]string, module string) error {
|
||||||
// Content, and now the path and owner too: a module that writes into a person's home names it
|
// Content, and now the path and owner too: a module that writes into a person's home names it
|
||||||
// with ${machine:account-home} and ${machine:account}, which it cannot know until assigned
|
// with ${machine:account-home} and ${machine:account}, which it cannot know until assigned
|
||||||
// (novox/hq to-be 29), the same reason its content names ${machine:address}.
|
// (novox/hq to-be 29), the same reason its content names ${machine:address}. And the name a
|
||||||
for _, field := range []string{"path", "owner", "content"} {
|
// `user` shape sets the login shell of, and the user a user-scoped unit or a process runs as:
|
||||||
|
// the shell module makes the operator's account its holder's login shell, and the desktop's
|
||||||
|
// watchers run as that account (novox/hq ADR 0176, ADR 0177) — neither can name the person.
|
||||||
|
for _, field := range []string{"path", "owner", "content", "name", "user"} {
|
||||||
s, ok := resource[field].(string)
|
s, ok := resource[field].(string)
|
||||||
if !ok {
|
if !ok {
|
||||||
continue
|
continue
|
||||||
|
|||||||
@@ -572,6 +572,36 @@ type Manifest struct {
|
|||||||
// a module that could ask for it could read every credential on the bus — and the claim on
|
// a module that could ask for it could read every credential on the bus — and the claim on
|
||||||
// `mesh-broker` is what authorises it, checked from this manifest alone.
|
// `mesh-broker` is what authorises it, checked from this manifest alone.
|
||||||
BusUsers string `json:"bus-users,omitempty"`
|
BusUsers string `json:"bus-users,omitempty"`
|
||||||
|
|
||||||
|
// Bundles are this module's compiled bundles as the build produced them: what each is called,
|
||||||
|
// where it is, what it hashes to, what language it is in and which files a tool runtime loads
|
||||||
|
// from it (novox/hq ADR 0175, to-be 38).
|
||||||
|
//
|
||||||
|
// **Derived, never written.** The manifest in a repository says `build.artifacts`; the manifest
|
||||||
|
// the mesh holds says what came out, the way a resource naming an artifact comes to name a
|
||||||
|
// digest. Kept here because a tools bundle is referenced by no resource of the module's own —
|
||||||
|
// the node's runtime loads it, and the runtime is composed by the mesh — so without this the
|
||||||
|
// resolved manifest would carry no trace of the one artifact the runtime needs. A repository
|
||||||
|
// manifest that writes this beside a build is refused: it would be stating the build's output
|
||||||
|
// by hand.
|
||||||
|
Bundles []Bundle `json:"bundles,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// Bundle is one compiled bundle after it exists, as the resolved manifest carries it.
|
||||||
|
type Bundle struct {
|
||||||
|
Name string `json:"name"`
|
||||||
|
// Source is where a machine fetches it, kept without the store's address like every reference
|
||||||
|
// the mesh records (artifacts.go); Digest is what it must hash to.
|
||||||
|
Source string `json:"source"`
|
||||||
|
Digest string `json:"digest"`
|
||||||
|
// Language is what it was compiled from, which is what says how it is run.
|
||||||
|
Language string `json:"language,omitempty"`
|
||||||
|
// Entrypoints are the compiled files it was built around, relative to its root.
|
||||||
|
Entrypoints []string `json:"entrypoints,omitempty"`
|
||||||
|
// Loads are the entrypoints a node's tool runtime imports from it: what the artifact said, or
|
||||||
|
// every entrypoint for a module declaring tools that said nothing. Empty for a bundle that is
|
||||||
|
// run rather than loaded.
|
||||||
|
Loads []string `json:"loads,omitempty"`
|
||||||
}
|
}
|
||||||
|
|
||||||
// Build says how to produce this module's artifacts from its source.
|
// Build says how to produce this module's artifacts from its source.
|
||||||
@@ -708,6 +738,16 @@ type Artifact struct {
|
|||||||
// somebody adds a helper. An empty list is a bundle that is run rather than loaded — a
|
// somebody adds a helper. An empty list is a bundle that is run rather than loaded — a
|
||||||
// provisioner or a step, named by whatever runs it.
|
// provisioner or a step, named by whatever runs it.
|
||||||
Entrypoints []string `json:"entrypoints,omitempty"`
|
Entrypoints []string `json:"entrypoints,omitempty"`
|
||||||
|
|
||||||
|
// Loads are the entrypoints of this bundle the node's tool runtime loads (novox/hq ADR 0175,
|
||||||
|
// to-be 38): the module's tool code, each file registering its tools as it is imported. A
|
||||||
|
// subset of Entrypoints, for a bundle that also carries things that are RUN — a daemon, a
|
||||||
|
// step, a report — and must not have them imported into the runtime.
|
||||||
|
//
|
||||||
|
// Absent means every entrypoint, for a module that declares `tools`: a bundle holding the
|
||||||
|
// module's tools and nothing else is the ordinary case and should not have to say the same
|
||||||
|
// list twice. A module declaring no tools has nothing the runtime loads, whatever it compiles.
|
||||||
|
Loads []string `json:"loads,omitempty"`
|
||||||
}
|
}
|
||||||
|
|
||||||
// Kinds an artifact may be.
|
// Kinds an artifact may be.
|
||||||
@@ -1333,6 +1373,15 @@ func ParseManifest(raw []byte) (Manifest, error) {
|
|||||||
//
|
//
|
||||||
// Refused here because the alternative is a build that never returns, on a mesh new enough
|
// Refused here because the alternative is a build that never returns, on a mesh new enough
|
||||||
// that nobody is watching it yet.
|
// that nobody is watching it yet.
|
||||||
|
if m.Build != nil && len(m.Bundles) > 0 {
|
||||||
|
// The output of a build, written beside the build that produces it (ADR 0175). A resource
|
||||||
|
// naming a digest beside an `artifact` would be the same mistake, and is caught the same way:
|
||||||
|
// what the mesh derives, a repository does not state.
|
||||||
|
problems = append(problems, fmt.Sprintf(
|
||||||
|
"%s writes `bundles` beside its build. The mesh derives that from what the build "+
|
||||||
|
"produced; a manifest states `build.artifacts` and nothing about what came out",
|
||||||
|
m.Module))
|
||||||
|
}
|
||||||
if m.Build != nil && len(m.Build.Artifacts) > 0 {
|
if m.Build != nil && len(m.Build.Artifacts) > 0 {
|
||||||
for _, o := range m.Offers() {
|
for _, o := range m.Offers() {
|
||||||
if o != ArtifactStoreProvision {
|
if o != ArtifactStoreProvision {
|
||||||
@@ -1667,6 +1716,7 @@ func ParseManifest(raw []byte) (Manifest, error) {
|
|||||||
problems = append(problems, m.undeclaredMounts()...)
|
problems = append(problems, m.undeclaredMounts()...)
|
||||||
problems = append(problems, m.unknownDirRefs()...)
|
problems = append(problems, m.unknownDirRefs()...)
|
||||||
problems = append(problems, m.unknownAccessRefs()...)
|
problems = append(problems, m.unknownAccessRefs()...)
|
||||||
|
problems = append(problems, m.jailProblems()...)
|
||||||
|
|
||||||
for i, r := range m.Resources {
|
for i, r := range m.Resources {
|
||||||
id, _ := r["id"].(string)
|
id, _ := r["id"].(string)
|
||||||
@@ -1769,6 +1819,46 @@ func (m Manifest) MachineSide(port int) (at int, mayAssign bool) {
|
|||||||
var facilitiesOf = map[string][]string{
|
var facilitiesOf = map[string][]string{
|
||||||
// Both spellings: /var/run is a link to /run on every machine the mesh runs on.
|
// Both spellings: /var/run is a link to /run on every machine the mesh runs on.
|
||||||
"container-runtime": {"/var/run/docker.sock", "/run/docker.sock"},
|
"container-runtime": {"/var/run/docker.sock", "/run/docker.sock"},
|
||||||
|
// The virtualisation daemon's socket, for the lab (novox/hq ADR 0172): it raises machines there.
|
||||||
|
"virtualisation": {"/var/lib/incus/unix.socket"},
|
||||||
|
}
|
||||||
|
|
||||||
|
// jailProblems is every jail this module declares that the machine's intrusion prevention would
|
||||||
|
// refuse (novox/hq ADR 0179).
|
||||||
|
//
|
||||||
|
// **Because one bad pattern stops every jail, not its own.** fail2ban expands `<HOST>` into a named
|
||||||
|
// capture group, so a pattern naming it twice is a duplicate group name, and the daemon refuses the
|
||||||
|
// whole configuration and exits — the machine keeps no bans at all, for any jail, including the one
|
||||||
|
// watching its ssh. Caught live on the control node the day this was built, where a proxy's pattern
|
||||||
|
// matched two shapes of refusal in one line. A pattern matches one shape; several shapes are several
|
||||||
|
// patterns, one per line, as fail2ban's own filters are written.
|
||||||
|
func (m Manifest) jailProblems() []string {
|
||||||
|
var problems []string
|
||||||
|
seen := map[string]bool{}
|
||||||
|
for _, j := range m.Jails {
|
||||||
|
switch {
|
||||||
|
case strings.TrimSpace(j.Name) == "":
|
||||||
|
problems = append(problems, m.Module+" declares a jail with no name")
|
||||||
|
case seen[j.Name]:
|
||||||
|
problems = append(problems, m.Module+" declares two jails called "+strconv.Quote(j.Name))
|
||||||
|
}
|
||||||
|
seen[j.Name] = true
|
||||||
|
if strings.TrimSpace(j.Failregex) == "" {
|
||||||
|
problems = append(problems, m.Module+"'s jail "+strconv.Quote(j.Name)+" says nothing a failed attempt looks like")
|
||||||
|
}
|
||||||
|
for _, line := range strings.Split(j.Failregex, "\n") {
|
||||||
|
if strings.TrimSpace(line) == "" {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if n := strings.Count(line, "<HOST>"); n > 1 {
|
||||||
|
problems = append(problems, fmt.Sprintf("%s's jail %s names <HOST> %d times in one pattern; "+
|
||||||
|
"fail2ban reads it as one capture group and refuses the whole configuration, so the machine "+
|
||||||
|
"keeps no bans at all — write one pattern per shape, each naming <HOST> once",
|
||||||
|
m.Module, strconv.Quote(j.Name), n))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return problems
|
||||||
}
|
}
|
||||||
|
|
||||||
// undeclaredMounts is every bind-mount source no declaration covers — see the check above.
|
// undeclaredMounts is every bind-mount source no declaration covers — see the check above.
|
||||||
@@ -1810,6 +1900,12 @@ func (m Manifest) undeclaredMounts() []string {
|
|||||||
claim(p)
|
claim(p)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
// The file a filter module's rule set is written to is declared by `filtering.into`: the mesh
|
||||||
|
// writes it, the module loads it, and the module's runtime may read it back to reload the
|
||||||
|
// mesh's own table (novox/hq ADR 0170).
|
||||||
|
if m.Filtering != nil {
|
||||||
|
claim(m.Filtering.Into)
|
||||||
|
}
|
||||||
// Under a declared directory is declared: a module that says where its data lives has said so
|
// Under a declared directory is declared: a module that says where its data lives has said so
|
||||||
// for what it puts inside.
|
// for what it puts inside.
|
||||||
covers := func(path string) bool {
|
covers := func(path string) bool {
|
||||||
|
|||||||
@@ -98,3 +98,13 @@ func TestAMountOfABoundFactIsAccepted(t *testing.T) {
|
|||||||
t.Fatalf("a mount of the file the mesh writes a binding to was refused: %v", err)
|
t.Fatalf("a mount of the file the mesh writes a binding to was refused: %v", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The file a filter module's rule set is written to is declared by `filtering.into` (novox/hq ADR
|
||||||
|
// 0169): the module's runtime mounts it to reload the mesh's own table, and nothing else declares it.
|
||||||
|
func TestAMountOfTheFilterFileIsDeclaredByFilteringInto(t *testing.T) {
|
||||||
|
_, err := ParseManifest([]byte(`{"module":"nftables","filtering":{"into":"/etc/nftables.conf"},` +
|
||||||
|
`"resources":[` + strings.Replace(aContainerMounting, "%s", "/etc/nftables.conf", 1) + `]}`))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("a filter module mounting its own filter file was refused: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -0,0 +1,60 @@
|
|||||||
|
package catalogue
|
||||||
|
|
||||||
|
import (
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// A `user` shape and a user-scoped unit name the operator account the way a home file does
|
||||||
|
// (novox/hq ADR 0176, ADR 0177): with ${machine:account}, resolved when the module is assigned.
|
||||||
|
func TestAUserShapeAndAUserScopedUnitNameTheAccount(t *testing.T) {
|
||||||
|
facts := map[string]string{"account": "ops", "account-home": "/home/ops"}
|
||||||
|
login := map[string]any{"type": "user", "id": "login", "name": "${machine:account}", "shell": "/usr/bin/zsh"}
|
||||||
|
if err := machineInto(login, facts, "zsh"); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if login["name"] != "ops" {
|
||||||
|
t.Fatalf("the user shape did not learn the account: %v", login["name"])
|
||||||
|
}
|
||||||
|
watcher := map[string]any{"type": "service", "id": "watcher", "unit": "i3-reload-watcher.service",
|
||||||
|
"scope": "user", "user": "${machine:account}"}
|
||||||
|
if err := machineInto(watcher, facts, "i3"); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if watcher["user"] != "ops" {
|
||||||
|
t.Fatalf("the user-scoped unit did not learn the account: %v", watcher["user"])
|
||||||
|
}
|
||||||
|
// A machine with no operator account refuses rather than writing the literal.
|
||||||
|
err := machineInto(map[string]any{"type": "user", "id": "login", "name": "${machine:account}"},
|
||||||
|
map[string]string{"address": "10.0.0.1"}, "zsh")
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "${machine:account}") {
|
||||||
|
t.Fatalf("a user shape on a machine with no account was not refused by name: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// The service manager is a seat of the mesh's own with the unit verbs as its contract (novox/hq
|
||||||
|
// ADR 0177): every verb described, with a schema, taking a scope.
|
||||||
|
func TestTheServiceManagerSeatServesTheUnitVerbs(t *testing.T) {
|
||||||
|
seat, ok := SeatNamed("node-service-manager")
|
||||||
|
if !ok {
|
||||||
|
t.Fatal("node-service-manager is not a seat the mesh defines")
|
||||||
|
}
|
||||||
|
if seat.Scope != ScopeNode {
|
||||||
|
t.Fatalf("the service manager is a role each machine has once, and the seat is %s-scoped", seat.Scope)
|
||||||
|
}
|
||||||
|
want := []string{"units", "status", "start", "stop", "restart", "enable", "disable", "journal"}
|
||||||
|
var got []string
|
||||||
|
for _, v := range seat.Serves {
|
||||||
|
got = append(got, v.Name)
|
||||||
|
if v.Description == "" || v.Input == nil {
|
||||||
|
t.Fatalf("%s is promised without a description or a schema", v.Name)
|
||||||
|
}
|
||||||
|
props, _ := v.Input["properties"].(map[string]any)
|
||||||
|
if _, has := props["scope"]; !has {
|
||||||
|
t.Fatalf("%s takes no scope, and a user unit could not be asked for", v.Name)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if strings.Join(got, ",") != strings.Join(want, ",") {
|
||||||
|
t.Fatalf("the seat serves %v, not %v", got, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -75,17 +75,26 @@ func TestAnAssignmentPlacesDirectoriesAndAccesses(t *testing.T) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// An access declared by id and placed by nobody resolves to nowhere, and that is refused with the
|
// An access declared by id and placed by nobody resolves to nowhere, and that is refused with the
|
||||||
// setting to write — not mounted as the literal, not skipped.
|
// setting to write — not mounted as the literal, not skipped. The refusal costs the module its
|
||||||
|
// place in the declaration, not the machine its declaration (novox/hq ADR 0163, rule 6).
|
||||||
func TestAnUnplacedAccessIsRefusedByName(t *testing.T) {
|
func TestAnUnplacedAccessIsRefusedByName(t *testing.T) {
|
||||||
got, err := Resolve(shelf(placeable()), []string{"arr"}, workstation(), World{})
|
got, err := Resolve(shelf(placeable()), []string{"arr"}, workstation(), World{})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
_, err = got.Declaration(placedBy(map[string]any{
|
with := placedBy(map[string]any{
|
||||||
AccessesSetting: map[string]any{"series": "/storage/media/series"},
|
AccessesSetting: map[string]any{"series": "/storage/media/series"},
|
||||||
}))
|
})
|
||||||
if err == nil || !strings.Contains(err.Error(), `"spool"`) || !strings.Contains(err.Error(), AccessesSetting) {
|
composed, err := got.Compose(with)
|
||||||
t.Fatalf("an access nobody placed was not refused by name: %v", err)
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
why := composed.LeftOut["arr"]
|
||||||
|
if why == "" || !strings.Contains(why, `"spool"`) || !strings.Contains(why, AccessesSetting) {
|
||||||
|
t.Fatalf("an access nobody placed was not refused by name: %v", composed.LeftOut)
|
||||||
|
}
|
||||||
|
if _, declared := byID(composed.Resources)["arr.server"]; declared {
|
||||||
|
t.Fatal("the module with the unplaced access was declared anyway")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,66 @@
|
|||||||
|
package catalogue
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"reflect"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// What a provider receives is composed once, and issued twice: as its received file, and in its
|
||||||
|
// membership on the bus (novox/hq ADR 0167). The two are the same list, so a proxy reading the bus
|
||||||
|
// and one reading the file serve the same routes — including the port the machine published, which
|
||||||
|
// is the same-node fix the file already carries.
