Compare commits
16
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1a44d281c2 | ||
|
|
1c8fe65601 | ||
|
|
bea1a1c513 | ||
|
|
21d38c9b0e | ||
|
|
689dd060b0 | ||
|
|
99c4c4ef04 | ||
|
|
e5e1666f91 | ||
|
|
bd58d1c3ef | ||
|
|
d134c89a7c | ||
|
|
a9307d9f33 | ||
|
|
5eb1c9c2b7 | ||
|
|
37b8edeec6 | ||
|
|
424406b2d6 | ||
|
|
90455c61f6 | ||
|
|
1f6793cf0c | ||
|
|
6ef522fbda |
@@ -59,7 +59,7 @@ PROVISIONER_IMAGE ?= mesh-provision-postgres:$(VERSION)
|
|||||||
PROVISIONER_DEV_TAG ?= mesh-provision-postgres:development
|
PROVISIONER_DEV_TAG ?= mesh-provision-postgres:development
|
||||||
|
|
||||||
provisioner-image:
|
provisioner-image:
|
||||||
docker build -f examples/postgres-provisioner/Dockerfile \
|
docker build --build-arg GO_BASE=$(GO_BASE) -f examples/postgres-provisioner/Dockerfile \
|
||||||
-t $(PROVISIONER_IMAGE) -t $(PROVISIONER_DEV_TAG) .
|
-t $(PROVISIONER_IMAGE) -t $(PROVISIONER_DEV_TAG) .
|
||||||
@echo
|
@echo
|
||||||
@docker image inspect $(PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
@docker image inspect $(PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
||||||
@@ -70,7 +70,7 @@ OBJECTSTORE_IMAGE ?= mesh-provision-objectstore:$(VERSION)
|
|||||||
OBJECTSTORE_DEV_TAG ?= mesh-provision-objectstore:development
|
OBJECTSTORE_DEV_TAG ?= mesh-provision-objectstore:development
|
||||||
|
|
||||||
objectstore-image:
|
objectstore-image:
|
||||||
docker build -f examples/objectstore-provisioner/Dockerfile \
|
docker build --build-arg GO_BASE=$(GO_BASE) -f examples/objectstore-provisioner/Dockerfile \
|
||||||
-t $(OBJECTSTORE_IMAGE) -t $(OBJECTSTORE_DEV_TAG) .
|
-t $(OBJECTSTORE_IMAGE) -t $(OBJECTSTORE_DEV_TAG) .
|
||||||
@echo
|
@echo
|
||||||
@docker image inspect $(OBJECTSTORE_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
@docker image inspect $(OBJECTSTORE_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
||||||
@@ -81,7 +81,7 @@ REDIS_PROVISIONER_IMAGE ?= mesh-provision-redis:$(VERSION)
|
|||||||
REDIS_PROVISIONER_DEV_TAG ?= mesh-provision-redis:development
|
REDIS_PROVISIONER_DEV_TAG ?= mesh-provision-redis:development
|
||||||
|
|
||||||
redis-provisioner-image:
|
redis-provisioner-image:
|
||||||
docker build -f examples/redis-provisioner/Dockerfile \
|
docker build --build-arg GO_BASE=$(GO_BASE) -f examples/redis-provisioner/Dockerfile \
|
||||||
-t $(REDIS_PROVISIONER_IMAGE) -t $(REDIS_PROVISIONER_DEV_TAG) .
|
-t $(REDIS_PROVISIONER_IMAGE) -t $(REDIS_PROVISIONER_DEV_TAG) .
|
||||||
@echo
|
@echo
|
||||||
@docker image inspect $(REDIS_PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
@docker image inspect $(REDIS_PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
||||||
@@ -91,7 +91,7 @@ PROXY_IMAGE ?= mesh-route-proxy:$(VERSION)
|
|||||||
PROXY_DEV_TAG ?= mesh-route-proxy:development
|
PROXY_DEV_TAG ?= mesh-route-proxy:development
|
||||||
|
|
||||||
proxy-image:
|
proxy-image:
|
||||||
docker build -f examples/route-proxy/Dockerfile -t $(PROXY_IMAGE) -t $(PROXY_DEV_TAG) .
|
docker build --build-arg GO_BASE=$(GO_BASE) -f examples/route-proxy/Dockerfile -t $(PROXY_IMAGE) -t $(PROXY_DEV_TAG) .
|
||||||
@echo
|
@echo
|
||||||
@docker image inspect $(PROXY_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
@docker image inspect $(PROXY_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'
|
||||||
|
|
||||||
|
|||||||
@@ -94,6 +94,8 @@ func showFiltering(f inventory.Filtering, adopted bool) {
|
|||||||
switch {
|
switch {
|
||||||
case fw.Active:
|
case fw.Active:
|
||||||
fmt.Printf(" found firewall %s is ACTIVE on this converged machine; the next apply retires it again\n", fw.Kind)
|
fmt.Printf(" found firewall %s is ACTIVE on this converged machine; the next apply retires it again\n", fw.Kind)
|
||||||
|
case fw.RetiredBy == "removed":
|
||||||
|
fmt.Printf(" found firewall %s, removed: the mesh's filter is what filters this machine (novox/hq ADR 0180)\n", fw.Kind)
|
||||||
case fw.RetiredBy == inventory.FilterMesh || fw.RetiredBy == "mesh":
|
case fw.RetiredBy == inventory.FilterMesh || fw.RetiredBy == "mesh":
|
||||||
fmt.Printf(" found firewall %s, retired by the mesh; its configuration stays on disk\n", fw.Kind)
|
fmt.Printf(" found firewall %s, retired by the mesh; its configuration stays on disk\n", fw.Kind)
|
||||||
case fw.RetiredBy != "":
|
case fw.RetiredBy != "":
|
||||||
|
|||||||
@@ -131,10 +131,17 @@ func serve(ctx context.Context) error {
|
|||||||
|
|
||||||
// And the mesh's own verbs, as the seat this control plane holds (novox/hq ADR 0154). Served
|
// And the mesh's own verbs, as the seat this control plane holds (novox/hq ADR 0154). Served
|
||||||
// from the store's row, so what the seat declares is what is answered.
