Compare commits
31
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9fe9b5349c | ||
|
|
c5dc7e732a | ||
|
|
7efcccd013 | ||
|
|
964285f08c | ||
|
|
5698dda11f | ||
|
|
6005a8471f | ||
|
|
e2ee0dfe98 | ||
|
|
70341cfbc7 | ||
|
|
77643aa3f4 | ||
|
|
1fd6194ff8 | ||
|
|
c37018fdd2 | ||
|
|
3907ea0db0 | ||
|
|
40f5e9a41c | ||
|
|
2c2eb51878 | ||
|
|
aa2d0b51ea | ||
|
|
64d154d9d7 | ||
|
|
ffa390f916 | ||
|
|
4d62e6caf1 | ||
|
|
386ae676ca | ||
|
|
f8a9c3d6bc | ||
|
|
83671fae5f | ||
|
|
9b715524a2 | ||
|
|
e06fc1ed16 | ||
|
|
13d7c5c5dd | ||
|
|
7b02feaebb | ||
|
|
bd10e2c695 | ||
|
|
4b209d944d | ||
|
|
84024cbdb6 | ||
|
|
ad2eed2f71 | ||
|
|
e8aa7ed9e7 | ||
|
|
337aaea123 |
@@ -135,6 +135,16 @@ func run() error {
|
|||||||
// machine told about both would take work from one and answer on the other, and every log line would
|
// machine told about both would take work from one and answer on the other, and every log line would
|
||||||
// say it was fine.
|
// say it was fine.
|
||||||
func takeWorkFrom(credential Credential, on string) (link.BuildMachine, error) {
|
func takeWorkFrom(credential Credential, on string) (link.BuildMachine, error) {
|
||||||
|
// **The credential decides, before any variable does.** A machine moved to the new bus was
|
||||||
|
// handed a credential for it and nothing else changed in its environment; that credential
|
||||||
|
// names the bus by scheme, so it is enough to know which bus to take work from.
|
||||||
|
if credential.onTheNewBus() {
|
||||||
|
js, err := broker.DialPinned(credential.natsURL(), credential.Fingerprint)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return link.MachineOverNATS(js, on), nil
|
||||||
|
}
|
||||||
address, onNATS, err := broker.OnNATS()
|
address, onNATS, err := broker.OnNATS()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
@@ -460,10 +470,26 @@ func brokerFrom() (Credential, error) {
|
|||||||
// **The same shape a node gets, for the same reason** (novox/hq ADR 0004): the fingerprint travels
|
// **The same shape a node gets, for the same reason** (novox/hq ADR 0004): the fingerprint travels
|
||||||
// out of band — here, sealed with the credential — and the endpoint is verified once at connect.
|
// out of band — here, sealed with the credential — and the endpoint is verified once at connect.
|
||||||
type Credential struct {
|
type Credential struct {
|
||||||
URL string `json:"url"`
|
URL string `json:"url"`
|
||||||
// Fingerprint is SHA-256 over the broker certificate's DER bytes, or empty to verify the
|
|
||||||
// ordinary way.
|
|
||||||
Fingerprint string `json:"fingerprint,omitempty"`
|
Fingerprint string `json:"fingerprint,omitempty"`
|
||||||
|
// User and Password ride beside the address on the bus being built (design 25): a credential
|
||||||
|
// embedded in a URL leaks into every log line that prints a connection, so the mesh seals them
|
||||||
|
// as two fields and this machine joins them once, here, to dial.
|
||||||
|
User string `json:"user,omitempty"`
|
||||||
|
Password string `json:"password,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// onTheNewBus is whether a credential is for the bus being built: its address says so, and the
|
||||||
|
// mesh only ever seals such a credential with the user and password beside it.
|
||||||
|
func (c Credential) onTheNewBus() bool { return strings.HasPrefix(strings.TrimSpace(c.URL), "nats://") }
|
||||||
|
|
||||||
|
// natsURL is the address with this machine's credential in it, for the one dial that needs it.