|
||||||
|
func TestWhatAProviderReceivesIsTheSameOnTheBusAsInItsFile(t *testing.T) {
|
||||||
|
gitea := Manifest{
|
||||||
|
Module: "gitea", Version: "1",
|
||||||
|
Listens: []Listening{{Port: 3000, Protocol: "tcp", From: FromMesh}},
|
||||||
|
Contributes: map[string]map[string]any{"route": {"label": "git", "port": 3000}},
|
||||||
|
Resources: []map[string]any{{
|
||||||
|
"id": "server", "type": "container", "name": "gitea", "ports": []any{"3000"},
|
||||||
|
}},
|
||||||
|
}
|
||||||
|
r, err := Resolve(shelf(gitea, routeProxy(), stepCA()),
|
||||||
|
[]string{"gitea", "route-proxy", "step-ca"}, reachable(), World{})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
composed, err := r.Compose(Rendering{Ports: map[string]map[int]int{"gitea": {3000: 20000}}})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
file := fileNamed(composed.Resources, "route-proxy.received-route")
|
||||||
|
if file == nil {
|
||||||
|
t.Fatal("the proxy was given no routes file")
|
||||||
|
}
|
||||||
|
var written struct {
|
||||||
|
Given []Contribution `json:"given"`
|
||||||
|
}
|
||||||
|
if err := json.Unmarshal([]byte(file["content"].(string)), &written); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
issued, said := composed.Received["route-proxy"]["route"]
|
||||||
|
if !said {
|
||||||
|
t.Fatalf("nothing is issued for the proxy to receive on the bus: %v", composed.Received)
|
||||||
|
}
|
||||||
|
// Compared as JSON, which is what both are once they leave the controller.
|
||||||
|
a, _ := json.Marshal(written.Given)
|
||||||
|
b, _ := json.Marshal(issued)
|
||||||
|
var fromFile, fromBus any
|
||||||
|
_ = json.Unmarshal(a, &fromFile)
|
||||||
|
_ = json.Unmarshal(b, &fromBus)
|
||||||
|
if !reflect.DeepEqual(fromFile, fromBus) {
|
||||||
|
t.Errorf("the bus and the file disagree about the routes:\nfile %s\nbus %s", a, b)
|
||||||
|
}
|
||||||
|
if len(issued) != 1 {
|
||||||
|
t.Fatalf("expected one route on the bus, got %v", issued)
|
||||||
|
}
|
||||||
|
if port, ok := asPort(issued[0].Values["port"]); !ok || port != 20000 {
|
||||||
|
t.Errorf("the bus carries a port nothing listens on: %v", issued[0].Values["port"])
|
||||||
|
}
|
||||||
|
|
||||||
|
// A module that receives nothing is issued nothing to receive.
|
||||||
|
if _, any := composed.Received["gitea"]; any {
|
||||||
|
t.Errorf("a module that receives nothing was issued something: %v", composed.Received["gitea"])
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -48,7 +48,9 @@ func TestTheResolverForwardsToFixedUpstreamsAndNeverReadsResolvConf(t *testing.T
|
|||||||
}
|
}
|
||||||
for _, want := range []string{
|
for _, want := range []string{
|
||||||
"\nno-resolv\n", "\nserver=1.1.1.1\n", "\nserver=8.8.8.8\n",
|
"\nno-resolv\n", "\nserver=1.1.1.1\n", "\nserver=8.8.8.8\n",
|
||||||
"\nlisten-address=127.0.0.1\n", "\nlisten-address=${machine:address}\n", "\nbind-dynamic\n",
|
// Loopback is the mesh-wide setting's default; a machine answering its own LAN adds its
|
||||||
|
// address there (novox/hq issue 198).
|
||||||
|
"\nlisten-address=${setting:listen-addresses}\n", "\nlisten-address=${machine:address}\n", "\nbind-dynamic\n",
|
||||||
"\ndomain-needed\n", "\nbogus-priv\n",
|
"\ndomain-needed\n", "\nbogus-priv\n",
|
||||||
"\nconf-file=" + m.Facts["node-zones"].Path + "\n",
|
"\nconf-file=" + m.Facts["node-zones"].Path + "\n",
|
||||||
} {
|
} {
|
||||||
@@ -113,7 +115,8 @@ func TestTheResolverAndWhatAsksItComposeOnOneMachine(t *testing.T) {
|
|||||||
// issue 111) — the resolver's zones read only the second, and in this scenario the two
|
// issue 111) — the resolver's zones read only the second, and in this scenario the two
|
||||||
// happen to be the same map, since nothing routed is part of it.
|
// happen to be the same map, since nothing routed is part of it.
|
||||||
Names: twoMachines, Machines: twoMachines, Suffix: "internal",
|
Names: twoMachines, Machines: twoMachines, Suffix: "internal",
|
||||||
Needed: map[string]map[string]string{"dnsmasq": {"broker": "sealed"}},
|
Needed: map[string]map[string]string{"dnsmasq": {"broker": "sealed"}},
|
||||||
|
Settings: SettingsBy{"dnsmasq": {{From: "the mesh", Values: map[string]any{"listen-addresses": "127.0.0.1"}}}},
|
||||||
})
|
})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
@@ -207,9 +210,16 @@ func TestTheResolverOnAMachineOffTheNetworkIsRefused(t *testing.T) {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
_, err = got.Declaration(Rendering{Names: twoMachines, Suffix: "internal",
|
// Left out of the declaration and said, rather than composed listening nowhere: a module that
|
||||||
Needed: map[string]map[string]string{"dnsmasq": {"broker": "sealed"}}})
|
// cannot compose on a machine is kept as it is there, with the reason (hq ADR 0163).
|
||||||
if err == nil || !strings.Contains(err.Error(), "${machine:address}") {
|
composed, err := got.Compose(Rendering{Names: twoMachines, Suffix: "internal",
|
||||||
t.Fatalf("a machine off the network was composed a resolver, or refused for another reason: %v", err)
|
Needed: map[string]map[string]string{"dnsmasq": {"broker": "sealed"}},
|
||||||
|
Settings: SettingsBy{"dnsmasq": {{From: "the mesh", Values: map[string]any{"listen-addresses": "127.0.0.1"}}}}})
|
||||||
|
if err == nil && !strings.Contains(composed.LeftOut["dnsmasq"], "${machine:address}") {
|
||||||
|
t.Fatalf("a machine off the network was composed a resolver, or left out for another reason: %v",
|
||||||
|
composed.LeftOut)
|
||||||
|
}
|
||||||
|
if err != nil && !strings.Contains(err.Error(), "${machine:address}") {
|
||||||
|
t.Fatalf("a machine off the network was refused for another reason: %v", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,251 @@
|
|||||||
|
package catalogue
|
||||||
|
|
||||||
|
import (
|
||||||
|
"fmt"
|
||||||
|
"sort"
|
||||||
|
"strings"
|
||||||
|
)
|
||||||
|
|
||||||
|
// The node's tool runtime, as the catalogue knows it (novox/hq ADR 0175, to-be 38).
|
||||||
|
//
|
||||||
|
// **One module is the runtime.** Where it is assigned, one process per machine serves every assigned
|
||||||
|
// module's tools and every held seat's verbs, on the host side, from the bundles each module's build
|
||||||
|
// produced — and no module needs a container to reach the bus with its tools. The name is a constant
|
||||||
|
// rather than a manifest field because a rule turns on it: the composer places the runtime's process
|
||||||
|
// where this module is, and registration refuses the old pattern once this module exists.
|
||||||
|
|
||||||
|
// RuntimeModule is the module that is the node's tool runtime. Mirrored in the broker package,
|
||||||
|
// which composes a principal of its own for it; the agreement test there holds the two to one string.
|
||||||
|
const RuntimeModule = "node-tools"
|
||||||
|
|
||||||
|
// BundleRoot is where a machine keeps the tools bundles the mesh delivers to it: under the mesh's
|
||||||
|
// own directory, beside the daemons the host unpacks there, and never where a package manager also
|
||||||
|
// writes. One directory per module, one per bundle beneath it, at a path that does not move with
|
||||||
|
// the version — so the runtime's process names each entrypoint once and is restarted, not
|
||||||
|
// recomposed, when a bundle changes.
|
||||||
|
const BundleRoot = "/var/lib/mesh/bundles"
|
||||||
|
|
||||||
|
// BundleID names the archive resource that delivers one of a module's bundles; prefixed with the
|
||||||
|
// module like every resource of its own.
|
||||||
|
func BundleID(bundle string) string { return "bundle-" + bundle }
|
||||||
|
|
||||||
|
// BundlePath is where one module's bundle is unpacked on a machine.
|
||||||
|
func BundlePath(module, bundle string) string { return BundleRoot + "/" + module + "/" + bundle }
|
||||||
|
|
||||||
|
// runtimeHere says whether this node's set includes the runtime module, which is what decides
|
||||||
|
// whether anything about tools changes on the machine (to-be 38 WP2): until the runtime is assigned,
|
||||||
|
// a node is sent exactly what it was sent before, bundles included, because a bundle nothing loads
|
||||||
|
// is bytes nobody reads.
|
||||||
|
func (r Resolution) runtimeHere() bool {
|
||||||
|
for _, m := range r.Modules {
|
||||||
|
if m.Module == RuntimeModule {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
// bundleArchives is one archive per tools bundle of a module — a bundle the runtime LOADS something
|
||||||
|
// from — as the host fetches and unpacks any artifact (novox/hq ADR 0175 §3: a module brings its
|
||||||
|
// tools as a bundle, delivered by the host like any artifact, never an image). A bundle it loads
|
||||||
|
// nothing from is run rather than loaded: a daemon, a step, the runtime itself — delivered by the
|
||||||
|
// process that runs it, and not again here.
|
||||||
|
//
|
||||||
|
// The source is the kept reference; the per-resource pass that follows routes it through the
|
||||||
|
// artifact store as this network reaches it now, as it does every image and archive the mesh built.
|
||||||
|
func bundleArchives(m Manifest) []map[string]any {
|
||||||
|
var out []map[string]any
|
||||||
|
for _, b := range m.Bundles {
|
||||||
|
if len(b.Loads) == 0 {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
out = append(out, map[string]any{
|
||||||
|
"id": BundleID(b.Name), "type": "archive",
|
||||||
|
"source": b.Source, "digest": b.Digest,
|
||||||
|
"path": BundlePath(m.Module, b.Name),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
return out
|
||||||
|
}
|
||||||
|
|
||||||
|
// RuntimeProcessID names the one process the mesh composes for a machine's runtime; prefixed with
|
||||||
|
// the runtime module like a resource of its own, because that module is what the host sees it as.
|
||||||
|
func RuntimeProcessID() string { return "runtime" }
|
||||||
|
|
||||||
|
// RuntimeToolModules is the variable the runtime reads the modules it serves from: one
|
||||||
|
// `<module>=<entrypoint>` per file it loads, comma-separated — several entries may name one module.
|
||||||
|
// RuntimeBrokerFile is where it reads the node's credential; RuntimeOperatorAccount and
|
||||||
|
// RuntimeOperatorHome are the machine's operator account and home, handed to every tool's
|
||||||
|
// environment (to-be 38 WP1), and absent on a machine with no account.
|
||||||
|
const (
|
||||||
|
RuntimeToolModules = "MESH_TOOL_MODULES"
|
||||||
|
RuntimeBrokerFile = "MESH_BROKER_FILE"
|
||||||
|
RuntimeOperatorAccount = "MESH_OPERATOR_ACCOUNT"
|
||||||
|
RuntimeOperatorHome = "MESH_OPERATOR_HOME"
|
||||||
|
)
|
||||||
|
|
||||||
|
// interpreterFor is how a bundle in a language is run: the program the host's unit starts, with the
|
||||||
|
// bundle's entrypoint after it. The one thing the composer takes from a language, and said here
|
||||||
|
// rather than in a manifest because the runtime's process is the mesh's to compose (to-be 38 WP3).
|
||||||
|
func interpreterFor(language string) (string, error) {
|
||||||
|
switch language {
|
||||||
|
case "typescript":
|
||||||
|
return "node", nil
|
||||||
|
}
|
||||||
|
return "", fmt.Errorf(
|
||||||
|
"%s is written in %q, and the mesh knows no interpreter to run a %q bundle with",
|
||||||
|
RuntimeModule, language, language)
|
||||||
|
}
|
||||||
|
|
||||||
|
// runtimeProcess is the one process a machine runs the node's tool runtime as (novox/hq ADR 0175,
|
||||||
|
// to-be 38 WP2.3): the runtime module's own bundle, run by its language's interpreter, told which
|
||||||
|
// modules it serves and from which files, where its credential is, and who the machine's operator
|
||||||
|
// is — and restarted when any bundle it loads or the credential it holds changes.
|
||||||
|
//
|
||||||
|
// Composed from the placed manifests, so the credential's path is where this node puts it. The
|
||||||
|
// runtime runs as the operator's account when the machine has one, which is what lets a tool that
|
||||||
|
// needs root escalate as the operator would (ADR 0175 §4); on a machine with no account it runs as
|
||||||
|
// root, and the two operator words are not set.
|
||||||
|
func (r Resolution) runtimeProcess(with Rendering) (map[string]any, error) {
|
||||||
|
var runtime *Manifest
|
||||||
|
for i := range r.Modules {
|
||||||
|
if r.Modules[i].Module == RuntimeModule {
|
||||||
|
runtime = &r.Modules[i]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if runtime == nil {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
if len(runtime.Bundles) != 1 {
|
||||||
|
return nil, fmt.Errorf(
|
||||||
|
"%s is assigned to %s and its build produced %d bundle(s); the runtime is one bundle "+
|
||||||
|
"the mesh runs, so the module declares exactly one (novox/hq to-be 38)",
|
||||||
|
RuntimeModule, r.Node, len(runtime.Bundles))
|
||||||
|
}
|
||||||
|
bundle := runtime.Bundles[0]
|
||||||
|
if len(bundle.Entrypoints) != 1 {
|
||||||
|
return nil, fmt.Errorf(
|
||||||
|
"%s's bundle %q names %d entrypoint(s); the runtime is run from one, so the module "+
|
||||||
|
"declares exactly one (novox/hq to-be 38)", RuntimeModule, bundle.Name, len(bundle.Entrypoints))
|
||||||
|
}
|
||||||
|
interpreter, err := interpreterFor(bundle.Language)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
credential, declared := runtime.OwnSecrets["broker"]
|
||||||
|
if !declared {
|
||||||
|
return nil, fmt.Errorf(
|
||||||
|
"%s declares no own secret named broker, and the node's credential is delivered there: "+
|
||||||
|
"a module that speaks on the bus declares \"own-secrets\": {\"broker\": <path>}",
|
||||||
|
RuntimeModule)
|
||||||
|
}
|
||||||
|
|
||||||
|
// What it serves, and from which files: every module on this machine that composes here, in
|
||||||
|
// name order, each bundle it loads from in the order the manifest gave. A module left out of
|
||||||
|
// the declaration — a filter on an adopted machine — is left out of this too, or the runtime
|
||||||
|
// would be told to load files that were never delivered.
|
||||||
|
var served []string
|
||||||
|
var restartOn []string
|
||||||
|
for _, m := range r.Modules {
|
||||||
|
if with.Adopted && m.Filtering != nil {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
for _, b := range m.Bundles {
|
||||||
|
if len(b.Loads) == 0 {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
for _, load := range b.Loads {
|
||||||
|
served = append(served, m.Module+"="+BundlePath(m.Module, b.Name)+"/"+load)
|
||||||
|
}
|
||||||
|
restartOn = append(restartOn, m.Module+"."+BundleID(b.Name))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
sort.Strings(served)
|
||||||
|
restartOn = append(restartOn, RuntimeModule+"."+NeedID("broker"))
|
||||||
|
sort.Strings(restartOn)
|
||||||
|
|
||||||
|
env := map[string]string{
|
||||||
|
RuntimeToolModules: strings.Join(served, ","),
|
||||||
|
RuntimeBrokerFile: credential.Path,
|
||||||
|
}
|
||||||
|
process := map[string]any{
|
||||||
|
"id": RuntimeModule + "." + RuntimeProcessID(), "type": "process", "name": RuntimeModule,
|
||||||
|
"source": bundle.Source, "digest": bundle.Digest,
|
||||||
|
"run": []any{interpreter, bundle.Entrypoints[0]},
|
||||||
|
"env": env,
|
||||||
|
"restart-on": toAny(restartOn),
|
||||||
|
}
|
||||||
|
if r.Account != "" {
|
||||||
|
env[RuntimeOperatorAccount] = r.Account
|
||||||
|
env[RuntimeOperatorHome] = accountHomeOf(r.Account, r.AccountHome)
|
||||||
|
process["user"] = r.Account
|
||||||
|
}
|
||||||
|
// Routed through the artifact store as this network reaches it now, like everything the mesh
|
||||||
|
// built; refused with the same words when there is no store to route through.