|
// from the store's row, so what the seat declares is what is answered.
|
||||||
handlers, err := seatToolHandlers()
|
handlers, behind, err := seatToolHandlers()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
if len(behind) > 0 {
|
||||||
|
// Said once, loudly, and then served anyway (novox/hq ADR 0185): the mesh keeps answering
|
||||||
|
// while whatever put an older control plane here is undone.
|
||||||
|
fmt.Printf("this control plane is behind the %s row: it cannot run %s. "+
|
||||||
|
"Those answer the reason when called; everything else is served as usual\n",
|
||||||
|
catalogue.ControllerSeatName, strings.Join(behind, ", "))
|
||||||
|
}
|
||||||
bus, isNATS := server.Bus().(link.OverNATS)
|
bus, isNATS := server.Bus().(link.OverNATS)
|
||||||
if !isNATS {
|
if !isNATS {
|
||||||
return errors.New("the mesh's verbs are served over the bus, and this control plane is not on it")
|
return errors.New("the mesh's verbs are served over the bus, and this control plane is not on it")
|
||||||
|
|||||||
@@ -48,6 +48,21 @@ func argvFor(verb string, args map[string]any) ([]string, error) {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
switch verb {
|
switch verb {
|
||||||
|
case "command":
|
||||||
|
// The generic verb: the command line as given, split as a shell would split it, with
|
||||||
|
// nothing added — the named verbs add flags a caller cannot reach; this one is the whole
|
||||||
|
// binary and says so in its description (novox/hq ADR 0154, 0175).
|
||||||
|
if err := need("command"); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
argv, err := splitCommandLine(str("command"))
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if len(argv) == 0 {
|
||||||
|
return nil, errors.New("command names no command")
|
||||||
|
}
|
||||||
|
return argv, nil
|
||||||
case "status":
|
case "status":
|
||||||
return []string{"status", "--json"}, nil
|
return []string{"status", "--json"}, nil
|
||||||
case "nodes":
|
case "nodes":
|
||||||
@@ -215,13 +230,15 @@ func runVerb(ctx context.Context, argv []string) (verbAnswer, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// seatToolHandlers are the handlers for every verb the mesh-controller seat declares, from the
|
// seatToolHandlers are the handlers for every verb the mesh-controller seat declares, from the
|
||||||
// store's row, so a verb the row does not carry is not served and a verb it carries that this binary
|
// store's row, so a verb the row does not carry is not served. A verb it carries that this binary
|
||||||
// cannot run is said at start rather than at the first call.
|
// cannot run is named at start and answers the reason when called — never a refusal to serve, which
|
||||||
func seatToolHandlers() (map[string]link.ToolHandler, error) {
|
// would take the whole control plane down for one word (novox/hq ADR 0185).
|
||||||
|
func seatToolHandlers() (map[string]link.ToolHandler, []string, error) {
|
||||||
seat, known := catalogue.SeatNamed(catalogue.ControllerSeatName)
|
seat, known := catalogue.SeatNamed(catalogue.ControllerSeatName)
|
||||||
if !known {
|
if !known {
|
||||||
return nil, fmt.Errorf("this mesh defines no %s seat", catalogue.ControllerSeatName)
|
return nil, nil, fmt.Errorf("this mesh defines no %s seat", catalogue.ControllerSeatName)
|
||||||
}
|
}
|
||||||
|
var behind []string
|
||||||
handlers := map[string]link.ToolHandler{}
|
handlers := map[string]link.ToolHandler{}
|
||||||
for _, v := range seat.Serves {
|
for _, v := range seat.Serves {
|
||||||
verb := v.Name
|
verb := v.Name
|
||||||
@@ -232,8 +249,27 @@ func seatToolHandlers() (map[string]link.ToolHandler, error) {
|
|||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
if _, err := argvFor(verb, sampleArguments(v)); err != nil {
|
if _, err := argvFor(verb, sampleArguments(v)); err != nil {
|
||||||
return nil, fmt.Errorf("the %s seat's row declares %q, which this control plane cannot run: %w",
|
// **A row ahead of this binary is not a reason to go silent.**
|
||||||
catalogue.ControllerSeatName, verb, err)
|
//
|
||||||
|
// The row is the store's and a control plane follows it (novox/hq ADR 0154), so a verb
|
||||||
|
// this build does not know means the row was widened by a newer one — the ordinary
|
||||||
|
// state of a roll-out, and of a push that put an older control plane back. Refusing to
|
||||||
|
// serve at all made that transient fatal: on 2026-10-02 one unknown verb took the whole
|
||||||
|
// mesh off the bus for ten minutes, and the way back was a human running the binary by
|
||||||
|
// hand, because the thing that would have repaired it is the thing that was down
|
||||||
|
// (novox/hq 04-ISSUES/201, ADR 0185).