|
||||||
|
if err := artifactsInto(process, RuntimeModule, with); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return process, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func toAny(in []string) []any {
|
||||||
|
out := make([]any, 0, len(in))
|
||||||
|
for _, s := range in {
|
||||||
|
out = append(out, s)
|
||||||
|
}
|
||||||
|
return out
|
||||||
|
}
|
||||||
|
|
||||||
|
// RuntimeImageModule and RuntimeImageArtifact name the image every per-module tool container was
|
||||||
|
// built on: the tool runtime's own runtime image. With the runtime a module of its own, that image
|
||||||
|
// stays the way a module's SERVICE may be built and stops being the way tools reach a node (ADR 0175).
|
||||||
|
const (
|
||||||
|
RuntimeImageModule = "mesh-tools"
|
||||||
|
RuntimeImageArtifact = "runtime"
|
||||||
|
)
|
||||||
|
|
||||||
|
// ToolContainerOnTheRuntime says why a manifest is the pattern ADR 0175 retires — a module whose tools
|
||||||
|
// are served from a container built on the tool runtime's image — or nothing when it is not. Judged
|
||||||
|
// from the manifest's own `build.on` when it is a repository manifest, and from what its build stood
|
||||||
|
// on when it is a built one, because a resolved manifest carries no build. The gate itself is
|
||||||
|
// registration's (to-be 38 WP2.4): once the runtime module is in the catalogue, this is refused.
|
||||||
|
//
|
||||||
|
// Three things must hold, and each alone is fine: declaring tools (a bundle does that); a container
|
||||||
|
// (a module's service may well be one); building on the runtime's image (a service written against
|
||||||
|
// the SDK may). All three is a container whose purpose is tools, which the runtime now serves.
|
||||||
|
func ToolContainerOnTheRuntime(m Manifest, against []string) string {
|
||||||
|
if len(m.Tools) == 0 {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
container := false
|
||||||
|
for _, r := range m.Resources {
|
||||||
|
if fmt.Sprint(r["type"]) == "container" {
|
||||||
|
container = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !container {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
onTheRuntime := false
|
||||||
|
if m.Build != nil {
|
||||||
|
for _, on := range m.Build.On {
|
||||||
|
if on.Module == RuntimeImageModule && on.Artifact == RuntimeImageArtifact {
|
||||||
|
onTheRuntime = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
for _, ref := range against {
|
||||||
|
path, kept := InArtifactStore(Recorded(ref))
|
||||||
|
if kept && strings.HasPrefix(path, RuntimeImageModule+"/"+RuntimeImageArtifact+"@") {
|
||||||
|
onTheRuntime = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !onTheRuntime {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
return fmt.Sprintf(
|
||||||
|
"%s declares tools and a container built on %s's %s image — a container whose purpose is "+
|
||||||
|
"serving tools. The node's tool runtime (%s) serves every module's tools from its bundle "+
|
||||||
|
"now (novox/hq ADR 0175, to-be 38); declare the tools as a bundle and drop the container",
|
||||||
|
m.Module, RuntimeImageModule, RuntimeImageArtifact, RuntimeModule)
|
||||||
|
}
|
||||||
@@ -0,0 +1,88 @@
|
|||||||
|
package catalogue
|
||||||
|
|
||||||
|
import (
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// The packet-filter manifest as it was the day the runtime was decided (novox/hq ADR 0175): tools,
|
||||||
|
// served from a container built on the tool runtime's image, with NET_ADMIN so the container could
|
||||||
|
// reach the filter. The exact pattern to-be 38 WP4 moves it off, and the one the gate refuses.
|
||||||
|
const thePacketFilterAsItWas = `{
|
||||||
|
"module": "nftables",
|
||||||
|
"version": "1",
|
||||||
|
"capabilities": ["firewall", "container-runtime"],
|
||||||
|
"claims": [{"name": "node-packet-filter", "scope": "node", "serves": ["rules", "reload", "remove"]}],
|
||||||
|
"filtering": {"into": "/etc/nftables.conf"},
|
||||||
|
"resources": [
|
||||||
|
{"id": "mesh-state", "type": "directory", "mode": "0700", "place": "mesh"},
|
||||||
|
{"id": "package", "type": "package", "package": "nftables"},
|
||||||
|
{"id": "unit", "type": "file", "path": "/etc/systemd/system/mesh-filter.service",
|
||||||
|
"content": "[Unit]\nDescription=The mesh's packet filter\n[Service]\nType=oneshot\nExecStart=nft -f /etc/nftables.conf\n", "mode": "0644"},
|
||||||
|
{"id": "load", "type": "service", "unit": "mesh-filter.service", "state": "running", "boot": "enabled",
|
||||||
|
"restart-on": ["unit"], "reload-on": ["filtering"]},
|
||||||
|
{"id": "runtime", "type": "container", "name": "mesh-nftables", "network": "host",
|
||||||
|
"capabilities": ["NET_ADMIN"],
|
||||||
|
"volumes": ["${dir:mesh-state}/broker:/run/secrets/broker:ro", "/etc/nftables.conf:/etc/nftables.conf:ro"],
|
||||||
|
"env": {"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_FILTER_FILE": "/etc/nftables.conf"},
|
||||||
|
"artifact": "runtime"}
|
||||||
|
],
|
||||||
|
"tools": ["firewall_rules"],
|
||||||
|
"own-secrets": {"broker": "${dir:mesh-state}/broker"},
|
||||||
|
"build": {
|
||||||
|
"on": [
|
||||||
|
{"arg": "BUILD_BASE", "module": "mesh-tools", "artifact": "build"},
|
||||||
|
{"arg": "RUNTIME_BASE", "module": "mesh-tools", "artifact": "runtime"}
|
||||||
|
],
|
||||||
|
"artifacts": [{"name": "runtime", "kind": "image", "from": "Dockerfile"}]
|
||||||
|
}
|
||||||
|
}`
|
||||||
|
|
||||||
|
func TestAToolContainerOnTheRuntimeImageIsNamedForWhatItIs(t *testing.T) {
|
||||||
|
m, err := ParseManifest([]byte(thePacketFilterAsItWas))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
// From the repository: the manifest says what it builds on.
|
||||||
|
why := ToolContainerOnTheRuntime(m, nil)
|
||||||
|
if why == "" {
|
||||||
|
t.Fatal("the packet filter's tool container was not recognised from its build")
|
||||||
|
}
|
||||||
|
for _, word := range []string{"nftables", "mesh-tools", "runtime", "ADR 0175", "bundle"} {
|
||||||
|
if !strings.Contains(why, word) {
|
||||||
|
t.Errorf("the refusal does not say %q: %s", word, why)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Built: the manifest carries no build, and what it stood on says the same.
|
||||||
|
built, err := m.Resolve([]Built{{Name: "runtime", Kind: ArtifactImage,
|
||||||
|
Reference: ArtifactStoreScheme + "nftables/runtime@" + digest}})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
stoodOn := []string{"anchor.internal:5100/mesh-tools/build@" + digest, "anchor.internal:5100/mesh-tools/runtime@" + digest}
|
||||||
|
if ToolContainerOnTheRuntime(built, stoodOn) == "" {
|
||||||
|
t.Error("the packet filter's tool container was not recognised from what its build stood on")
|
||||||
|
}
|
||||||
|
if ToolContainerOnTheRuntime(built, nil) != "" {
|
||||||
|
t.Error("a built manifest with no record of its base was judged to be on the runtime")
|
||||||
|
}
|
||||||
|
|
||||||
|
// Each of the three alone is an ordinary module.
|
||||||
|
bundle := m
|
||||||
|
bundle.Resources = m.Resources[:len(m.Resources)-1]
|
||||||
|
if ToolContainerOnTheRuntime(bundle, nil) != "" {
|
||||||
|
t.Error("a module with tools and no container is the pattern the runtime serves, and was refused")
|
||||||
|
}
|
||||||
|
service := m
|
||||||
|
service.Tools = nil
|
||||||
|
if ToolContainerOnTheRuntime(service, nil) != "" {
|
||||||
|
t.Error("a service built against the SDK, declaring no tools, was refused")
|
||||||
|
}
|
||||||
|
elsewhere := m
|
||||||
|
elsewhere.Build = &Build{On: []BuildsOn{{Arg: "NODE_BASE", Image: "node@" + digest}},
|
||||||
|
Artifacts: m.Build.Artifacts}
|
||||||
|
if ToolContainerOnTheRuntime(elsewhere, nil) != "" {
|
||||||
|
t.Error("a tool container on a public base was refused as though it were on the runtime's")
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,212 @@
|
|||||||
|
package catalogue
|
||||||
|
|
||||||
|
import (
|
||||||
|
"fmt"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// The node's tool runtime (novox/hq ADR 0175, to-be 38): where the runtime module is assigned, a
|
||||||
|
// machine is sent every assigned module's tools bundle as an archive, and the runtime's own process
|
||||||
|
// loading them. Where it is not, the machine is sent exactly what it was sent before.
|
||||||
|
|
||||||
|
var bundleDigest = "sha256:" + strings.Repeat("b", 64)
|
||||||
|
|
||||||
|
// aToolsModule is a module whose tools come as a compiled bundle and nothing else — the shape every
|
||||||
|
// module takes once its tool container goes (to-be 38 WP4).
|
||||||
|
func aToolsModule(t *testing.T, name string, entrypoints ...string) Manifest {
|
||||||
|
t.Helper()
|
||||||
|
m := Manifest{Module: name, Version: "1", Tools: []string{"status"},
|
||||||
|
Build: &Build{Artifacts: []Artifact{
|
||||||
|
{Name: "tools", Kind: ArtifactBundle, Language: "typescript", Entrypoints: entrypoints},
|
||||||
|
}}}
|
||||||
|
resolved, err := m.Resolve([]Built{{Name: "tools", Kind: ArtifactBundle,
|
||||||
|
Reference: ArtifactStoreScheme + name + "/tools/blobs/" + bundleDigest, Digest: bundleDigest}})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
return resolved
|
||||||
|
}
|
||||||
|
|
||||||
|
// theRuntime is the runtime module as the catalogue holds it: its own bundle, run rather than
|
||||||
|
// loaded, and its broker secret to receive the node's credential in.
|
||||||
|
func theRuntime(t *testing.T) Manifest {
|
||||||
|
t.Helper()
|
||||||
|
m := Manifest{Module: RuntimeModule, Version: "1",
|
||||||
|
OwnSecrets: OwnSecrets{"broker": {Path: "/var/lib/mesh/" + RuntimeModule + "/broker"}},
|
||||||
|
Build: &Build{Artifacts: []Artifact{{Name: "runtime", Kind: ArtifactBundle, Language: "typescript",
|
||||||
|
Entrypoints: []string{"src/main.js"}}}}}
|
||||||
|
resolved, err := m.Resolve([]Built{{Name: "runtime", Kind: ArtifactBundle,
|
||||||
|
Reference: ArtifactStoreScheme + RuntimeModule + "/runtime/blobs/" + bundleDigest, Digest: bundleDigest}})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
return resolved
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestABuildsBundlesAreCarriedOnTheResolvedManifest(t *testing.T) {
|
||||||
|
m := aToolsModule(t, "nftables", "tools/index.js")
|
||||||
|
if len(m.Bundles) != 1 {
|
||||||
|
t.Fatalf("the resolved manifest carries %d bundle(s), not the one the build made", len(m.Bundles))
|
||||||
|
}
|
||||||
|
b := m.Bundles[0]
|
||||||
|
if b.Name != "tools" || b.Digest != bundleDigest || b.Language != "typescript" ||
|
||||||
|
b.Source != ArtifactStoreScheme+"nftables/tools/blobs/"+bundleDigest ||
|
||||||
|
len(b.Entrypoints) != 1 || b.Entrypoints[0] != "tools/index.js" {
|
||||||
|
t.Errorf("the bundle is carried as %+v", b)
|
||||||
|
}
|
||||||
|
// A repository manifest may not write what the build derives.
|
||||||
|
raw := `{"module":"x","version":"1","build":{"artifacts":[{"name":"t","kind":"bundle","language":"typescript"}]},` +
|
||||||
|
`"bundles":[{"name":"t","source":"s","digest":"` + bundleDigest + `"}]}`
|
||||||
|
if _, err := ParseManifest([]byte(raw)); err == nil || !strings.Contains(err.Error(), "bundles") {
|
||||||
|
t.Errorf("a manifest stating its build's output by hand was accepted: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestEveryToolsBundleIsDeliveredWhereTheRuntimeRuns(t *testing.T) {
|
||||||
|
store := Rendering{ArtifactStore: "anchor.internal:5101",
|
||||||
|
Needed: map[string]map[string]string{RuntimeModule: {"broker": "sealed-credential"}}}
|
||||||
|
nftables := aToolsModule(t, "nftables", "tools/index.js")
|
||||||
|
zsh := aToolsModule(t, "zsh", "tools/index.js", "tools/more.js")
|
||||||
|
|
||||||
|
t.Run("with the runtime, one archive per tools bundle", func(t *testing.T) {
|
||||||
|
r := Resolution{Node: "anchor", Modules: []Manifest{nftables, zsh, theRuntime(t)}}
|
||||||
|
out, err := r.Declaration(store)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
archive := fileNamed(out, "nftables."+BundleID("tools"))
|
||||||
|
if archive == nil {
|
||||||
|
t.Fatalf("nftables' tools bundle was not delivered: %v", ids(out))
|
||||||
|
}
|
||||||
|
if archive["type"] != "archive" || archive["digest"] != bundleDigest ||
|
||||||
|
archive["path"] != BundleRoot+"/nftables/tools" {
|
||||||
|
t.Errorf("delivered as %v", archive)
|
||||||
|
}
|
||||||
|
if archive["source"] != "http://anchor.internal:5101/v2/nftables/tools/blobs/"+bundleDigest {
|
||||||
|
t.Errorf("fetched from %v, not through the store as this network reaches it", archive["source"])
|
||||||
|
}
|
||||||
|
if fileNamed(out, "zsh."+BundleID("tools")) == nil {
|
||||||
|
t.Errorf("zsh's tools bundle was not delivered: %v", ids(out))
|
||||||
|
}
|
||||||
|
// The runtime's own bundle is run, not loaded: its process delivers it, not an archive.
|
||||||
|
if fileNamed(out, RuntimeModule+"."+BundleID("runtime")) != nil {
|
||||||
|
t.Error("the runtime's own bundle was delivered as an archive beside its process")
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
|
t.Run("without the runtime, nothing changes", func(t *testing.T) {
|
||||||
|
r := Resolution{Node: "anchor", Modules: []Manifest{nftables, zsh}}
|
||||||
|
out, err := r.Declaration(store)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
for _, id := range ids(out) {
|
||||||
|
if strings.Contains(id, BundleID("")) {
|
||||||
|
t.Errorf("%s was delivered to a machine running no runtime to load it", id)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
func ids(out []map[string]any) []string {
|
||||||
|
var names []string
|
||||||
|
for _, r := range out {
|
||||||
|
names = append(names, r["id"].(string))
|
||||||
|
}
|
||||||
|
return names
|
||||||
|
}
|
||||||
|
|
||||||
|
// One process per machine runs the runtime from its own bundle, told what it serves and from where,
|
||||||
|
// where its credential is, and who the operator is — restarted when any of that changes.
|
||||||
|
func TestTheMachineRunsOneRuntimeLoadingEveryDeliveredBundle(t *testing.T) {
|
||||||
|
with := Rendering{ArtifactStore: "anchor.internal:5101",
|
||||||
|
Needed: map[string]map[string]string{RuntimeModule: {"broker": "sealed-credential"}}}
|
||||||
|
nftables := aToolsModule(t, "nftables", "tools/index.js")
|
||||||
|
// A bundle carrying a daemon beside its tools says which files the runtime loads.
|
||||||
|
showcase := Manifest{Module: "showcase", Version: "1", Tools: []string{"greet"},
|
||||||
|
Build: &Build{Artifacts: []Artifact{{Name: "code", Kind: ArtifactBundle, Language: "typescript",
|
||||||
|
Entrypoints: []string{"daemon/index.js", "tools/index.js"}, Loads: []string{"tools/index.js"}}}}}
|
||||||
|
showcase, err := showcase.Resolve([]Built{{Name: "code", Kind: ArtifactBundle,
|
||||||
|
Reference: ArtifactStoreScheme + "showcase/code/blobs/" + bundleDigest, Digest: bundleDigest}})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
r := Resolution{Node: "anchor", Account: "ops", Modules: []Manifest{nftables, showcase, theRuntime(t)}}
|
||||||
|
out, err := r.Declaration(with)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
process := fileNamed(out, RuntimeModule+"."+RuntimeProcessID())
|
||||||
|
if process == nil {
|
||||||
|
t.Fatalf("no runtime process was composed: %v", ids(out))
|
||||||
|
}
|
||||||
|
if process["type"] != "process" || process["name"] != RuntimeModule || process["digest"] != bundleDigest ||
|
||||||
|
process["source"] != "http://anchor.internal:5101/v2/"+RuntimeModule+"/runtime/blobs/"+bundleDigest {
|
||||||
|
t.Errorf("the runtime's process is %v", process)
|
||||||
|
}
|
||||||
|
if fmt.Sprint(process["run"]) != "[node src/main.js]" {
|
||||||
|
t.Errorf("the runtime is run as %v; its bundle's one entrypoint, by its language's interpreter", process["run"])
|
||||||
|
}
|
||||||
|
env := process["env"].(map[string]string)
|
||||||
|
if env[RuntimeToolModules] != "nftables="+BundleRoot+"/nftables/tools/tools/index.js,"+
|
||||||
|
"showcase="+BundleRoot+"/showcase/code/tools/index.js" {
|
||||||
|
t.Errorf("the runtime is told to serve %q: every loaded file, by module, and nothing a bundle runs", env[RuntimeToolModules])
|
||||||
|
}
|
||||||
|
if env[RuntimeBrokerFile] != "/var/lib/mesh/"+RuntimeModule+"/broker" {
|
||||||
|
t.Errorf("the runtime reads its credential at %q, not where the module's own secret is placed", env[RuntimeBrokerFile])
|
||||||
|
}
|
||||||
|
if env[RuntimeOperatorAccount] != "ops" || env[RuntimeOperatorHome] != "/home/ops" || process["user"] != "ops" {
|
||||||
|
t.Errorf("the operator is not handed to the runtime: %v as %v", env, process["user"])
|
||||||
|
}
|
||||||
|
// The credential the process reads belongs to the account it runs as, or it could not read it
|
||||||
|
// (to-be 38 WP3); other modules' secrets are left as their manifests say.