|
||||||
|
//
|
||||||
|
// So the verbs this binary knows are served, and this one answers the reason instead of
|
||||||
|
// nothing: a caller gets a sentence naming the fault, and everything else keeps working
|
||||||
|
// — including the push that replaces this binary with the one whose verb it is.
|
||||||
|
behind = append(behind, verb)
|
||||||
|
reason := err
|
||||||
|
handlers[verb] = func(context.Context, json.RawMessage) (any, error) {
|
||||||
|
return nil, fmt.Errorf("%s is in this mesh's %s row and the control plane running "+
|
||||||
|
"here cannot run it: %w. It is a verb of a newer build; this one is behind",
|
||||||
|
verb, catalogue.ControllerSeatName, reason)
|
||||||
|
}
|
||||||
|
continue
|
||||||
}
|
}
|
||||||
handlers[verb] = func(ctx context.Context, raw json.RawMessage) (any, error) {
|
handlers[verb] = func(ctx context.Context, raw json.RawMessage) (any, error) {
|
||||||
args := map[string]any{}
|
args := map[string]any{}
|
||||||
@@ -249,7 +285,7 @@ func seatToolHandlers() (map[string]link.ToolHandler, error) {
|
|||||||
return runVerb(ctx, argv)
|
return runVerb(ctx, argv)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
return handlers, nil
|
return handlers, behind, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// seatTools is what `tools` answers: every seat with a protocol, and the tools each serves, from the
|
// seatTools is what `tools` answers: every seat with a protocol, and the tools each serves, from the
|
||||||
@@ -289,3 +325,57 @@ func sampleArguments(v catalogue.Verb) map[string]any {
|
|||||||
}
|
}
|
||||||
return sample
|
return sample
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// splitCommandLine splits a command line into words the way a POSIX shell does for the simple
|
||||||
|
// cases a controller command needs: spaces separate, single or double quotes group, a backslash
|
||||||
|
// escapes the next character inside double quotes or outside any. No expansion of anything.
|
||||||
|
func splitCommandLine(line string) ([]string, error) {
|
||||||
|
var words []string
|
||||||
|
var cur strings.Builder
|
||||||
|
inWord := false
|
||||||
|
quote := rune(0)
|
||||||
|
runes := []rune(line)
|
||||||
|
for i := 0; i < len(runes); i++ {
|
||||||
|
r := runes[i]
|
||||||
|
switch {
|
||||||
|
case quote == '\'':
|
||||||
|
if r == '\'' {
|
||||||
|
quote = 0
|
||||||
|
} else {
|
||||||
|
cur.WriteRune(r)
|
||||||
|
}
|
||||||
|
case quote == '"':
|
||||||
|
if r == '"' {
|
||||||
|
quote = 0
|
||||||
|
} else if r == '\\' && i+1 < len(runes) {
|
||||||
|
i++
|
||||||
|
cur.WriteRune(runes[i])
|
||||||
|
} else {
|
||||||
|
cur.WriteRune(r)
|
||||||
|
}
|
||||||
|
case r == '\'' || r == '"':
|
||||||
|
quote = r
|
||||||
|
inWord = true
|
||||||
|
case r == '\\' && i+1 < len(runes):
|
||||||
|
i++
|
||||||
|
cur.WriteRune(runes[i])
|
||||||
|
inWord = true
|
||||||
|
case r == ' ' || r == '\t' || r == '\n':
|
||||||
|
if inWord {
|
||||||
|
words = append(words, cur.String())
|
||||||
|
cur.Reset()
|
||||||
|
inWord = false
|
||||||
|
}
|
||||||
|
default:
|
||||||
|
cur.WriteRune(r)
|
||||||
|
inWord = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if quote != 0 {
|
||||||
|
return nil, fmt.Errorf("command has an unclosed %c quote", quote)
|
||||||
|
}
|
||||||
|
if inWord {
|
||||||
|
words = append(words, cur.String())
|
||||||
|
}
|
||||||
|
return words, nil
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
package main
|
package main
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"context"
|
||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
@@ -130,10 +131,13 @@ func TestActsDoNotBlockTheCall(t *testing.T) {
|
|||||||
|
|
||||||
// What `tools` answers is the seats' records, with each verb's schema.
|
// What `tools` answers is the seats' records, with each verb's schema.
|
||||||
func TestToolsAnswersTheSeatsRecords(t *testing.T) {
|
func TestToolsAnswersTheSeatsRecords(t *testing.T) {
|
||||||
handlers, err := seatToolHandlers()
|
handlers, behind, err := seatToolHandlers()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
if len(behind) != 0 {
|
||||||
|
t.Fatalf("this build cannot run %v of its own seat's verbs", behind)
|
||||||
|
}
|
||||||
if len(handlers) != len(catalogue.ControllerVerbs) {
|
if len(handlers) != len(catalogue.ControllerVerbs) {
|
||||||
t.Fatalf("%d handlers for %d verbs", len(handlers), len(catalogue.ControllerVerbs))
|
t.Fatalf("%d handlers for %d verbs", len(handlers), len(catalogue.ControllerVerbs))
|
||||||
}
|
}
|
||||||
@@ -171,3 +175,77 @@ func TestAJSONVerbsAnswerIsItsStandardOutput(t *testing.T) {
|
|||||||
t.Fatalf("stderr and stdout are both what the command said: %s", answer.Output)
|
t.Fatalf("stderr and stdout are both what the command said: %s", answer.Output)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// `command` is the generic verb: the command line as given, split as a shell would, nothing added —
|
||||||
|
// so an operator's `node account g14 jochen` is one call through the console rather than a shell on
|
||||||
|
// the control node (novox/hq ADR 0154, ADR 0175).
|
||||||
|
func TestCommandRunsTheLineAsGiven(t *testing.T) {
|
||||||
|
argv, err := argvFor("command", map[string]any{"command": "node account g14 jochen"})
|
||||||
|
if err != nil || strings.Join(argv, " ") != "node account g14 jochen" {
|
||||||
|
t.Fatalf("a plain line: %v %v", argv, err)
|
||||||
|
}
|
||||||
|
argv, err = argvFor("command", map[string]any{"command": `settings set dnsmasq '{"a": "b c"}' --node ace`})
|
||||||
|
if err != nil || len(argv) != 6 || argv[3] != `{"a": "b c"}` {
|
||||||
|
t.Fatalf("a quoted word stays one word: %q %v", argv, err)
|
||||||
|
}
|
||||||
|
argv, err = argvFor("command", map[string]any{"command": `node add "the box" --adopted`})
|
||||||
|
if err != nil || len(argv) != 4 || argv[2] != "the box" {
|
||||||
|
t.Fatalf("double quotes group: %q %v", argv, err)
|
||||||
|
}
|
||||||
|
if _, err := argvFor("command", map[string]any{"command": " "}); err == nil {
|
||||||
|
t.Fatal("an empty line was accepted")
|
||||||
|
}
|
||||||
|
if _, err := argvFor("command", map[string]any{"command": `node "unclosed`}); err == nil {
|
||||||
|
t.Fatal("an unclosed quote was accepted")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A verb in the row that this binary cannot run does not take the control plane off the bus: the
|
||||||
|
// rest are served, the unknown one answers the reason, and the start-up names it (novox/hq ADR
|
||||||
|
// 0185). One unknown word cost the mesh ten minutes of silence on 2026-10-02, recoverable only by
|
||||||
|
// a person running the binary by hand — the push that would have repaired it needs the control
|
||||||
|
// plane that was down.
|
||||||
|
func TestARowAheadOfThisBuildIsServedAnyway(t *testing.T) {
|
||||||
|
seat, known := catalogue.SeatNamed(catalogue.ControllerSeatName)
|
||||||
|
if !known {
|
||||||
|
t.Fatal("no controller seat")
|
||||||
|
}
|
||||||
|
// The row as a newer control plane would have written it: every verb this build knows, and one
|
||||||
|
// it does not.
|
||||||
|
widened := seat
|
||||||
|
widened.Serves = append(append([]catalogue.Verb{}, seat.Serves...),
|
||||||
|
catalogue.Verb{Name: "teleport", Description: "a verb from a build that does not exist yet"})
|
||||||
|
rows := catalogue.DefaultSeats()
|
||||||
|
for i := range rows {
|
||||||
|
if rows[i].Name == catalogue.ControllerSeatName {
|
||||||
|
rows[i] = widened
|
||||||
|
}
|
||||||
|
}
|
||||||
|
catalogue.UseSeats(rows)
|
||||||
|
t.Cleanup(func() { catalogue.UseSeats(catalogue.DefaultSeats()) })
|
||||||
|
|
||||||
|
handlers, behind, err := seatToolHandlers()
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("a row with one unknown verb refused to serve at all: %v", err)
|
||||||
|
}
|
||||||
|
if len(behind) != 1 || behind[0] != "teleport" {
|
||||||
|
t.Fatalf("the verbs this build cannot run were reported as %v", behind)
|
||||||
|
}
|
||||||
|
if len(handlers) != len(widened.Serves) {
|
||||||
|
t.Fatalf("%d handlers for %d verbs in the row", len(handlers), len(widened.Serves))
|
||||||
|
}
|
||||||
|
for _, known := range []string{"status", "nodes", "push"} {
|
||||||
|
if handlers[known] == nil {
|
||||||
|
t.Errorf("%s is not served although this build knows it", known)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
_, err = handlers["teleport"](context.Background(), nil)
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("the unknown verb answered as though it had run")
|
||||||
|
}
|
||||||
|
for _, want := range []string{"teleport", "cannot run it", "behind"} {
|
||||||
|
if !strings.Contains(err.Error(), want) {
|
||||||
|
t.Errorf("the answer does not say %q: %v", want, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -10,7 +10,10 @@