|
||||||
|
if credential := fileNamed(out, RuntimeModule+"."+NeedID("broker")); credential == nil || credential["owner"] != "ops" {
|
||||||
|
t.Errorf("the runtime's credential is not the account's to read: %v", credential)
|
||||||
|
}
|
||||||
|
restarts := fmt.Sprint(process["restart-on"])
|
||||||
|
for _, want := range []string{"nftables." + BundleID("tools"), "showcase." + BundleID("code"), RuntimeModule + "." + NeedID("broker")} {
|
||||||
|
if !strings.Contains(restarts, want) {
|
||||||
|
t.Errorf("the runtime is not restarted when %s changes: %s", want, restarts)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// After every bundle and the credential, so both exist before it starts.
|
||||||
|
names := ids(out)
|
||||||
|
if names[len(names)-1] != RuntimeModule+"."+RuntimeProcessID() {
|
||||||
|
t.Errorf("the runtime's process is not last: %v", names)
|
||||||
|
}
|
||||||
|
|
||||||
|
t.Run("a machine with no account runs it as root without the operator words", func(t *testing.T) {
|
||||||
|
out, err := Resolution{Node: "anchor", Modules: []Manifest{nftables, theRuntime(t)}}.Declaration(with)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
process := fileNamed(out, RuntimeModule+"."+RuntimeProcessID())
|
||||||
|
env := process["env"].(map[string]string)
|
||||||
|
if _, set := env[RuntimeOperatorAccount]; set {
|
||||||
|
t.Error("an operator account was named on a machine that has none")
|
||||||
|
}
|
||||||
|
if _, set := process["user"]; set {
|
||||||
|
t.Error("a user was set on a machine with no account")
|
||||||
|
}
|
||||||
|
if credential := fileNamed(out, RuntimeModule+"."+NeedID("broker")); credential == nil || credential["owner"] != nil {
|
||||||
|
t.Errorf("the runtime's credential was given an owner on a machine with no account: %v", credential)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
|
t.Run("a runtime module built wrong is refused by name", func(t *testing.T) {
|
||||||
|
two := Manifest{Module: RuntimeModule, Version: "1", OwnSecrets: OwnSecrets{"broker": {Path: "/b"}},
|
||||||
|
Build: &Build{Artifacts: []Artifact{{Name: "runtime", Kind: ArtifactBundle, Language: "typescript",
|
||||||
|
Entrypoints: []string{"a.js", "b.js"}}}}}
|
||||||
|
resolved, err := two.Resolve([]Built{{Name: "runtime", Kind: ArtifactBundle,
|
||||||
|
Reference: ArtifactStoreScheme + "x/runtime/blobs/" + bundleDigest, Digest: bundleDigest}})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
_, err = Resolution{Node: "anchor", Modules: []Manifest{resolved}}.Declaration(with)
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "entrypoint") {
|
||||||
|
t.Errorf("a runtime bundle with two entrypoints was composed: %v", err)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
@@ -96,11 +96,60 @@ var defaultSeats = []Seat{
|
|||||||
// A build says what it does as it does it (novox/hq ADR 0157): `started` when work is taken,
|
// A build says what it does as it does it (novox/hq ADR 0157): `started` when work is taken,
|
||||||
// `log.<build id>` for every line, `built` for the outcome. The log's tail token is the build's
|
// `log.<build id>` for every line, `built` for the outcome. The log's tail token is the build's
|
||||||
// id, so a reader follows one build by subject alone.
|
// id, so a reader follows one build by subject alone.
|
||||||
|
// **Node-scoped, and every holder takes from one queue** (novox/hq ADR 0190): a build is asked of
|
||||||
|
// the role, and whichever machine holding the seat is idle pulls it. One holder per machine is
|
||||||
|
// what the scope says; sharing the work is what a seat's queue has always done.
|
||||||
|
{Name: "node-build-agent", Scope: ScopeNode,
|
||||||
|
Accepts: []string{"build"}, Emits: []string{"started", "built", "log.*"}, Decision: "novox/hq ADR 0190"},
|
||||||
|
// **Retired by ADR 0190, kept while a manifest still claims it.** The one build machine's seat.
|
||||||
|
// A claim to a seat the mesh no longer defines is refused, and the module holding this one is
|
||||||
|
// assigned on a live machine until build-agent replaces it — removing the row first would make
|
||||||
|
// that machine unresolvable in the meantime. Deleted once no registered manifest claims it.
|
||||||
{Name: "mesh-build-machine", Scope: ScopeMesh,
|
{Name: "mesh-build-machine", Scope: ScopeMesh,
|
||||||
Accepts: []string{"build"}, Emits: []string{"started", "built", "log.*"}, Decision: "novox/hq ADR 0121"},
|
Accepts: []string{"build"}, Emits: []string{"started", "built", "log.*"}, Decision: "novox/hq ADR 0190"},
|
||||||
{Name: "node-dns-resolver", Scope: ScopeNode, Decision: "novox/hq ADR 0121"},
|
{Name: "node-dns-resolver", Scope: ScopeNode, Decision: "novox/hq ADR 0121"},
|
||||||
{Name: "node-intrusion-prevention", Scope: ScopeNode, Decision: "novox/hq ADR 0121"},
|
// The intrusion prevention's verbs (novox/hq ADR 0179): what a person asks a machine's ban list
|
||||||
{Name: "node-packet-filter", Scope: ScopeNode, Decision: "novox/hq ADR 0121"},
|
// whatever keeps it — who is banned and why, ban one address, let one go. Every holder serves all
|
||||||
|
// four; the jails themselves are composed from the modules the machine runs (to-be 31).
|
||||||
|
{Name: "node-intrusion-prevention", Scope: ScopeNode, Decision: "novox/hq ADR 0121",
|
||||||
|
Serves: []Verb{
|
||||||
|
{Name: "status", Description: "Every jail on this machine with how many it is watching and " +
|
||||||
|
"holding now, and the totals since the jail started; one jail's detail when named.",
|
||||||
|
Input: schema(map[string]string{"jail": "one jail (optional)"}, nil)},
|
||||||
|
{Name: "banned", Description: "Every address banned on this machine right now, with the jail " +
|
||||||
|
"that holds it and when the ban ends.",
|
||||||
|
Input: schema(map[string]string{"jail": "one jail (optional)"}, nil)},
|
||||||
|
{Name: "ban", Description: "Ban one address in one jail now, for the jail's ban time — an " +
|
||||||
|
"operator's act on the live ban list, which the mesh never writes itself.",
|
||||||
|
Input: schema(map[string]string{"ip": "the address", "jail": "the jail to hold it"}, []string{"ip", "jail"})},
|
||||||
|
{Name: "unban", Description: "Let one address go, from one jail or from every jail when none is named.",
|
||||||
|
Input: schema(map[string]string{"ip": "the address", "jail": "one jail (optional)"}, []string{"ip"})},
|
||||||
|
}},
|
||||||
|
// The packet filter's verbs (novox/hq ADR 0170): what a person asks a machine's filter whatever
|
||||||
|
// filter answers — the rules as enforced, reload the mesh's own, remove one thing the mesh did
|
||||||
|
// not write. Every holder serves all three; what differs by filter is the holder's own tools.
|
||||||
|
{Name: "node-packet-filter", Scope: ScopeNode, Decision: "novox/hq ADR 0121",
|
||||||
|
Serves: []Verb{
|
||||||
|
{Name: "rules", Description: "The packet filter as this machine enforces it now: the nftables " +
|
||||||
|
"ruleset and, where the tool exists, the legacy filter's listings. Narrowed to one table or " +
|
||||||
|
"chain when asked.",
|
||||||
|
Input: schema(map[string]string{"table": "one nftables table, as `family name` (optional)",
|
||||||
|
"chain": "one chain of that table (optional)"}, nil)},
|
||||||
|
{Name: "reload", Description: "Load the mesh's own filter again from the file the mesh writes, " +
|
||||||
|
"and answer with the mesh's table as loaded.",
|
||||||
|
Input: schema(map[string]string{}, nil)},
|
||||||
|
{Name: "remove", Description: "Remove one rule set the mesh did not write, named exactly as the " +
|
||||||
|
"host reports it (novox/hq ADR 0168) — `chain X (iptables-legacy)` or `table ip6 filter, chain " +
|
||||||
|
"DOCKER-USER`. Refuses the mesh's tables, the runtime's own chains, a built-in chain and an " +
|
||||||
|
"active found firewall's chains. An operator's act, by name, never a flush.",
|
||||||
|
Input: schema(map[string]string{"where": "the rule set, as `node show` lists it"}, []string{"where"})},
|
||||||
|
}},
|
||||||
|
// The machine's service manager (novox/hq ADR 0177). The host applies every declared unit,
|
||||||
|
// system or user scope; the holder answers questions and operator acts about them, each verb
|
||||||
|
// taking the unit and an optional scope. The holder runs nothing of its own: its verbs are
|
||||||
|
// served by the node tools runtime (ADR 0175).
|
||||||
|
{Name: "node-service-manager", Scope: ScopeNode, Decision: "novox/hq ADR 0177",
|
||||||
|
Serves: serviceManagerVerbs()},
|
||||||
// Deferred (novox/hq ADR 0121): renaming to mesh-private-network is a scope + server/client
|
// Deferred (novox/hq ADR 0121): renaming to mesh-private-network is a scope + server/client
|
||||||
// model change, not a rename, so it stays until that is built.
|
// model change, not a rename, so it stays until that is built.
|
||||||
{Name: "the-private-network", Scope: ScopeNode, Decision: "novox/hq ADR 0110"},
|
{Name: "the-private-network", Scope: ScopeNode, Decision: "novox/hq ADR 0110"},
|
||||||
@@ -374,3 +423,36 @@ func SeatsWithAProtocol() []Seat {
|
|||||||
}
|
}
|
||||||
return out
|
return out
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// serviceManagerVerbs is the contract every holder of node-service-manager serves (novox/hq ADR
|
||||||
|
// 0177): the units on the machine in both scopes, read and acted on by name. Every verb takes an
|
||||||
|
// optional scope — "system" when absent, "user" for the operator account's own manager — so a
|
||||||
|
// caller asks for a user unit the way it asks for a system one.
|
||||||
|
func serviceManagerVerbs() []Verb {
|
||||||
|
scoped := func(more map[string]string, required []string) map[string]any {
|
||||||
|
props := map[string]string{"scope": "\"system\" (the default) or \"user\": the operator account's own manager"}
|
||||||
|
for k, v := range more {
|
||||||
|
props[k] = v
|
||||||
|
}
|
||||||
|
return schema(props, required)
|
||||||
|
}
|
||||||
|
unit := map[string]string{"unit": "the unit's name, as the service manager knows it"}
|
||||||
|
return []Verb{
|
||||||
|
{Name: "units", Description: "The units the service manager knows in a scope, each with its load, active and sub state; narrowed to a pattern when asked.",
|
||||||
|
Input: scoped(map[string]string{"pattern": "a glob the unit's name must match (optional)"}, nil)},
|
||||||
|
{Name: "status", Description: "One unit as the service manager sees it now: its states, whether it starts at boot, its main process, and whether the mesh declares it.",
|
||||||
|
Input: scoped(unit, []string{"unit"})},
|
||||||
|
{Name: "start", Description: "Start one unit. For a unit the mesh declares, the answer says the host will restore what its declaration says at the next apply.",
|
||||||
|
Input: scoped(unit, []string{"unit"})},
|
||||||
|
{Name: "stop", Description: "Stop one unit; for a mesh-declared unit the answer says the host will restore its declared state.",
|
||||||
|
Input: scoped(unit, []string{"unit"})},
|
||||||
|
{Name: "restart", Description: "Restart one unit.",
|
||||||
|
Input: scoped(unit, []string{"unit"})},
|
||||||
|
{Name: "enable", Description: "Make one unit start at boot (or at the account's login, in user scope).",
|
||||||
|
Input: scoped(unit, []string{"unit"})},
|
||||||
|
{Name: "disable", Description: "Stop one unit starting at boot (or at login, in user scope).",
|
||||||
|
Input: scoped(unit, []string{"unit"})},
|
||||||
|
{Name: "journal", Description: "The last lines of one unit's journal.",
|
||||||
|
Input: scoped(map[string]string{"unit": unit["unit"], "lines": "how many lines from the end (default 100)"}, []string{"unit"})},
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -44,8 +44,10 @@ func TestTheSeatsAreAClosedSetAndEachNamesItsDecision(t *testing.T) {
|
|||||||
delivered[s.Delivers] = s.Name
|
delivered[s.Delivers] = s.Name
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if len(Seats()) != 15 {
|
// Seventeen since node-build-agent (novox/hq ADR 0190) — sixteen once the retired
|
||||||
t.Errorf("the mesh defines %d seats rather than 14; the set is closed, so a change here is "+
|
// mesh-build-machine row goes, when no registered manifest claims it any more.
|
||||||
|
if len(Seats()) != 17 {
|
||||||
|
t.Errorf("the mesh defines %d seats rather than 17; the set is closed, so a change here is "+
|
||||||
"a decision (novox/hq ADR 0110): %s", len(Seats()), seatNames())
|
"a decision (novox/hq ADR 0110): %s", len(Seats()), seatNames())
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ package catalogue
|
|||||||
import (
|
import (
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"regexp"
|
||||||
"sort"
|
"sort"
|
||||||
"strings"
|
"strings"
|
||||||
)
|
)
|
||||||
@@ -275,6 +276,11 @@ func UnusedSettings(m Manifest, layers []Layer) []string {
|
|||||||
if key == AccessesSetting && len(m.Accesses) > 0 {
|
if key == AccessesSetting && len(m.Accesses) > 0 {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
// `networks` keeps a found network for a taken container on one adopted machine
|
||||||
|
// (novox/hq ADR 0163). Validated in KeptNetworks, so not stray.
|
||||||
|
if key == NetworksSetting {
|
||||||
|
continue
|
||||||
|
}
|
||||||
unused = append(unused, fmt.Sprintf(
|
unused = append(unused, fmt.Sprintf(
|
||||||
"%s sets %q, and %s has no file that merges it, asks for no ${setting:%s}, and "+
|
"%s sets %q, and %s has no file that merges it, asks for no ${setting:%s}, and "+
|
||||||
"declares no %q in what it contributes or serves",
|
"declares no %q in what it contributes or serves",
|
||||||
@@ -298,3 +304,125 @@ func stringsOf(v any) []string {
|
|||||||
}
|
}
|
||||||
return out
|
return out
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// NetworksSetting is the settings key that keeps a found network for a taken container, on one
|
||||||
|
// adopted machine (novox/hq ADR 0163, rule 4):
|
||||||
|
//
|
||||||
|
// {"networks": {"server": ["predecessor_default"]}}
|
||||||
|
//
|
||||||
|
// has the module's container `server` also join `predecessor_default` once taken, so a neighbour
|
||||||
|
// that resolves it by name on that network keeps resolving it. Migration scaffolding in the sense
|
||||||
|
// of ADR 0104: assigned only on an adopted machine, reported while it stands, removed when the
|
||||||
|
// neighbours are taken. Keyed by the container's resource id; the value is the networks it keeps.
|
||||||
|
const NetworksSetting = "networks"
|
||||||
|
|
||||||
|
// KeptNetworks reads which found networks each of a module's containers keeps, by container id.
|
||||||
|
//
|
||||||
|
// Refused from a mesh-wide layer — a found network is a fact about one machine — for an id the
|
||||||
|
// module declares no container under, for a name that is not a network's, and on a machine that
|
||||||
|
// is not adopted: the setting exists so neighbours the mesh has not taken yet keep reaching the
|
||||||
|
// container, and a converged machine has no such neighbours.