|
|||||||
# The client is copied from the vendor's own image rather than installed from a distribution:
|
# The client is copied from the vendor's own image rather than installed from a distribution:
|
||||||
# `apk add mc` on Alpine installs Midnight Commander, which is a different program with the same
|
# `apk add mc` on Alpine installs Midnight Commander, which is a different program with the same
|
||||||
# name, and the failure would be a provisioner that starts cleanly and cannot do anything.
|
# name, and the failure would be a provisioner that starts cleanly and cannot do anything.
|
||||||
FROM golang:1.25-alpine AS build
|
# The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the
|
||||||
|
# build machine alike; the default only serves a hand build, and matches go.mod.
|
||||||
|
ARG GO_BASE=golang:1.26-alpine
|
||||||
|
FROM ${GO_BASE} AS build
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|||||||
@@ -3,7 +3,10 @@
|
|||||||
# Built here so a machine can be given it by the mesh rather than by somebody putting a binary on
|
# Built here so a machine can be given it by the mesh rather than by somebody putting a binary on
|
||||||
# it. Static and FROM scratch for the same reason the control plane's image is: it is fetched by
|
# it. Static and FROM scratch for the same reason the control plane's image is: it is fetched by
|
||||||
# digest and run on a machine, and everything in it is something a person would have to audit.
|
# digest and run on a machine, and everything in it is something a person would have to audit.
|
||||||
FROM golang:1.25-alpine AS build
|
# The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the
|
||||||
|
# build machine alike; the default only serves a hand build, and matches go.mod.
|
||||||
|
ARG GO_BASE=golang:1.26-alpine
|
||||||
|
FROM ${GO_BASE} AS build
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|||||||
@@ -2,7 +2,10 @@
|
|||||||
#
|
#
|
||||||
# FROM scratch, like the postgres one and unlike the bucket one: it speaks the store's own wire
|
# FROM scratch, like the postgres one and unlike the bucket one: it speaks the store's own wire
|
||||||
# protocol directly and needs no client in the image.
|
# protocol directly and needs no client in the image.
|
||||||
FROM golang:1.25-alpine AS build
|
# The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the
|
||||||
|
# build machine alike; the default only serves a hand build, and matches go.mod.
|
||||||
|
ARG GO_BASE=golang:1.26-alpine
|
||||||
|
FROM ${GO_BASE} AS build
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|||||||
@@ -2,7 +2,10 @@
|
|||||||
#
|
#
|
||||||
# Static and FROM scratch like the control plane's image, and for the same reason: it is fetched
|
# Static and FROM scratch like the control plane's image, and for the same reason: it is fetched
|
||||||
# by digest and run on a machine, so everything in it is something a person would have to audit.
|
# by digest and run on a machine, so everything in it is something a person would have to audit.
|
||||||
FROM golang:1.25-alpine AS build
|
# The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the
|
||||||
|
# build machine alike; the default only serves a hand build, and matches go.mod.
|
||||||
|
ARG GO_BASE=golang:1.26-alpine
|
||||||
|
FROM ${GO_BASE} AS build
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|||||||
@@ -732,6 +732,11 @@ func handler(held *table) http.Handler {
|
|||||||
// And since a host may now be routed only on some paths, those are a third thing:
|
// And since a host may now be routed only on some paths, those are a third thing:
|
||||||
// saying "no route for this name" while listing that very name as served is a
|
// saying "no route for this name" while listing that very name as served is a
|
||||||
// contradiction an operator would have to disbelieve the proxy to get past.
|
// contradiction an operator would have to disbelieve the proxy to get past.
|
||||||
|
// **Said in the log as well as to the client.** A name this mesh does not serve, asked
|
||||||
|
// for from outside, is what a scanner does, and the machine's intrusion prevention reads
|
||||||
|
// this proxy's log for exactly that line (novox/hq ADR 0179): the address last, as the
|
||||||
|
// jail's filter expects it.
|
||||||
|
log.Printf("refused: no route for %q, asked from %s", r.Host, r.RemoteAddr)
|
||||||
w.Header().Set("Content-Type", "text/plain; charset=utf-8")
|
w.Header().Set("Content-Type", "text/plain; charset=utf-8")
|
||||||
w.WriteHeader(http.StatusNotFound)
|
w.WriteHeader(http.StatusNotFound)
|
||||||
if !hidden && held.routed(r.Host) {
|
if !hidden && held.routed(r.Host) {
|
||||||
|
|||||||
@@ -102,8 +102,11 @@ func accountHomeOf(account, home string) string {
|
|||||||
func machineInto(resource map[string]any, facts map[string]string, module string) error {
|
func machineInto(resource map[string]any, facts map[string]string, module string) error {
|
||||||
// Content, and now the path and owner too: a module that writes into a person's home names it
|
// Content, and now the path and owner too: a module that writes into a person's home names it
|
||||||
// with ${machine:account-home} and ${machine:account}, which it cannot know until assigned
|
// with ${machine:account-home} and ${machine:account}, which it cannot know until assigned
|
||||||
// (novox/hq to-be 29), the same reason its content names ${machine:address}.
|
// (novox/hq to-be 29), the same reason its content names ${machine:address}. And the name a
|
||||||
for _, field := range []string{"path", "owner", "content"} {
|
// `user` shape sets the login shell of, and the user a user-scoped unit or a process runs as:
|
||||||
|
// the shell module makes the operator's account its holder's login shell, and the desktop's
|
||||||
|
// watchers run as that account (novox/hq ADR 0176, ADR 0177) — neither can name the person.
|
||||||
|
for _, field := range []string{"path", "owner", "content", "name", "user"} {
|
||||||
s, ok := resource[field].(string)
|
s, ok := resource[field].(string)
|
||||||
if !ok {
|
if !ok {
|
||||||
continue
|
continue
|
||||||
|
|||||||
@@ -1667,6 +1667,7 @@ func ParseManifest(raw []byte) (Manifest, error) {
|
|||||||
problems = append(problems, m.undeclaredMounts()...)
|
problems = append(problems, m.undeclaredMounts()...)
|
||||||
problems = append(problems, m.unknownDirRefs()...)
|
problems = append(problems, m.unknownDirRefs()...)
|
||||||
problems = append(problems, m.unknownAccessRefs()...)