|
||||||
|
func KeptNetworks(m Manifest, layers []Layer, adopted bool) (map[string][]string, error) {
|
||||||
|
containers := map[string]bool{}
|
||||||
|
for _, r := range m.Resources {
|
||||||
|
if fmt.Sprint(r["type"]) == "container" {
|
||||||
|
containers[fmt.Sprint(r["id"])] = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
out := map[string][]string{}
|
||||||
|
for _, layer := range layers {
|
||||||
|
raw, ok := layer.Values[NetworksSetting]
|
||||||
|
if !ok {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if layer.From == MeshWideLayer {
|
||||||
|
return nil, fmt.Errorf("%s: %s is given per node — a found network is a fact about one "+
|
||||||
|
"machine; set it with --node", m.Module, NetworksSetting)
|
||||||
|
}
|
||||||
|
if !adopted {
|
||||||
|
return nil, fmt.Errorf("%s: %s keeps a found network for neighbours the mesh has not taken "+
|
||||||
|
"yet, and %s is converged — nothing on it is found; clear the setting", m.Module,
|
||||||
|
NetworksSetting, layer.From)
|
||||||
|
}
|
||||||
|
blocks, ok := raw.(map[string]any)
|
||||||
|
if !ok {
|
||||||
|
return nil, fmt.Errorf("%s: %s is a { container: [network, …] } map, and %q set it to "+
|
||||||
|
"something else", m.Module, NetworksSetting, layer.From)
|
||||||
|
}
|
||||||
|
for id, body := range blocks {
|
||||||
|
if !containers[id] {
|
||||||
|
return nil, fmt.Errorf("%s: %s names the container %q, which it does not declare — "+
|
||||||
|
"the setting reaches nothing; it declares %s", m.Module, NetworksSetting, id,
|
||||||
|
orNothing(sortedKeys(containers)))
|
||||||
|
}
|
||||||
|
names := stringsOf(body)
|
||||||
|
if len(names) == 0 {
|
||||||
|
return nil, fmt.Errorf("%s: %s for %q is a list of network names, and %q set it to %v",
|
||||||
|
m.Module, NetworksSetting, id, layer.From, body)
|
||||||
|
}
|
||||||
|
for _, n := range names {
|
||||||
|
if !networkName.MatchString(n) {
|
||||||
|
return nil, fmt.Errorf("%s: %s for %q names %q, which is not a network name",
|
||||||
|
m.Module, NetworksSetting, id, n)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
sort.Strings(names)
|
||||||
|
out[id] = names
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if len(out) == 0 {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
return out, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// networkName is what a container runtime accepts as a network's name.
|
||||||
|
var networkName = regexp.MustCompile(`^[A-Za-z0-9][A-Za-z0-9_.-]*$`)
|
||||||
|
|
||||||
|
// JudgeSettings composes a module's settings against its definition and refuses the first thing
|
||||||
|
// that cannot work, naming the module, the layer and the key (novox/hq ADR 0163, rule 6).
|
||||||
|
//
|
||||||
|
// **The same judgement where a setting is stored and where a machine is declared.** Stored, a
|
||||||
|
// setting that cannot compose is refused before it is kept; composed later, a definition that has
|
||||||
|
// moved under a stored setting leaves that module out of the machine's declaration rather than
|
||||||
|
// the machine without one. Every reader of settings runs here: a port given, an exposure, a reach,
|
||||||
|
// an endpoint, a placement, an access, a kept network, a mergeable file's keys and a file's
|
||||||
|
// `${setting:…}`. A key that reaches nothing is not here: it cannot break a composition, so it is
|
||||||
|
// refused where it is stored (SetSettings, with UnusedSettings) and said where a plan is read,
|
||||||
|
// and never costs a module its place.
|
||||||
|
func JudgeSettings(m Manifest, layers []Layer, adopted bool) error {
|
||||||
|
// With no layers too: a definition may ask for a setting nobody made — an access placed by
|
||||||
|
// nobody, a file's ${setting:…} nothing sets — and that is the same statement, missing.
|
||||||
|
if _, err := GivenPorts(m, layers); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if _, err := Reaches(m, layers); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if _, err := Endpoints(m, layers); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if _, err := Places(m, layers); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if _, _, err := accessesFor(m, layers); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if _, err := KeptNetworks(m, layers, adopted); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
for _, r := range m.Resources {
|
||||||
|
settled, err := ApplySettings(r, layers)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
copied := map[string]any{}
|
||||||
|
for k, v := range settled {
|
||||||
|
copied[k] = v
|
||||||
|
}
|
||||||
|
if err := settingInto(copied, layers, m.Module); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|||||||
@@ -0,0 +1,127 @@
|
|||||||
|
package catalogue
|
||||||
|
|
||||||
|
import (
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// A setting is judged where it is stored, and an impossible one costs a module, not a machine
|
||||||
|
// (novox/hq ADR 0163, rule 6): the one judgement, used by SetSettings before storing and by
|
||||||
|
// Compose when a definition has moved under a stored setting.
|
||||||
|
func TestASettingThatCannotComposeIsRefusedByNameAndLeavesOnlyItsModuleOut(t *testing.T) {
|
||||||
|
web := Manifest{Module: "hello-web",
|
||||||
|
Listens: []Listening{{Port: 8080, From: FromEverywhere}},
|
||||||
|
Resources: []map[string]any{{"id": "server", "type": "container", "name": "hello-web",
|
||||||
|
"ports": []any{"8080"}}}}
|
||||||
|
for _, c := range []struct {
|
||||||
|
name string
|
||||||
|
layer map[string]any
|
||||||
|
refuse string
|
||||||
|
}{
|
||||||
|
{"a port the module does not publish", map[string]any{PortsSetting: map[string]any{"9999": 10000}},
|
||||||
|
"hello-web gives port 9999 a machine port, and no container of its publishes 9999"},
|
||||||
|
{"a mesh-wide port", map[string]any{PortsSetting: map[string]any{"8080": 10000}},
|
||||||
|
"a port is a fact about one machine"},
|
||||||
|
} {
|
||||||
|
from := "anchor"
|
||||||
|
if c.name == "a mesh-wide port" {
|
||||||
|
from = MeshWideLayer
|
||||||
|
}
|
||||||
|
err := JudgeSettings(web, []Layer{{From: from, Values: c.layer}}, true)
|
||||||
|
if err == nil || !strings.Contains(err.Error(), c.refuse) {
|
||||||
|
t.Errorf("%s: judged %v, want %q", c.name, err, c.refuse)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if err := JudgeSettings(web, []Layer{{From: "anchor", Values: map[string]any{PortsSetting: map[string]any{"8080": 10000}}}}, true); err != nil {
|
||||||
|
t.Fatalf("a port the module publishes was refused: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Composed, a module whose stored setting no longer works is left out by name; the rest of
|
||||||
|
// the machine is declared.
|
||||||
|
r := anAdoptedAnchor()
|
||||||
|
with := anchorRendering(false)
|
||||||
|
with.Settings = SettingsBy{"hello-web": {{From: "anchor", Values: map[string]any{PortsSetting: map[string]any{"9999": 10000}}}}}
|
||||||
|
composed, err := r.Compose(with)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
why, left := composed.LeftOut["hello-web"]
|
||||||
|
if !left || !strings.Contains(why, "no container of its publishes 9999") {
|
||||||
|
t.Fatalf("hello-web is not left out by name: %v", composed.LeftOut)
|
||||||
|
}
|
||||||
|
if len(composed.LeftOut) != 1 {
|
||||||
|
t.Fatalf("more than hello-web is left out: %v", composed.LeftOut)
|
||||||
|
}
|
||||||
|
got := byID(composed.Resources)
|
||||||
|
if _, declared := got["hello-web.server"]; declared {
|
||||||
|
t.Fatal("the left-out module's container is still declared")
|
||||||
|
}
|
||||||
|
if _, declared := got["distribution.store"]; !declared {
|
||||||
|
t.Fatal("the rest of the machine was not declared")
|
||||||
|
}
|
||||||
|
if left := r.LeftOut(with.Settings, false); len(left) != 1 || left["hello-web"] == "" {
|
||||||
|
t.Fatalf("the judgement a plan reads differs from what compose did: %v", left)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A taken container keeps a found network by a per-machine setting (novox/hq ADR 0163, rule 4):
|
||||||
|
// on an adopted machine only, for a container the module declares, and it reaches the container's
|
||||||
|
// declaration as the networks it also joins.
|
||||||
|
func TestAKeptNetworkReachesTheContainerOnAnAdoptedMachineOnly(t *testing.T) {
|
||||||
|
r := anAdoptedAnchor()
|
||||||
|
keep := SettingsBy{"hello-web": {{From: "anchor",
|
||||||
|
Values: map[string]any{NetworksSetting: map[string]any{"server": []any{"predecessor_default"}}}}}}
|
||||||
|
|
||||||
|
with := anchorRendering(true)
|
||||||
|
with.Settings = keep
|
||||||
|
composed, err := r.Compose(with)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if len(composed.LeftOut) != 0 {
|
||||||
|
t.Fatalf("a kept network left a module out: %v", composed.LeftOut)
|
||||||
|
}
|
||||||
|
server := byID(composed.Resources)["hello-web.server"]
|
||||||
|
networks, _ := server["networks"].([]any)
|
||||||
|
if len(networks) != 1 || networks[0] != "predecessor_default" {
|
||||||
|
t.Fatalf("the container does not join the kept network: %v", server)
|
||||||
|
}
|
||||||
|
if _, has := byID(composed.Resources)["distribution.store"]["networks"]; has {
|
||||||
|
t.Fatal("another container joins a network nobody kept for it")
|
||||||
|
}
|
||||||
|
|
||||||
|
// Converged, the setting reaches nothing it was for, and the module is left out saying so.
|
||||||
|
with = anchorRendering(false)
|
||||||
|
with.Settings = keep
|
||||||
|
composed, err = r.Compose(with)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if why := composed.LeftOut["hello-web"]; !strings.Contains(why, "anchor is converged") {
|
||||||
|
t.Fatalf("a kept network on a converged machine: %v", composed.LeftOut)
|
||||||
|
}
|
||||||
|
|
||||||
|
web := r.Modules[4]
|
||||||
|
for _, c := range []struct {
|
||||||
|
name string
|
||||||
|
layer Layer
|
||||||
|
want string
|
||||||
|
}{
|
||||||
|
{"mesh-wide", Layer{From: MeshWideLayer, Values: map[string]any{NetworksSetting: map[string]any{"server": []any{"x"}}}},
|
||||||
|
"a found network is a fact about one machine"},
|
||||||
|
{"an unknown container", Layer{From: "anchor", Values: map[string]any{NetworksSetting: map[string]any{"db": []any{"x"}}}},
|
||||||
|
`names the container "db", which it does not declare`},
|
||||||
|
{"not a list", Layer{From: "anchor", Values: map[string]any{NetworksSetting: map[string]any{"server": "x"}}},
|
||||||
|
"is a list of network names"},
|
||||||
|
{"not a network name", Layer{From: "anchor", Values: map[string]any{NetworksSetting: map[string]any{"server": []any{"a/b"}}}},
|
||||||
|
"which is not a network name"},
|
||||||
|
} {
|
||||||
|
_, err := KeptNetworks(web, []Layer{c.layer}, true)
|
||||||
|
if err == nil || !strings.Contains(err.Error(), c.want) {
|
||||||
|
t.Errorf("%s: %v, want %q", c.name, err, c.want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if kept, err := KeptNetworks(web, nil, false); err != nil || kept != nil {
|
||||||
|
t.Fatalf("no setting: %v %v", kept, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -129,6 +129,29 @@ var ControllerVerbs = []Verb{
|
|||||||
"module": "an own secret: the module",
|
"module": "an own secret: the module",
|
||||||
"secret": "an own secret: its name in the module's definition",
|
"secret": "an own secret: its name in the module's definition",
|
||||||
}, nil)},
|
}, nil)},
|
||||||
|
{Name: "issue", Description: "Give a module on a machine its account on the bus: minted, and sealed to the " +
|
||||||
|
"machine as the module's own secret named broker, read at the next push of that machine. For a module " +
|
||||||
|
"whose definition declares that secret; refused with the reason otherwise. Issued again, it replaces the account.",
|
||||||
|
Input: schema(map[string]string{
|
||||||
|
"node": "the machine that runs the module",
|
||||||
|
"module": "the module's name",
|
||||||
|
}, []string{"node", "module"})},
|
||||||
|
{Name: "settings", Description: "Set what an assignment is configured with: a module's settings for the whole mesh, " +
|
||||||
|
"or for one machine. Replaces that layer whole — what it does not name, it no longer sets — and takes effect " +
|
||||||
|
"at the next push. With clear, removes the layer and the module is back to what its definition says.",
|
||||||
|
Input: schema(map[string]string{
|
||||||
|
"module": "the module's name",
|
||||||
|
"values": "the settings as a JSON object, for set",
|
||||||
|
"node": "one machine; the whole mesh when absent",
|
||||||
|
"clear": "\"true\" to remove the layer instead of setting it",
|
||||||
|
}, []string{"module"})},
|
||||||
|
{Name: "command", Description: "Run one command line of the controller's own, as you would type it at its " +
|
||||||
|
"shell — `node account g14 jochen`, `node show ace`, `module list` — and answer what it printed. The " +
|
||||||
|
"generic verb beside the named ones (novox/hq ADR 0154): everything the binary can do, without a verb " +
|
||||||
|
"per command. Any node may call any tool (ADR 0175), so nothing is held back here.",
|
||||||
|
Input: schema(map[string]string{
|
||||||
|
"command": "the command line, as the controller's binary takes it; quotes group a word with spaces",
|
||||||
|
}, []string{"command"})},
|
||||||
{Name: "build", Description: "Have the build machine build a repository. Answers at once with the build's id: " +
|
{Name: "build", Description: "Have the build machine build a repository. Answers at once with the build's id: " +
|
||||||
"`builds` with that id follows it line by line, and the module is registered when the outcome comes.",
|
"`builds` with that id follows it line by line, and the module is registered when the outcome comes.",
|
||||||
Input: schema(map[string]string{
|
Input: schema(map[string]string{
|
||||||
|
|||||||
@@ -178,6 +178,103 @@ type Stray struct {
|
|||||||
Detail string `json:"detail,omitempty"`
|
Detail string `json:"detail,omitempty"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// A Filter is one place on a machine that refuses traffic, with its owner (novox/hq ADR 0168).
|
||||||
|
type Filter struct {
|
||||||
|
Where string `json:"where"`
|
||||||
|
Owner string `json:"owner"`
|
||||||
|
Refuses string `json:"refuses"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// Owners of a filter, as the host names them (ADR 0168).
|
||||||
|
const (
|
||||||
|
FilterMesh = "mesh"
|
||||||
|
FilterFoundFirewall = "found-firewall"
|
||||||
|
FilterRuntime = "runtime"
|
||||||
|
FilterBan = "ban"
|
||||||
|
FilterOther = "other"
|
||||||
|
)
|
||||||
|
|
||||||
|
// FoundFirewall is the state of a converged machine's found firewall (ADR 0168): in force now or
|
||||||
|
// not, and how it came to be inactive.
|
||||||
|
type FoundFirewall struct {
|
||||||
|
Kind string `json:"kind"`
|
||||||
|
Active bool `json:"active"`
|
||||||
|
RetiredBy string `json:"retired_by,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// Filtering is what a machine last said filters it (ADR 0168).
|
||||||
|
type Filtering struct {
|
||||||
|
Filters []Filter
|
||||||
|
FoundFirewall *FoundFirewall
|
||||||
|
}
|
||||||
|
|
||||||
|
// Alone is whether the machine is filtered by the mesh alone: nothing in its list but the mesh's
|
||||||
|
// own, the runtime's plumbing and bans, and no found firewall in force.
|
||||||
|
func (f Filtering) Alone() bool {
|
||||||
|
for _, x := range f.Filters {
|
||||||
|
if x.Owner == FilterOther || x.Owner == FilterFoundFirewall {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return f.FoundFirewall == nil || !f.FoundFirewall.Active
|
||||||
|
}
|
||||||
|
|
||||||
|
// Others is every filter that is neither the mesh's, the runtime's nor a ban.
|
||||||
|
func (f Filtering) Others() []Filter {
|
||||||
|
var out []Filter
|
||||||
|
for _, x := range f.Filters {
|
||||||
|
if x.Owner == FilterOther || x.Owner == FilterFoundFirewall {
|
||||||
|
out = append(out, x)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return out
|
||||||
|
}
|
||||||
|
|
||||||
|
// RecordFiltering keeps what a machine last said filters it, replacing what was there (ADR 0168).
|
||||||
|
func (i *Inventory) RecordFiltering(ctx context.Context, nodeID string, filters []Filter, found *FoundFirewall) error {
|
||||||
|
raw, err := json.Marshal(nonNil(filters))
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
var foundRaw any
|
||||||
|
if found != nil {
|
||||||
|
b, err := json.Marshal(found)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
foundRaw = string(b)
|
||||||
|
}
|
||||||
|
_, err = i.store.Pool().Exec(ctx,
|
||||||
|
`update node set filters = $2, found_firewall = $3 where id = $1`, nodeID, raw, foundRaw)
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
// FilteringOf is what a machine last said filters it; empty for a machine that never said.
|
||||||
|
func (i *Inventory) FilteringOf(ctx context.Context, name string) (Filtering, error) {
|
||||||
|
var filtersRaw, foundRaw []byte
|
||||||
|
err := i.store.Pool().QueryRow(ctx,
|
||||||
|
`select filters, found_firewall from node where name = $1`, name).Scan(&filtersRaw, &foundRaw)
|
||||||
|
if errors.Is(err, pgx.ErrNoRows) {
|
||||||
|
return Filtering{}, fmt.Errorf("%w: %s", ErrNoSuchNode, name)
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
return Filtering{}, err
|
||||||
|
}
|
||||||
|
var out Filtering
|
||||||
|
if len(filtersRaw) > 0 {
|
||||||
|
if err := json.Unmarshal(filtersRaw, &out.Filters); err != nil {
|
||||||
|
return Filtering{}, err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if len(foundRaw) > 0 {
|
||||||
|
out.FoundFirewall = &FoundFirewall{}
|
||||||
|
if err := json.Unmarshal(foundRaw, out.FoundFirewall); err != nil {
|
||||||
|
return Filtering{}, err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return out, nil
|
||||||
|
}
|
||||||
|
|
||||||
// Reach is one thing reachable on an adopted node: a listening socket or a published port.
|
// Reach is one thing reachable on an adopted node: a listening socket or a published port.
|
||||||
type Reach struct {
|
type Reach struct {
|
||||||
Protocol string `json:"protocol"`
|
Protocol string `json:"protocol"`
|
||||||
|
|||||||
@@ -42,6 +42,9 @@ const (
|
|||||||
BusModule = "module"
|
BusModule = "module"
|
||||||
BusEnrolment = "enrolment"
|
BusEnrolment = "enrolment"
|
||||||
BusPerson = "person"
|
BusPerson = "person"
|
||||||
|
// BusNodeTools is a machine's tool runtime (novox/hq ADR 0175): named like the module it
|
||||||
|
// stands for, recorded as what it is.
|
||||||
|
BusNodeTools = "node-tools"
|
||||||
)
|
)
|
||||||
|
|
||||||
// MintBusPassword makes a bus password and records its hash under a username, replacing whatever was
|
// MintBusPassword makes a bus password and records its hash under a username, replacing whatever was
|
||||||
|
|||||||
@@ -42,6 +42,11 @@ type Source struct {
|
|||||||
// Seen is when the source was last looked at — by a build, by hand, or by the forge saying it
|
// Seen is when the source was last looked at — by a build, by hand, or by the forge saying it
|
||||||
// moved. What a late report of an older move is judged against.
|
// moved. What a late report of an older move is judged against.
|
||||||
Seen time.Time
|
Seen time.Time
|
||||||
|
// Against is every artifact the build this manifest came from stood on, as recorded. Part of a
|
||||||
|
// module's provenance like the commit is, and what tells a built manifest's base when the manifest
|
||||||
|
// itself no longer carries its build (novox/hq to-be 38 WP2.4). Empty for a manifest handed over
|
||||||
|
// by hand, which carries its `build.on` itself.
|
||||||
|
Against []string
|
||||||
}
|
}
|
||||||
|
|
||||||
// Current reports whether what the mesh holds is what the source last had.
|
// Current reports whether what the mesh holds is what the source last had.
|
||||||
@@ -61,6 +66,32 @@ func (s Source) Current() bool {
|
|||||||
// gains a requirement, a claim, a resource. What matters is that the change is visible the next
|
// gains a requirement, a claim, a resource. What matters is that the change is visible the next
|
||||||
// time a node is resolved, which it is.
|
// time a node is resolved, which it is.
|
||||||
func (i *Inventory) RegisterModule(ctx context.Context, m catalogue.Manifest, from Source) error {
|
func (i *Inventory) RegisterModule(ctx context.Context, m catalogue.Manifest, from Source) error {
|
||||||
|
// **Once the node's tool runtime is in the catalogue, the pattern it retires may not spread**
|
||||||
|
// (novox/hq ADR 0175, to-be 38 WP2.4): a module serving its tools from a container built on the
|
||||||
|
// runtime's image. Refused at registration, by name, for a module that is new to the catalogue
|
||||||
|
// or that was registered in another shape — the mechanism that keeps the old pattern from
|
||||||
|
// returning by habit. **Not refused for a module already registered in that shape**: the
|
||||||
|
// catalogue holds some thirty of them the day the runtime arrives, each moves to a bundle in
|
||||||
|
// its own change (to-be 38 WP4 onward), and a gate that refused every rebuild of every unmoved
|
||||||
|
// module in the meantime would stop the whole pipeline to make a point the record already makes.
|
||||||
|
// Before the runtime exists the pattern is accepted as it always was.
|
||||||
|
if m.Module != catalogue.RuntimeModule {
|
||||||
|
if why := catalogue.ToolContainerOnTheRuntime(m, from.Against); why != "" {
|
||||||
|
runtime, err := i.hasModule(ctx, catalogue.RuntimeModule)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if runtime {
|
||||||
|
already, err := i.registeredInThatShape(ctx, m.Module)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if !already {
|
||||||
|
return fmt.Errorf("%s is not registered: %s", m.Module, why)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
raw, err := json.Marshal(m)
|
raw, err := json.Marshal(m)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
@@ -89,6 +120,36 @@ func (i *Inventory) RegisterModule(ctx context.Context, m catalogue.Manifest, fr
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// registeredInThatShape is whether the catalogue already holds this module as a tools container on
|
||||||
|
// the runtime's image — judged from the manifest it holds and what that module's newest build stood
|
||||||
|
// on, the same two things the gate judges a new registration by. False for a module the catalogue
|
||||||
|
// does not hold.
|
||||||
|
func (i *Inventory) registeredInThatShape(ctx context.Context, name string) (bool, error) {
|
||||||
|
held, err := i.Catalogue(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
stored, has := held[name]
|
||||||
|
if !has {
|
||||||
|
return false, nil
|
||||||
|
}
|
||||||
|
against, err := i.BuiltAgainst(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
return catalogue.ToolContainerOnTheRuntime(stored, against[name]) != "", nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// hasModule is whether the catalogue holds a module of that name.
|
||||||
|
func (i *Inventory) hasModule(ctx context.Context, name string) (bool, error) {
|
||||||
|
var one int
|
||||||
|
err := i.store.Pool().QueryRow(ctx, `select 1 from module where name = $1`, name).Scan(&one)
|
||||||
|
if errors.Is(err, pgx.ErrNoRows) {
|
||||||
|
return false, nil
|
||||||
|
}
|
||||||
|
return err == nil, err
|
||||||
|
}
|
||||||
|
|
||||||
// SourceMoved records that a module's source has a newer commit than the mesh has built.
|
// SourceMoved records that a module's source has a newer commit than the mesh has built.
|
||||||
//
|
//
|
||||||
// This is the whole of noticing. Nothing here builds anything — it writes down that the two
|
// This is the whole of noticing. Nothing here builds anything — it writes down that the two
|
||||||
@@ -605,6 +666,12 @@ func (i *Inventory) SetSettings(ctx context.Context, nodeName, module string, va
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
// Judged here, against the module's current definition, before it is kept (novox/hq ADR 0163,
|
||||||
|
// rule 6): a setting that cannot compose is refused where it is set, naming the node, the
|
||||||
|
// module, the layer and the key — never stored to refuse the whole machine where it is read.
|
||||||
|
if err := i.judgeSettings(ctx, nodeName, module, values); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
if nodeName == "" {
|
if nodeName == "" {
|
||||||
// A port is a fact about one machine (novox/hq ADR 0100). Refused here, in composition's
|
// A port is a fact about one machine (novox/hq ADR 0100). Refused here, in composition's
|
||||||
// words: stored, it refuses every node running the module at composition, and the mesh
|
// words: stored, it refuses every node running the module at composition, and the mesh
|
||||||
@@ -661,6 +728,50 @@ func (i *Inventory) SetSettings(ctx context.Context, nodeName, module string, va
|
|||||||
return tx.Commit(ctx)
|
return tx.Commit(ctx)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// judgeSettings composes a layer somebody is about to store against the module's definition, with
|
||||||
|
// the mesh-wide layer under it when the layer is one node's, and refuses the first thing that
|
||||||
|
// cannot work (ADR 0163, rule 6). The same judgement composition makes; what passes here composes.
|
||||||
|
func (i *Inventory) judgeSettings(ctx context.Context, nodeName, module string, values map[string]any) error {
|
||||||
|
m, err := i.declared(ctx, module)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("%w: %s", ErrNoSuchModule, module)
|
||||||
|
}
|
||||||
|
where, from := "the mesh", catalogue.MeshWideLayer
|
||||||
|
adopted := false
|
||||||
|
var layers []catalogue.Layer
|
||||||
|
if nodeName != "" {
|
||||||
|
node, err := i.NodeByName(ctx, nodeName)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
where, from, adopted = nodeName, nodeName, node.Adopted
|
||||||
|
var meshWide []byte
|
||||||
|
err = i.store.Pool().QueryRow(ctx,
|
||||||
|
`select values from settings where module = $1 and node is null`, module).Scan(&meshWide)
|
||||||
|
if err != nil && !errors.Is(err, pgx.ErrNoRows) {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if len(meshWide) > 0 {
|
||||||
|
var under map[string]any
|
||||||
|
if err := json.Unmarshal(meshWide, &under); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
layers = append(layers, catalogue.Layer{From: catalogue.MeshWideLayer, Values: under})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
layers = append(layers, catalogue.Layer{From: from, Values: values})
|
||||||
|
if err := catalogue.JudgeSettings(m, layers, adopted); err != nil {
|
||||||
|
return fmt.Errorf("refused: %s on %s cannot compose with the layer %q — %w", module, where, from, err)
|
||||||
|
}
|
||||||
|
// And a key that reaches nothing, refused here where somebody can still fix the spelling:
|
||||||
|
// stored, it would be a setting somebody believes they made.
|
||||||
|
if stray := catalogue.UnusedSettings(m, layers[len(layers)-1:]); len(stray) > 0 {
|
||||||
|
return fmt.Errorf("refused: %s on %s — these settings reach nothing:\n - %s", module, where,
|
||||||
|
strings.Join(stray, "\n - "))
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
// givenIn is the machine ports a node-level settings layer gives a module, software port →
|
// givenIn is the machine ports a node-level settings layer gives a module, software port →
|
||||||
// machine port (novox/hq ADR 0100). Nothing when the layer gives none; what is not a port is left
|
// machine port (novox/hq ADR 0100). Nothing when the layer gives none; what is not a port is left
|
||||||
// for composition to refuse in its own words.
|
// for composition to refuse in its own words.
|
||||||
|
|||||||
@@ -685,3 +685,61 @@ func TestRegisteringWithoutProvenanceKeepsTheSeat(t *testing.T) {
|
|||||||
t.Fatalf("a hand-registered manifest erased where the module comes from: %+v", got)
|
t.Fatalf("a hand-registered manifest erased where the module comes from: %+v", got)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Once the node's tool runtime is in the catalogue, a module serving its tools from a container
|
||||||
|
// built on the runtime's image is refused at registration, naming the record (novox/hq ADR 0175,
|
||||||
|
// to-be 38 WP2.4) — for a module new to the catalogue or one that had moved away from it; a module
|
||||||
|
// already standing in that shape is rebuilt as before, so the catalogue's pipeline keeps running
|
||||||
|
// while each moves (WP3's amendment). Before the runtime, it is accepted as it always was — so a
|
||||||
|
// mesh converts in the order the design says and nothing is refused before there is anything to
|
||||||
|
// move to.
|
||||||
|
func TestAToolContainerIsRefusedOnceTheRuntimeIsRegistered(t *testing.T) {
|
||||||
|
inv := fresh(t)
|
||||||
|
ctx := t.Context()
|
||||||
|
filter := catalogue.Manifest{Module: "nftables", Version: "1", Tools: []string{"firewall_rules"},
|
||||||
|
Resources: []map[string]any{{"id": "runtime", "type": "container", "name": "mesh-nftables"}}}
|
||||||
|
stoodOn := []string{catalogue.ArtifactStoreScheme + "mesh-tools/runtime@sha256:" + strings.Repeat("d", 64)}
|
||||||
|
|
||||||
|
// Before the runtime exists the old pattern is accepted as it always was — and built, which is
|
||||||
|
// how the catalogue comes to know what the module stood on.
|
||||||
|
if err := inv.RegisterModule(ctx, filter, Source{Repository: "/r", Against: stoodOn}); err != nil {
|
||||||
|
t.Fatalf("before the runtime exists the old pattern is accepted: %v", err)
|
||||||
|
}
|
||||||
|
built := aBuild("nf1", "nftables", "")
|
||||||
|
built.Against = stoodOn
|
||||||
|
if err := inv.RecordBuild(ctx, built); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
runtime := catalogue.Manifest{Module: catalogue.RuntimeModule, Version: "1"}
|
||||||
|
if err := inv.RegisterModule(ctx, runtime, Source{Repository: "/r"}); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// **A module already registered in that shape is rebuilt without complaint** (to-be 38 WP2.4 as
|
||||||
|
// amended by WP3): some thirty of them stand the day the runtime arrives, and each moves in its
|
||||||
|
// own change. The gate is against the pattern spreading, not against the pipeline running.
|
||||||
|
if err := inv.RegisterModule(ctx, filter, Source{Repository: "/r", Against: stoodOn}); err != nil {
|
||||||
|
t.Fatalf("a rebuild of a module that already had the pattern was refused: %v", err)
|
||||||
|
}
|
||||||
|
// A module new to the catalogue in that shape is refused, naming the record.
|
||||||
|
newcomer := filter
|
||||||
|
newcomer.Module = "lamp"
|
||||||
|
err := inv.RegisterModule(ctx, newcomer, Source{Repository: "/r", Against: stoodOn})
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "ADR 0175") {
|
||||||
|
t.Fatalf("a new module in the old pattern was registered beside the runtime: %v", err)
|
||||||
|
}
|
||||||
|
// And a module that had moved its tools to a bundle may not come back to a container.
|
||||||
|
moved := filter
|
||||||
|
moved.Resources = nil
|
||||||
|
if err := inv.RegisterModule(ctx, moved, Source{Repository: "/r", Against: stoodOn}); err != nil {
|
||||||
|
t.Fatalf("a module whose tools are a bundle was refused: %v", err)
|
||||||
|
}
|
||||||
|
unbuilt := aBuild("nf2", "nftables", "")
|
||||||
|
if err := inv.RecordBuild(ctx, unbuilt); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
err = inv.RegisterModule(ctx, filter, Source{Repository: "/r", Against: stoodOn})
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "ADR 0175") {
|
||||||
|
t.Fatalf("a module that had moved returned to the old pattern unrefused: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -63,7 +63,7 @@ func dependenciesOf(entries []Entry, against map[string][]string, read map[strin
|
|||||||
if r := repositoryKey(e.Source.Repository); r != "" {
|
if r := repositoryKey(e.Source.Repository); r != "" {
|
||||||
byRepository[r] = append(byRepository[r], name)
|
byRepository[r] = append(byRepository[r], name)
|
||||||
}
|
}
|
||||||
if e.Manifest.ClaimsSeat("mesh-build-machine") {
|
if e.Manifest.ClaimsSeat("node-build-agent") || e.Manifest.ClaimsSeat("mesh-build-machine") {
|
||||||
builders = append(builders, name)
|
builders = append(builders, name)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ func TestDependenciesAreOneRelationWithTheirKinds(t *testing.T) {
|
|||||||
return Entry{Manifest: catalogue.Manifest{Module: name}, Source: Source{Repository: repository}}
|
return Entry{Manifest: catalogue.Manifest{Module: name}, Source: Source{Repository: repository}}
|
||||||
}
|
}
|
||||||
builder := entry("builder", "http://forge/novox/mesh-catalog.git")
|
builder := entry("builder", "http://forge/novox/mesh-catalog.git")
|
||||||
builder.Manifest.Claims = []catalogue.Claim{{Name: "mesh-build-machine", Scope: catalogue.ScopeMesh}}
|
builder.Manifest.Claims = []catalogue.Claim{{Name: "node-build-agent", Scope: catalogue.ScopeNode}}
|
||||||
plugin := entry("shop-plugin", "http://forge/novox/mesh-catalog.git")
|
plugin := entry("shop-plugin", "http://forge/novox/mesh-catalog.git")
|
||||||
plugin.Manifest.Build = &catalogue.Build{On: []catalogue.BuildsOn{{Arg: "BASE", Module: "shop"}}}
|
plugin.Manifest.Build = &catalogue.Build{On: []catalogue.BuildsOn{{Arg: "BASE", Module: "shop"}}}
|
||||||
entries := []Entry{
|
entries := []Entry{
|
||||||
|
|||||||
@@ -31,8 +31,11 @@ func TestRegisteringAModuleAgainKeepsWhatTheMeshHoldsForIt(t *testing.T) {
|
|||||||
if err := inv.RecordSealingKey(ctx, node.ID, key); err != nil {
|
if err := inv.RecordSealingKey(ctx, node.ID, key); err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
// A mergeable file, so any setting composes (novox/hq ADR 0163, rule 6: a setting is judged
|
||||||
|
// where it is stored).