|
problems = append(problems, m.unknownAccessRefs()...)
|
||||||
|
problems = append(problems, m.jailProblems()...)
|
||||||
|
|
||||||
for i, r := range m.Resources {
|
for i, r := range m.Resources {
|
||||||
id, _ := r["id"].(string)
|
id, _ := r["id"].(string)
|
||||||
@@ -1773,6 +1774,44 @@ var facilitiesOf = map[string][]string{
|
|||||||
"virtualisation": {"/var/lib/incus/unix.socket"},
|
"virtualisation": {"/var/lib/incus/unix.socket"},
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// jailProblems is every jail this module declares that the machine's intrusion prevention would
|
||||||
|
// refuse (novox/hq ADR 0179).
|
||||||
|
//
|
||||||
|
// **Because one bad pattern stops every jail, not its own.** fail2ban expands `<HOST>` into a named
|
||||||
|
// capture group, so a pattern naming it twice is a duplicate group name, and the daemon refuses the
|
||||||
|
// whole configuration and exits — the machine keeps no bans at all, for any jail, including the one
|
||||||
|
// watching its ssh. Caught live on the control node the day this was built, where a proxy's pattern
|
||||||
|
// matched two shapes of refusal in one line. A pattern matches one shape; several shapes are several
|
||||||
|
// patterns, one per line, as fail2ban's own filters are written.
|
||||||
|
func (m Manifest) jailProblems() []string {
|
||||||
|
var problems []string
|
||||||
|
seen := map[string]bool{}
|
||||||
|
for _, j := range m.Jails {
|
||||||
|
switch {
|
||||||
|
case strings.TrimSpace(j.Name) == "":
|
||||||
|
problems = append(problems, m.Module+" declares a jail with no name")
|
||||||
|
case seen[j.Name]:
|
||||||
|
problems = append(problems, m.Module+" declares two jails called "+strconv.Quote(j.Name))
|
||||||
|
}
|
||||||
|
seen[j.Name] = true
|
||||||
|
if strings.TrimSpace(j.Failregex) == "" {
|
||||||
|
problems = append(problems, m.Module+"'s jail "+strconv.Quote(j.Name)+" says nothing a failed attempt looks like")
|
||||||
|
}
|
||||||
|
for _, line := range strings.Split(j.Failregex, "\n") {
|
||||||
|
if strings.TrimSpace(line) == "" {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if n := strings.Count(line, "<HOST>"); n > 1 {
|
||||||
|
problems = append(problems, fmt.Sprintf("%s's jail %s names <HOST> %d times in one pattern; "+
|
||||||
|
"fail2ban reads it as one capture group and refuses the whole configuration, so the machine "+
|
||||||
|
"keeps no bans at all — write one pattern per shape, each naming <HOST> once",
|
||||||
|
m.Module, strconv.Quote(j.Name), n))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return problems
|
||||||
|
}
|
||||||
|
|
||||||
// undeclaredMounts is every bind-mount source no declaration covers — see the check above.
|
// undeclaredMounts is every bind-mount source no declaration covers — see the check above.
|
||||||
func (m Manifest) undeclaredMounts() []string {
|
func (m Manifest) undeclaredMounts() []string {
|
||||||
declared := map[string]bool{}
|
declared := map[string]bool{}
|
||||||
|
|||||||
@@ -0,0 +1,60 @@
|
|||||||
|
package catalogue
|
||||||
|
|
||||||
|
import (
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// A `user` shape and a user-scoped unit name the operator account the way a home file does
|
||||||
|
// (novox/hq ADR 0176, ADR 0177): with ${machine:account}, resolved when the module is assigned.
|
||||||
|
func TestAUserShapeAndAUserScopedUnitNameTheAccount(t *testing.T) {
|
||||||
|
facts := map[string]string{"account": "ops", "account-home": "/home/ops"}
|
||||||
|
login := map[string]any{"type": "user", "id": "login", "name": "${machine:account}", "shell": "/usr/bin/zsh"}
|
||||||
|
if err := machineInto(login, facts, "zsh"); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if login["name"] != "ops" {
|
||||||
|
t.Fatalf("the user shape did not learn the account: %v", login["name"])
|
||||||
|
}
|
||||||
|
watcher := map[string]any{"type": "service", "id": "watcher", "unit": "i3-reload-watcher.service",
|
||||||
|
"scope": "user", "user": "${machine:account}"}
|
||||||
|
if err := machineInto(watcher, facts, "i3"); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if watcher["user"] != "ops" {
|
||||||
|
t.Fatalf("the user-scoped unit did not learn the account: %v", watcher["user"])
|
||||||
|
}
|
||||||
|
// A machine with no operator account refuses rather than writing the literal.
|
||||||
|
err := machineInto(map[string]any{"type": "user", "id": "login", "name": "${machine:account}"},
|
||||||
|
map[string]string{"address": "10.0.0.1"}, "zsh")
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "${machine:account}") {
|
||||||
|
t.Fatalf("a user shape on a machine with no account was not refused by name: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// The service manager is a seat of the mesh's own with the unit verbs as its contract (novox/hq
|
||||||
|
// ADR 0177): every verb described, with a schema, taking a scope.
|
||||||
|
func TestTheServiceManagerSeatServesTheUnitVerbs(t *testing.T) {
|
||||||
|
seat, ok := SeatNamed("node-service-manager")
|
||||||
|
if !ok {
|
||||||
|
t.Fatal("node-service-manager is not a seat the mesh defines")
|
||||||
|
}
|
||||||
|
if seat.Scope != ScopeNode {
|
||||||
|
t.Fatalf("the service manager is a role each machine has once, and the seat is %s-scoped", seat.Scope)
|
||||||
|
}
|
||||||
|
want := []string{"units", "status", "start", "stop", "restart", "enable", "disable", "journal"}
|
||||||
|
var got []string
|
||||||
|
for _, v := range seat.Serves {
|
||||||
|
got = append(got, v.Name)
|
||||||
|
if v.Description == "" || v.Input == nil {
|
||||||
|
t.Fatalf("%s is promised without a description or a schema", v.Name)
|
||||||
|
}
|
||||||
|
props, _ := v.Input["properties"].(map[string]any)
|
||||||
|
if _, has := props["scope"]; !has {
|
||||||
|
t.Fatalf("%s takes no scope, and a user unit could not be asked for", v.Name)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if strings.Join(got, ",") != strings.Join(want, ",") {
|
||||||
|
t.Fatalf("the seat serves %v, not %v", got, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -99,7 +99,23 @@ var defaultSeats = []Seat{
|
|||||||
{Name: "mesh-build-machine", Scope: ScopeMesh,
|
{Name: "mesh-build-machine", Scope: ScopeMesh,
|
||||||
Accepts: []string{"build"}, Emits: []string{"started", "built", "log.*"}, Decision: "novox/hq ADR 0121"},
|
Accepts: []string{"build"}, Emits: []string{"started", "built", "log.*"}, Decision: "novox/hq ADR 0121"},
|
||||||
{Name: "node-dns-resolver", Scope: ScopeNode, Decision: "novox/hq ADR 0121"},
|
{Name: "node-dns-resolver", Scope: ScopeNode, Decision: "novox/hq ADR 0121"},
|
||||||
{Name: "node-intrusion-prevention", Scope: ScopeNode, Decision: "novox/hq ADR 0121"},
|
// The intrusion prevention's verbs (novox/hq ADR 0179): what a person asks a machine's ban list
|
||||||
|
// whatever keeps it — who is banned and why, ban one address, let one go. Every holder serves all
|
||||||
|
// four; the jails themselves are composed from the modules the machine runs (to-be 31).
|
||||||
|
{Name: "node-intrusion-prevention", Scope: ScopeNode, Decision: "novox/hq ADR 0121",
|
||||||
|
Serves: []Verb{
|
||||||
|
{Name: "status", Description: "Every jail on this machine with how many it is watching and " +
|
||||||
|
"holding now, and the totals since the jail started; one jail's detail when named.",
|
||||||
|
Input: schema(map[string]string{"jail": "one jail (optional)"}, nil)},
|
||||||
|
{Name: "banned", Description: "Every address banned on this machine right now, with the jail " +
|
||||||
|
"that holds it and when the ban ends.",
|
||||||
|
Input: schema(map[string]string{"jail": "one jail (optional)"}, nil)},
|
||||||
|
{Name: "ban", Description: "Ban one address in one jail now, for the jail's ban time — an " +
|
||||||
|
"operator's act on the live ban list, which the mesh never writes itself.",
|
||||||
|
Input: schema(map[string]string{"ip": "the address", "jail": "the jail to hold it"}, []string{"ip", "jail"})},
|
||||||
|
{Name: "unban", Description: "Let one address go, from one jail or from every jail when none is named.",
|
||||||
|
Input: schema(map[string]string{"ip": "the address", "jail": "one jail (optional)"}, []string{"ip"})},
|
||||||
|
}},
|
||||||
// The packet filter's verbs (novox/hq ADR 0170): what a person asks a machine's filter whatever
|
// The packet filter's verbs (novox/hq ADR 0170): what a person asks a machine's filter whatever
|
||||||
// filter answers — the rules as enforced, reload the mesh's own, remove one thing the mesh did
|
// filter answers — the rules as enforced, reload the mesh's own, remove one thing the mesh did
|
||||||
// not write. Every holder serves all three; what differs by filter is the holder's own tools.
|
// not write. Every holder serves all three; what differs by filter is the holder's own tools.
|
||||||
@@ -119,6 +135,12 @@ var defaultSeats = []Seat{
|
|||||||
"active found firewall's chains. An operator's act, by name, never a flush.",
|
"active found firewall's chains. An operator's act, by name, never a flush.",
|
||||||
Input: schema(map[string]string{"where": "the rule set, as `node show` lists it"}, []string{"where"})},
|
Input: schema(map[string]string{"where": "the rule set, as `node show` lists it"}, []string{"where"})},
|
||||||
}},
|
}},
|
||||||
|
// The machine's service manager (novox/hq ADR 0177). The host applies every declared unit,
|
||||||
|
// system or user scope; the holder answers questions and operator acts about them, each verb
|
||||||
|
// taking the unit and an optional scope. The holder runs nothing of its own: its verbs are
|
||||||
|
// served by the node tools runtime (ADR 0175).
|
||||||
|
{Name: "node-service-manager", Scope: ScopeNode, Decision: "novox/hq ADR 0177",
|
||||||
|
Serves: serviceManagerVerbs()},
|
||||||
// Deferred (novox/hq ADR 0121): renaming to mesh-private-network is a scope + server/client
|
// Deferred (novox/hq ADR 0121): renaming to mesh-private-network is a scope + server/client
|
||||||
// model change, not a rename, so it stays until that is built.