|
||||||
m := catalogue.Manifest{Module: "step-ca", Version: "1",
|
m := catalogue.Manifest{Module: "step-ca", Version: "1",
|
||||||
Provides: catalogue.Offers("acme-ca"), OwnSecrets: catalogue.OwnSecrets{"password": {Path: "/run/password"}}}
|
Provides: catalogue.Offers("acme-ca"), OwnSecrets: catalogue.OwnSecrets{"password": {Path: "/run/password"}},
|
||||||
|
Resources: []map[string]any{{"id": "conf", "type": "file", "path": "/etc/step-ca.json", "content": "{}", "merge": "json"}}}
|
||||||
if err := inv.RegisterModule(ctx, m, Source{}); err != nil {
|
if err := inv.RegisterModule(ctx, m, Source{}); err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
@@ -229,5 +232,9 @@ func TestAModuleStillAssignedRefusesBeforeAnythingAboutWhatItHolds(t *testing.T)
|
|||||||
// declares (novox/hq 04-ISSUES/078).
|
// declares (novox/hq 04-ISSUES/078).
|
||||||
func withOwnSecret(m catalogue.Manifest, name string) catalogue.Manifest {
|
func withOwnSecret(m catalogue.Manifest, name string) catalogue.Manifest {
|
||||||
m.OwnSecrets = catalogue.OwnSecrets{name: {Path: "/run/" + name}}
|
m.OwnSecrets = catalogue.OwnSecrets{name: {Path: "/run/" + name}}
|
||||||
|
// And a mergeable file, so any setting these tests store composes (novox/hq ADR 0163, rule 6:
|
||||||
|
// a setting is judged where it is stored).
|
||||||
|
m.Resources = append(m.Resources, map[string]any{"id": "conf", "type": "file",
|
||||||
|
"path": "/etc/" + m.Module + ".json", "content": "{}", "merge": "json"})
|
||||||
return m
|
return m
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
-- What filters a machine, with owners, as the host reports it with every apply (novox/hq ADR 0168):
|
||||||
|
-- every table and chain that refuses traffic — the mesh's, the found firewall's, the runtime's own,
|
||||||
|
-- a ban, or other — so the mesh says truthfully what filters a converged machine and names what it
|
||||||
|
-- did not write. And the state of the firewall a converged machine was found with: in force now or
|
||||||
|
-- not, and who retired it.
|
||||||
|
alter table node add column filters jsonb;
|
||||||
|
alter table node add column found_firewall jsonb;
|
||||||
@@ -15,9 +15,16 @@ func aNodeWithModules(t *testing.T, modules ...string) (*Inventory, string) {
|
|||||||
if _, err := inv.AddNode(ctx, "anchor"); err != nil {
|
if _, err := inv.AddNode(ctx, "anchor"); err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
// Each publishes the port these tests give it a machine port for: a port given for one the
|
||||||
|
// module does not publish is refused where it is stored (novox/hq ADR 0163, rule 6).
|
||||||
|
publishes := map[string]string{"postgres": "5432", "another-database": "5432", "cache": "6379", "web": "8080"}
|
||||||
for _, m := range modules {
|
for _, m := range modules {
|
||||||
if err := inv.RegisterModule(ctx,
|
manifest := catalogue.Manifest{Module: m, Version: "1"}
|
||||||
catalogue.Manifest{Module: m, Version: "1"}, Source{}); err != nil {
|
if port, known := publishes[m]; known {
|
||||||
|
manifest.Resources = []map[string]any{{"id": "server", "type": "container", "name": m,
|
||||||
|
"image": "x", "ports": []any{port}}}
|
||||||
|
}
|
||||||
|
if err := inv.RegisterModule(ctx, manifest, Source{}); err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -820,3 +820,52 @@ func (i *Inventory) SharedHolders(ctx context.Context, provider, providerModule,
|
|||||||
sort.Strings(out)
|
sort.Strings(out)
|
||||||
return out, nil
|
return out, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// SecretState is one secret a module holds on a machine, as a take compares it (novox/hq ADR
|
||||||
|
// 0163): its name, where it came from — made by the mesh or accepted from a person — and, for a
|
||||||
|
// credential the module requires from a provider, which node provides it and the local name it
|
||||||
|
// goes by where the module keeps several.
|
||||||
|
type SecretState struct {
|
||||||
|
Name string
|
||||||
|
// Local is the credential's name inside the module (ADR 0094); empty for an own secret or the
|
||||||
|
// ordinary one.
|
||||||
|
Local string
|
||||||
|
// Origin is OriginMade or OriginAccepted.
|
||||||
|
Origin string
|
||||||
|
// Provider is the node providing a required secret; empty for the module's own.
|
||||||
|
Provider string
|
||||||
|
}
|
||||||
|
|
||||||
|
// Own says the secret is the module's own rather than one it requires from a provider.
|
||||||
|
func (s SecretState) Own() bool { return s.Provider == "" }
|
||||||
|
|
||||||
|
// SecretsOf is every secret a module holds on a machine: its own, and each credential it requires
|
||||||
|
// from a provider — with where each value came from. What a take reads to refuse minting over a
|
||||||
|
// service that already has one (ADR 0163, rule 2).
|
||||||
|
func (i *Inventory) SecretsOf(ctx context.Context, node, module string) ([]SecretState, error) {
|
||||||
|
record, err := i.NodeByName(ctx, node)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
rows, err := i.store.Pool().Query(ctx,
|
||||||
|
`select name, '' as local, origin, '' as provider from module_secret
|
||||||
|
where node = $1 and module = $2
|
||||||
|
union all
|
||||||
|
select s.name, s.local, s.origin, p.name from secret s
|
||||||
|
join node p on p.id = s.provider
|
||||||
|
where s.consumer = $1 and s.consumer_module = $2
|
||||||
|
order by 4, 1, 2`, record.ID, module)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
defer rows.Close()
|
||||||
|
var out []SecretState
|
||||||
|
for rows.Next() {
|
||||||
|
var s SecretState
|
||||||
|
if err := rows.Scan(&s.Name, &s.Local, &s.Origin, &s.Provider); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
out = append(out, s)
|
||||||
|
}
|
||||||
|
return out, rows.Err()
|
||||||
|
}
|
||||||
|
|||||||
@@ -934,3 +934,47 @@ func TestASharedCredentialIsOneValueSealedToEveryHolder(t *testing.T) {
|
|||||||
t.Fatalf("a consumer binding after an acceptance must be refused with the way out: %v", err)
|
t.Fatalf("a consumer binding after an acceptance must be refused with the way out: %v", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// SecretsOf is every secret a module holds on a machine with where each came from — what a take
|
||||||
|
// reads to refuse minting over a service that already has a value (novox/hq ADR 0163, rule 2).
|
||||||
|
func TestSecretsOfSaysEachSecretsOriginAndProvider(t *testing.T) {
|
||||||
|
inv, ctx := twoNodesWithKeys(t)
|
||||||
|
if err := inv.RegisterModule(ctx, catalogue.Manifest{Module: "forge", Version: "1",
|
||||||
|
Requires: []string{"secret", "postgres-database"},
|
||||||
|
Secrets: map[string]string{"secret": "/run/secret", "postgres-database": "/run/pg"},
|
||||||
|
OwnSecrets: catalogue.OwnSecrets{"admin": {Path: "/run/admin"}}}, Source{}); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if _, err := inv.SecretForModule(ctx, "consumer", "forge", "admin"); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if _, err := inv.SecretFor(ctx, "postgres-database", "consumer", "forge", "provider", ""); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := inv.AcceptSecretForPair(ctx, "secret", "consumer", "forge", "provider", "", "hunter2"); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
got, err := inv.SecretsOf(ctx, "consumer", "forge")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
want := []SecretState{
|
||||||
|
{Name: "admin", Origin: OriginMade},
|
||||||
|
{Name: "postgres-database", Origin: OriginMade, Provider: "provider"},
|
||||||
|
{Name: "secret", Origin: OriginAccepted, Provider: "provider"},
|
||||||
|
}
|
||||||
|
if len(got) != len(want) {
|
||||||
|
t.Fatalf("got %+v", got)
|
||||||
|
}
|
||||||
|
for i := range want {
|
||||||
|
if got[i] != want[i] {
|
||||||
|
t.Errorf("secret %d: got %+v, want %+v", i, got[i], want[i])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !got[0].Own() || got[1].Own() {
|
||||||
|
t.Error("own and required are not told apart")
|
||||||
|
}
|
||||||
|
if other, _ := inv.SecretsOf(ctx, "consumer", "gitea"); len(other) != 0 {
|
||||||
|
t.Fatalf("another module's secrets: %+v", other)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -0,0 +1,69 @@
|
|||||||
|
package inventory
|
||||||
|
|
||||||
|
import (
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/novox/mesh-controller/internal/catalogue"
|
||||||
|
)
|
||||||
|
|
||||||
|
// A setting is judged where it is stored (novox/hq ADR 0163, rule 6): one that cannot compose with
|
||||||
|
// the module's definition is refused naming the node, the module, the layer and the key, and is not
|
||||||
|
// kept; one that reaches nothing is refused the same way.
|
||||||
|
func TestASettingIsJudgedWhereItIsStored(t *testing.T) {
|
||||||
|
inv := fresh(t)
|
||||||
|
ctx := t.Context()
|
||||||
|
if _, err := inv.AddNode(ctx, "anchor"); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
web := catalogue.Manifest{Module: "web", Version: "1",
|
||||||
|
Resources: []map[string]any{
|
||||||
|
{"id": "server", "type": "container", "name": "web", "image": "x", "ports": []any{"8080"}},
|
||||||
|
{"id": "conf", "type": "file", "path": "/etc/web.json", "content": "{}", "merge": "json"},
|
||||||
|
}}
|
||||||
|
plain := catalogue.Manifest{Module: "plain", Version: "1",
|
||||||
|
Resources: []map[string]any{{"id": "server", "type": "container", "name": "plain", "image": "x"}}}
|
||||||
|
for _, m := range []catalogue.Manifest{web, plain} {
|
||||||
|
if err := inv.RegisterModule(ctx, m, Source{}); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
err := inv.SetSettings(ctx, "anchor", "web", map[string]any{catalogue.PortsSetting: map[string]any{"9999": 10000}})
|
||||||
|
for _, want := range []string{"refused: web on anchor", `layer "anchor"`, "9999"} {
|
||||||
|
if err == nil || !strings.Contains(err.Error(), want) {
|
||||||
|
t.Errorf("a port the module does not publish: %v, want %q", err, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if layers, _ := inv.SettingsFor(ctx, "anchor", "web"); len(layers) != 0 {
|
||||||
|
t.Fatalf("the refused layer was stored: %v", layers)
|
||||||
|
}
|
||||||
|
// A key that reaches nothing is refused too, where the spelling can still be fixed; a module
|
||||||
|
// with a mergeable file takes any key.
|
||||||
|
err = inv.SetSettings(ctx, "", "plain", map[string]any{"colour": "blue"})
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "reach nothing") || !strings.Contains(err.Error(), `"colour"`) {
|
||||||
|
t.Fatalf("a stray key was stored: %v", err)
|
||||||
|
}
|
||||||
|
if err := inv.SetSettings(ctx, "", "web", map[string]any{"colour": "blue"}); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
// The mesh-wide layer is under the node's when the node's is judged.
|
||||||
|
if err := inv.SetSettings(ctx, "anchor", "web", map[string]any{catalogue.PortsSetting: map[string]any{"8080": 10000}}); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
// A kept network is for an adopted machine only (rule 4).
|
||||||
|
keep := map[string]any{catalogue.NetworksSetting: map[string]any{"server": []any{"predecessor_default"}}}
|
||||||
|
err = inv.SetSettings(ctx, "anchor", "plain", keep)
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "anchor is converged") {
|
||||||
|
t.Fatalf("a kept network on a converged machine was stored: %v", err)
|
||||||
|
}
|
||||||
|
if err := inv.SetAdopted(ctx, "anchor", true); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := inv.SetSettings(ctx, "anchor", "plain", keep); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := inv.SetSettings(ctx, "anchor", "nothing", keep); err == nil {
|
||||||
|
t.Fatal("a setting for a module the mesh does not know was stored")
|
||||||
|
}
|
||||||
|
}
|
||||||
+11
-2
@@ -19,8 +19,17 @@ import (
|
|||||||
// act on or a declaration a node reconciles toward; a build is a request that takes minutes and has
|
// act on or a declaration a node reconciles toward; a build is a request that takes minutes and has
|
||||||
// exactly one answer. Too long for request/reply, too particular to be an event.
|
// exactly one answer. Too long for request/reply, too particular to be an event.
|
||||||
|
|
||||||
// TheBuildMachine is the role a build is submitted to.
|
// TheBuildMachine is the role a build is submitted to: node-scoped, held on every machine that
|
||||||
const TheBuildMachine = "mesh-build-machine"
|
// builds, and the work shared among them (novox/hq ADR 0190). The name stays for every caller; what
|
||||||
|
// it names moved from the mesh's one build machine to whichever build agent is idle.
|
||||||
|
//
|
||||||
|
// **Switching a live mesh over, in order.** The old seat's stream and worker
|
||||||
|
// (SEAT_MESH_BUILD_MACHINE, SEAT_MESH_BUILD_MACHINE_worker) stay on the bus until removed by hand,
|
||||||
|
// and the builder module keeps draining them while it is assigned. From the moment a controller
|
||||||
|
// with this name runs, new asks go to node-build-agent and wait in its stream until some machine
|
||||||
|
// holds the seat. So: let the queued builds finish; roll this controller; register and assign
|
||||||
|
// build-agent to the machines that build; unassign builder and forget it and its seat's stream.
|
||||||
|
const TheBuildMachine = "node-build-agent"
|
||||||
|
|
||||||
// BuildWork is where a build request lands, and BuildOutcome is where its result does. Derived from
|
// BuildWork is where a build request lands, and BuildOutcome is where its result does. Derived from
|
||||||
// the seat, so both sides name the role and neither names the other.
|
// the seat, so both sides name the role and neither names the other.
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ func TestTheOldBusAnnouncesABuildUnderBothNames(t *testing.T) {
|
|||||||
if KeyRoleBuilt != "built" {
|
if KeyRoleBuilt != "built" {
|
||||||
t.Fatalf("the role's event is %q, and a holder emits its verbs bare", KeyRoleBuilt)
|
t.Fatalf("the role's event is %q, and a holder emits its verbs bare", KeyRoleBuilt)
|
||||||
}
|
}
|
||||||
if TheBuildMachine != "mesh-build-machine" {
|
if TheBuildMachine != "node-build-agent" {
|
||||||
t.Fatalf("the role is %q", TheBuildMachine)
|
t.Fatalf("the role is %q", TheBuildMachine)
|
||||||
}
|
}
|
||||||
// The two must differ, or one publish would serve both and this doubling would be pointless.
|
// The two must differ, or one publish would serve both and this doubling would be pointless.
|
||||||
|
|||||||
@@ -126,29 +126,31 @@ func (m *natsMachine) Close() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Take binds to the role's worker and hands each request over, one at a time.
|
// Take binds to the role's worker and pulls one request at a time, handing each over.
|
||||||
//
|
//
|
||||||
// **Bound, never created.** The work queue and the worker on it are the controller's to define
|
// **Bound, never created.** The work queue and the worker on it are the controller's to define
|
||||||
// (design 25 §3), and a build machine reaches no part of the JetStream API — so a missing one is said
|
// (design 25 §3), and a build machine reaches no part of the JetStream API — so a missing one is said
|
||||||
// as the mesh's to answer rather than quietly created with whatever this client defaults to.
|
// as the mesh's to answer rather than quietly created with whatever this client defaults to.
|
||||||
|
//
|
||||||
|
// **Pulled, one at a time, by whichever holder is free** (novox/hq ADR 0190). Every machine holding
|
||||||
|
// the role binds this same worker; a machine asks for the next request only when it has finished
|
||||||
|
// the last, so a slow machine never holds an ask an idle one could take, and a machine that took
|
||||||
|
// five at once would run five container builds against one runtime and finish all of them slower
|
||||||
|
// than the first.
|
||||||
func (m *natsMachine) Take(ctx context.Context, do func(context.Context, Build)) error {
|
func (m *natsMachine) Take(ctx context.Context, do func(context.Context, Build)) error {
|
||||||
worker, found := broker.HolderConsumerFor(m.on, "builder",
|
worker, found := broker.HolderConsumerFor(m.on, "build-agent",
|
||||||
broker.DeclaredSeat{Name: m.seat, Accepts: []string{"build"}})
|
broker.DeclaredSeat{Name: m.seat, Accepts: []string{"build"}})
|
||||||
if !found {
|
if !found {
|
||||||
return fmt.Errorf("%s accepts no work, so there is nothing for this machine to take", m.seat)
|
return fmt.Errorf("%s accepts no work, so there is nothing for this machine to take", m.seat)
|
||||||
}
|
}
|
||||||
|
|
||||||
// One at a time, which the consumer's own ack-pending limit enforces rather than a prefetch
|
|
||||||
// setting: a machine that took five requests at once would run five container builds against one
|
|
||||||
// runtime and finish all of them slower than the first.
|
|
||||||
work := make(chan *nats.Msg, 1)
|
|
||||||
// **The consumer's own filter, not the one subject this machine cares about.** The client checks
|
// **The consumer's own filter, not the one subject this machine cares about.** The client checks
|
||||||
// what is asked for against the consumer's filter and refuses anything that is not the same —
|
// what is asked for against the consumer's filter and refuses anything that is not the same —
|
||||||
// "subject does not match consumer" — so subscribing `…accept.build` against a consumer filtered
|
// "subject does not match consumer" — so subscribing `…accept.build` against a consumer filtered
|
||||||
// on `…accept.>` is rejected even though it is narrower. Learned twice now, on two different
|
// on `…accept.>` is rejected even though it is narrower. Learned twice now, on two different
|
||||||
// consumers, which is why it is written down here.
|
// consumers, which is why it is written down here.
|
||||||
filter := worker.Filters[0]
|
filter := worker.Filters[0]
|
||||||
sub, err := m.js.Context().ChanQueueSubscribe(filter, worker.Queue, work,
|
sub, err := m.js.Context().PullSubscribe(filter, worker.Name,
|
||||||
nats.Bind(worker.Stream, worker.Name), nats.ManualAck())
|
nats.Bind(worker.Stream, worker.Name), nats.ManualAck())
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf(
|
return fmt.Errorf(
|
||||||
@@ -159,13 +161,27 @@ func (m *natsMachine) Take(ctx context.Context, do func(context.Context, Build))
|
|||||||
m.sub = sub
|
m.sub = sub
|
||||||
|
|
||||||
for {
|
for {
|
||||||
select {
|
if ctx.Err() != nil {
|
||||||
case <-ctx.Done():
|
|
||||||
return nil
|
return nil
|
||||||
case msg, ok := <-work:
|
}
|
||||||
if !ok {
|
// One, and wait a while for it; an empty queue is a timeout, which is the normal state of a
|
||||||
return errors.New("the bus stopped delivering build work")
|
// machine with nothing to build, and is asked again.
|
||||||
|
fetched, err := sub.Fetch(1, nats.Context(ctx))
|
||||||
|
switch {
|
||||||
|
case errors.Is(err, context.Canceled), errors.Is(err, context.DeadlineExceeded):
|
||||||
|
return nil
|
||||||
|
case errors.Is(err, nats.ErrTimeout):
|
||||||
|
continue
|
||||||
|
case err != nil:
|
||||||
|
if sub.IsValid() {
|
||||||
|
// A transient fault in asking — a reconnect, a slow server — is asked past rather
|
||||||
|
// than ending the machine; one that outlasts the ack wait redelivers nothing lost.
|
||||||
|
time.Sleep(time.Second)
|
||||||
|
continue
|
||||||
}
|
}
|
||||||
|
return fmt.Errorf("the bus stopped delivering build work: %w", err)
|
||||||
|
}
|
||||||
|
for _, msg := range fetched {
|
||||||
var request BuildRequest
|
var request BuildRequest
|
||||||
if err := json.Unmarshal(msg.Data, &request); err != nil {
|
if err := json.Unmarshal(msg.Data, &request); err != nil {
|
||||||
// Unreadable: terminated rather than retried, because the next attempt reads the same
|
// Unreadable: terminated rather than retried, because the next attempt reads the same
|
||||||
|
|||||||
@@ -48,7 +48,7 @@ func aBusWithTheBuildRole(t *testing.T) *broker.JetStream {
|
|||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
clean := func() {
|
clean := func() {
|
||||||
_ = js.Context().DeleteStream("SEAT_MESH_BUILD_MACHINE")
|
_ = js.Context().DeleteStream("SEAT_NODE_BUILD_AGENT")
|
||||||
for _, s := range broker.MeshStreams() {
|
for _, s := range broker.MeshStreams() {
|
||||||
_ = js.Context().PurgeStream(s.Name)
|
_ = js.Context().PurgeStream(s.Name)
|
||||||
}
|
}
|
||||||
@@ -158,7 +158,7 @@ func TestNatsABuildIsTakenAndItsOutcomeReachesEverybody(t *testing.T) {
|
|||||||
// And the work left the queue: a request a machine took and settled must not be given to another.
|
// And the work left the queue: a request a machine took and settled must not be given to another.
|
||||||
deadline := time.Now().Add(5 * time.Second)
|
deadline := time.Now().Add(5 * time.Second)
|
||||||
for time.Now().Before(deadline) {
|
for time.Now().Before(deadline) {
|
||||||
info, err := js.Context().StreamInfo("SEAT_MESH_BUILD_MACHINE")
|
info, err := js.Context().StreamInfo("SEAT_NODE_BUILD_AGENT")
|
||||||
if err == nil && info.State.Msgs == 0 {
|
if err == nil && info.State.Msgs == 0 {
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
@@ -177,7 +177,7 @@ func TestNatsABuildWaitsForAMachineRatherThanFailing(t *testing.T) {
|
|||||||
if _, err := js.Context().Publish(BuildWork(), body); err != nil {
|
if _, err := js.Context().Publish(BuildWork(), body); err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
info, err := js.Context().StreamInfo("SEAT_MESH_BUILD_MACHINE")
|
info, err := js.Context().StreamInfo("SEAT_NODE_BUILD_AGENT")
|
||||||
if err != nil || info.State.Msgs != 1 {
|
if err != nil || info.State.Msgs != 1 {
|
||||||
t.Fatalf("the work did not queue: %+v %v", info, err)
|
t.Fatalf("the work did not queue: %+v %v", info, err)
|
||||||
}
|
}
|
||||||
@@ -245,3 +245,83 @@ func TestNatsWorkAMachineDidNotAnswerGoesBackToTheQueue(t *testing.T) {
|
|||||||
func quietLog() *log.Logger { return log.New(io.Discard, "", 0) }
|
func quietLog() *log.Logger { return log.New(io.Discard, "", 0) }
|
||||||
|
|
||||||
var _ = quietLog
|
var _ = quietLog
|
||||||
|
|
||||||
|
// Two machines holding the role share one queue (novox/hq ADR 0190): three asks, each machine takes
|
||||||
|
// one and the third waits until one of them is done; an ask is never handed to a machine that is
|
||||||
|
// busy; and a machine that stops mid-ask leaves its ask to the other.
|
||||||
|
func TestNatsTwoMachinesShareTheWorkAndNeitherIsHandedMoreThanItCanTake(t *testing.T) {
|
||||||
|
js := aBusWithTheBuildRole(t)
|
||||||
|
ctx, stop := context.WithCancel(context.Background())
|
||||||
|
defer stop()
|
||||||
|
|
||||||
|
for _, id := range []string{"w-1", "w-2", "w-3"} {
|
||||||
|
body, _ := json.Marshal(BuildRequest{ID: id, Repository: "/r"})
|
||||||
|
if _, err := js.Context().Publish(BuildWork(), body); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
type taken struct{ machine, id string }
|
||||||
|
took := make(chan taken, 8)
|
||||||
|
release := map[string]chan struct{}{"anchor": make(chan struct{}), "laptop": make(chan struct{})}
|
||||||
|
machines := map[string]BuildMachine{}
|
||||||
|
for _, name := range []string{"anchor", "laptop"} {
|
||||||
|
name := name
|
||||||
|
m := MachineOverNATS(js, name)
|
||||||
|
machines[name] = m
|
||||||
|
defer m.Close()
|
||||||
|
go func() {
|
||||||
|
_ = m.Take(ctx, func(ctx context.Context, work Build) {
|
||||||
|
took <- taken{name, work.Request().ID}
|
||||||
|
<-release[name]
|
||||||
|
_ = work.Announce(ctx, BuildResult{ID: work.Request().ID, On: name})
|
||||||
|
_ = work.Done()
|
||||||
|
})
|
||||||
|
}()
|
||||||
|
}
|
||||||
|
|
||||||
|
// Each machine took exactly one, and they are different asks.
|
||||||
|
first := map[string]string{}
|
||||||
|
for i := 0; i < 2; i++ {
|
||||||
|
select {
|
||||||
|
case got := <-took:
|
||||||
|
if _, twice := first[got.machine]; twice {
|
||||||
|
t.Fatalf("%s was handed a second ask while busy with its first", got.machine)
|
||||||
|
}
|
||||||
|
first[got.machine] = got.id
|
||||||
|
case <-time.After(10 * time.Second):
|
||||||
|
t.Fatalf("only %d machine(s) took work; two idle holders should both have", len(first))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if first["anchor"] == first["laptop"] {
|
||||||
|
t.Fatalf("both machines took %q: the queue is not shared, it is copied", first["anchor"])
|
||||||
|
}
|
||||||
|
// The third waits: nobody is free.
|
||||||
|
select {
|
||||||
|
case got := <-took:
|
||||||
|
t.Fatalf("%s was handed %s while both machines were busy", got.machine, got.id)
|
||||||
|
case <-time.After(2 * time.Second):
|
||||||
|
}
|
||||||
|
// One finishes, and only then is the third taken — by that machine, the one that is free.
|
||||||
|
close(release["anchor"])
|
||||||
|
release["anchor"] = make(chan struct{})
|
||||||
|
select {
|
||||||
|
case got := <-took:
|
||||||
|
if got.machine != "anchor" {
|
||||||
|
t.Fatalf("the third ask went to %s, which is still busy", got.machine)
|
||||||
|
}
|
||||||
|
case <-time.After(10 * time.Second):
|
||||||
|
t.Fatal("the third ask was never taken after a machine became free")
|
||||||
|
}
|
||||||
|
// A machine that stops mid-ask leaves its ask unacknowledged, and the ack wait brings it round
|
||||||
|
// to whoever is left — the path TestNatsWorkAMachineDidNotAnswerGoesBackToTheQueue proves with
|
||||||
|
// an explicit hand-back, because the real wait is a minute. Here: the laptop goes, anchor
|
||||||
|
// finishes, and with nothing queued nothing more is taken by the machine that is left.
|
||||||
|
machines["laptop"].Close()
|
||||||
|
close(release["anchor"])
|
||||||
|
select {
|
||||||
|
case got := <-took:
|
||||||
|
t.Fatalf("%s took %s; the queue should be empty", got.machine, got.id)
|
||||||
|
case <-time.After(2 * time.Second):
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -305,6 +305,23 @@ func (e Enrolment) Heard(ctx context.Context, report Report) (news bool, err err
|
|||||||
return false, err
|
return false, err
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
// What filters the machine, and the state of its found firewall (novox/hq ADR 0168), whenever
|
||||||
|
// it says — every apply of a host that knows how, adopted or converged; never cleared by a
|
||||||
|
// report that carries none, which is every bare word that the node is there.
|
||||||
|
if len(report.Filters) > 0 || report.FoundFirewall != nil {
|
||||||
|
filters := make([]inventory.Filter, 0, len(report.Filters))
|
||||||
|
for _, f := range report.Filters {
|
||||||
|
filters = append(filters, inventory.Filter{Where: f.Where, Owner: f.Owner, Refuses: f.Refuses})
|
||||||
|
}
|
||||||
|
var found *inventory.FoundFirewall
|
||||||
|
if report.FoundFirewall != nil {
|
||||||
|
found = &inventory.FoundFirewall{Kind: report.FoundFirewall.Kind, Active: report.FoundFirewall.Active,
|
||||||
|
RetiredBy: report.FoundFirewall.RetiredBy}
|
||||||
|
}
|
||||||
|
if err := e.Inventory.RecordFiltering(ctx, node.ID, filters, found); err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
}
|
||||||
// Which of its links face outside (novox/hq ADR 0140), whenever it says so. Recorded on every
|
// Which of its links face outside (novox/hq ADR 0140), whenever it says so. Recorded on every
|
||||||
// report that carries it, adopted or converged, because the filter the mesh composes is written
|
// report that carries it, adopted or converged, because the filter the mesh composes is written
|
||||||
// around it — and never cleared by a report that carries none, which is every bare word that the
|
// around it — and never cleared by a report that carries none, which is every bare word that the
|
||||||
|
|||||||
@@ -218,3 +218,45 @@ func TestWhatAnAdoptedNodeHoldsIsKeptAndAnAliveWordDoesNotWipeIt(t *testing.T) {
|
|||||||
t.Fatalf("a report from an adopted node holding nothing did not empty held: %+v", got)
|
t.Fatalf("a report from an adopted node holding nothing did not empty held: %+v", got)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// What filters a machine, and the state of its found firewall, are kept from every report that
|
||||||
|
// carries them and never cleared by one that does not (novox/hq ADR 0168).
|
||||||
|
func TestWhatFiltersAMachineIsKeptFromItsReport(t *testing.T) {
|
||||||
|
inv, _, _ := heardFrom(t, link.Report{
|
||||||
|
Node: "home-server", Applied: []string{"a"},
|
||||||
|
Filters: []link.Filter{
|
||||||
|
{Where: "table inet mesh, chain forward", Owner: "mesh", Refuses: "policy drop"},
|
||||||
|
{Where: "chain HAL-MESH-ONLY (iptables-legacy)", Owner: "other", Refuses: "-j DROP"},
|
||||||
|
},
|
||||||
|
FoundFirewall: &link.FoundFirewall{Kind: "ufw", Active: false, RetiredBy: "found-inactive"},
|
||||||
|
})
|
||||||
|
ctx := context.Background()
|
||||||
|
f, err := inv.FilteringOf(ctx, "home-server")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if len(f.Filters) != 2 || f.Filters[1].Owner != inventory.FilterOther || f.Alone() {
|
||||||
|
t.Fatalf("recorded %+v", f)
|
||||||
|
}
|
||||||
|
if f.FoundFirewall == nil || f.FoundFirewall.RetiredBy != "found-inactive" || f.FoundFirewall.Active {
|
||||||
|
t.Fatalf("the found firewall's state: %+v", f.FoundFirewall)
|
||||||
|
}
|
||||||
|
if len(f.Others()) != 1 || f.Others()[0].Where != "chain HAL-MESH-ONLY (iptables-legacy)" {
|
||||||
|
t.Fatalf("others: %+v", f.Others())
|
||||||
|
}
|
||||||
|
// A bare word that the node is there clears nothing.
|
||||||
|
if _, err := (link.Enrolment{Inventory: inv}).Heard(ctx, link.Report{Node: "home-server"}); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if again, _ := inv.FilteringOf(ctx, "home-server"); len(again.Filters) != 2 {
|
||||||
|
t.Fatalf("a bare report cleared what filters the machine: %+v", again)
|
||||||
|
}
|
||||||
|
// The next full report replaces it: the chain removed by hand is gone from the record.
|
||||||
|
if _, err := (link.Enrolment{Inventory: inv}).Heard(ctx, link.Report{Node: "home-server", Applied: []string{"a"},
|
||||||
|
Filters: []link.Filter{{Where: "table inet mesh, chain forward", Owner: "mesh", Refuses: "policy drop"}}}); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if again, _ := inv.FilteringOf(ctx, "home-server"); len(again.Filters) != 1 || !again.Alone() {
|
||||||
|
t.Fatalf("the next report did not replace what filters the machine: %+v", again)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -197,6 +197,15 @@ type Report struct {
|
|||||||
// Strays is what runs on the machine that the mesh neither wrote nor holds (ADR 0163).
|
// Strays is what runs on the machine that the mesh neither wrote nor holds (ADR 0163).
|
||||||
Strays []Stray `json:"strays,omitempty"`
|
Strays []Stray `json:"strays,omitempty"`
|
||||||
|
|
||||||
|
// Filters is what filters the machine now: every table and chain that refuses traffic, with
|
||||||
|
// its owner — the mesh's, the found firewall's, the container runtime's own, a ban, or other
|
||||||
|
// (novox/hq ADR 0168). Every machine reports it, adopted or converged; absent from a host older
|
||||||
|
// than this.
|
||||||
|
Filters []Filter `json:"filters,omitempty"`
|
||||||
|
// FoundFirewall is the state of the firewall a converged machine was found with: in force now
|
||||||
|
// or not, and how it came to be inactive — the mesh disabled it, or it was found so (ADR 0168).
|
||||||
|
FoundFirewall *FoundFirewall `json:"found_firewall,omitempty"`
|
||||||
|
|
||||||
// Profile is what the machine can do, detected again by this apply (novox/hq ADR 0161): the
|
// Profile is what the machine can do, detected again by this apply (novox/hq ADR 0161): the
|
||||||
// same shape enrolment sends, so a machine that gained or lost a capability — switched its
|
// same shape enrolment sends, so a machine that gained or lost a capability — switched its
|
||||||
// network manager — is known at its next push and not at its next enrolment. Absent from a host
|
// network manager — is known at its next push and not at its next enrolment. Absent from a host
|
||||||
@@ -278,6 +287,21 @@ type Held struct {
|
|||||||
Facts map[string]any `json:"facts,omitempty"`
|
Facts map[string]any `json:"facts,omitempty"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// A Filter is one place on a machine that refuses traffic, with its owner (novox/hq ADR 0168):
|
||||||
|
// the host's own shape, carried as data.
|
||||||
|
type Filter struct {
|
||||||
|
Where string `json:"where"`
|
||||||
|
Owner string `json:"owner"`
|
||||||
|
Refuses string `json:"refuses"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// FoundFirewall is the state of a converged machine's found firewall (ADR 0168).
|
||||||
|
type FoundFirewall struct {
|
||||||
|
Kind string `json:"kind"`
|
||||||
|
Active bool `json:"active"`
|
||||||
|
RetiredBy string `json:"retired_by,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
// A Stray is a container a machine runs that the mesh neither wrote nor holds (ADR 0163).
|
// A Stray is a container a machine runs that the mesh neither wrote nor holds (ADR 0163).
|
||||||
type Stray struct {
|
type Stray struct {
|
||||||
Kind string `json:"kind"`
|
Kind string `json:"kind"`
|
||||||
|
|||||||
Reference in New Issue
Block a user