|
// model change, not a rename, so it stays until that is built.
|
||||||
{Name: "the-private-network", Scope: ScopeNode, Decision: "novox/hq ADR 0110"},
|
{Name: "the-private-network", Scope: ScopeNode, Decision: "novox/hq ADR 0110"},
|
||||||
@@ -392,3 +414,36 @@ func SeatsWithAProtocol() []Seat {
|
|||||||
}
|
}
|
||||||
return out
|
return out
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// serviceManagerVerbs is the contract every holder of node-service-manager serves (novox/hq ADR
|
||||||
|
// 0177): the units on the machine in both scopes, read and acted on by name. Every verb takes an
|
||||||
|
// optional scope — "system" when absent, "user" for the operator account's own manager — so a
|
||||||
|
// caller asks for a user unit the way it asks for a system one.
|
||||||
|
func serviceManagerVerbs() []Verb {
|
||||||
|
scoped := func(more map[string]string, required []string) map[string]any {
|
||||||
|
props := map[string]string{"scope": "\"system\" (the default) or \"user\": the operator account's own manager"}
|
||||||
|
for k, v := range more {
|
||||||
|
props[k] = v
|
||||||
|
}
|
||||||
|
return schema(props, required)
|
||||||
|
}
|
||||||
|
unit := map[string]string{"unit": "the unit's name, as the service manager knows it"}
|
||||||
|
return []Verb{
|
||||||
|
{Name: "units", Description: "The units the service manager knows in a scope, each with its load, active and sub state; narrowed to a pattern when asked.",
|
||||||
|
Input: scoped(map[string]string{"pattern": "a glob the unit's name must match (optional)"}, nil)},
|
||||||
|
{Name: "status", Description: "One unit as the service manager sees it now: its states, whether it starts at boot, its main process, and whether the mesh declares it.",
|
||||||
|
Input: scoped(unit, []string{"unit"})},
|
||||||
|
{Name: "start", Description: "Start one unit. For a unit the mesh declares, the answer says the host will restore what its declaration says at the next apply.",
|
||||||
|
Input: scoped(unit, []string{"unit"})},
|
||||||
|
{Name: "stop", Description: "Stop one unit; for a mesh-declared unit the answer says the host will restore its declared state.",
|
||||||
|
Input: scoped(unit, []string{"unit"})},
|
||||||
|
{Name: "restart", Description: "Restart one unit.",
|
||||||
|
Input: scoped(unit, []string{"unit"})},
|
||||||
|
{Name: "enable", Description: "Make one unit start at boot (or at the account's login, in user scope).",
|
||||||
|
Input: scoped(unit, []string{"unit"})},
|
||||||
|
{Name: "disable", Description: "Stop one unit starting at boot (or at login, in user scope).",
|
||||||
|
Input: scoped(unit, []string{"unit"})},
|
||||||
|
{Name: "journal", Description: "The last lines of one unit's journal.",
|
||||||
|
Input: scoped(map[string]string{"unit": unit["unit"], "lines": "how many lines from the end (default 100)"}, []string{"unit"})},
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -44,8 +44,9 @@ func TestTheSeatsAreAClosedSetAndEachNamesItsDecision(t *testing.T) {
|
|||||||
delivered[s.Delivers] = s.Name
|
delivered[s.Delivers] = s.Name
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if len(Seats()) != 15 {
|
// Sixteen since node-service-manager (novox/hq ADR 0177).
|
||||||
t.Errorf("the mesh defines %d seats rather than 14; the set is closed, so a change here is "+
|
if len(Seats()) != 16 {
|
||||||
|
t.Errorf("the mesh defines %d seats rather than 16; the set is closed, so a change here is "+
|
||||||
"a decision (novox/hq ADR 0110): %s", len(Seats()), seatNames())
|
"a decision (novox/hq ADR 0110): %s", len(Seats()), seatNames())
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -145,6 +145,13 @@ var ControllerVerbs = []Verb{
|
|||||||
"node": "one machine; the whole mesh when absent",
|
"node": "one machine; the whole mesh when absent",
|
||||||
"clear": "\"true\" to remove the layer instead of setting it",
|
"clear": "\"true\" to remove the layer instead of setting it",
|
||||||
}, []string{"module"})},
|
}, []string{"module"})},
|
||||||
|
{Name: "command", Description: "Run one command line of the controller's own, as you would type it at its " +
|
||||||
|
"shell — `node account g14 jochen`, `node show ace`, `module list` — and answer what it printed. The " +
|
||||||
|
"generic verb beside the named ones (novox/hq ADR 0154): everything the binary can do, without a verb " +
|
||||||
|
"per command. Any node may call any tool (ADR 0175), so nothing is held back here.",
|
||||||
|
Input: schema(map[string]string{
|
||||||
|
"command": "the command line, as the controller's binary takes it; quotes group a word with spaces",
|
||||||
|
}, []string{"command"})},
|
||||||
{Name: "build", Description: "Have the build machine build a repository. Answers at once with the build's id: " +
|
{Name: "build", Description: "Have the build machine build a repository. Answers at once with the build's id: " +
|
||||||
"`builds` with that id follows it line by line, and the module is registered when the outcome comes.",
|
"`builds` with that id follows it line by line, and the module is registered when the outcome comes.",
|
||||||
Input: schema(map[string]string{
|
Input: schema(map[string]string{
|
||||||
|
|||||||
Reference in New Issue
Block a user