|
||||||
|
func (c Credential) natsURL() string {
|
||||||
|
rest := strings.TrimPrefix(strings.TrimSpace(c.URL), "nats://")
|
||||||
|
if c.User == "" {
|
||||||
|
return "nats://" + rest
|
||||||
|
}
|
||||||
|
return "nats://" + c.User + ":" + c.Password + "@" + rest
|
||||||
}
|
}
|
||||||
|
|
||||||
// dial opens the connection, pinning the broker's certificate when there is one to pin.
|
// dial opens the connection, pinning the broker's certificate when there is one to pin.
|
||||||
|
|||||||
@@ -14,8 +14,8 @@ func TestBuilderDiagnosticsStayOffStdout(t *testing.T) {
|
|||||||
allowed := map[string]bool{
|
allowed := map[string]bool{
|
||||||
"string(body)": true, // once.go: the result JSON, which IS stdout
|
"string(body)": true, // once.go: the result JSON, which IS stdout
|
||||||
"version)": true, // --version
|
"version)": true, // --version
|
||||||
`"stopping")`: true, // the loop.s shutdown line
|
`"stopping")`: true, // the loop.s shutdown line
|
||||||
"usage)": true, // --help text, for a human
|
"usage)": true, // --help text, for a human
|
||||||
}
|
}
|
||||||
for _, file := range []string{"once.go", "main.go"} {
|
for _, file := range []string{"once.go", "main.go"} {
|
||||||
src, err := os.ReadFile(file)
|
src, err := os.ReadFile(file)
|
||||||
|
|||||||
@@ -37,7 +37,7 @@ func askCommand(ctx context.Context, args []string) error {
|
|||||||
arguments = json.RawMessage(positionals[2])
|
arguments = json.RawMessage(positionals[2])
|
||||||
}
|
}
|
||||||
|
|
||||||
server, err := link.Connect(nil, nil)
|
server, err := connectLink(ctx, nil, nil, nil)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -368,7 +368,7 @@ func buildOne(ctx context.Context, source buildSource, path, ref string, wait ti
|
|||||||
}
|
}
|
||||||
defer ident.Close()
|
defer ident.Close()
|
||||||
|
|
||||||
server, err := link.Connect(nil, nil)
|
server, err := connectLink(ctx, nil, nil, nil)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -472,7 +472,7 @@ func buildAndShow(ctx context.Context, source buildSource, path, ref string, wai
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
defer ident.Close()
|
defer ident.Close()
|
||||||
server, err := link.Connect(nil, nil)
|
server, err := connectLink(ctx, nil, nil, nil)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -614,6 +614,15 @@ func issueOnTheNewBus(ctx context.Context, inv *inventory.Inventory, m catalogue
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
return issueWith(ctx, inv, m, node, busAddress, known, reachable, user, password)
|
||||||
|
}
|
||||||
|
|
||||||
|
// issueWith is the delivery half: the minted password sealed to the machine as the module's broker
|
||||||
|
// secret, and the module's consumer created where the bus can be reached. Split from the minting
|
||||||
|
// so the move can issue every module against a bus whose address it worked out itself
|
||||||
|
// (`rollout mint`, design 28 task 5.2) rather than the one in this process's environment.
|
||||||
|
func issueWith(ctx context.Context, inv *inventory.Inventory, m catalogue.Manifest,
|
||||||
|
node, busAddress string, known broker.Broker, reachable, user, password string) error {
|
||||||
held, err := json.Marshal(struct {
|
held, err := json.Marshal(struct {
|
||||||
URL string `json:"url"`
|
URL string `json:"url"`
|
||||||
Fingerprint string `json:"fingerprint,omitempty"`
|
Fingerprint string `json:"fingerprint,omitempty"`
|
||||||
@@ -639,14 +648,19 @@ func issueOnTheNewBus(ctx context.Context, inv *inventory.Inventory, m catalogue
|
|||||||
Kind: broker.KindModule, Node: node, Module: m.Module,
|
Kind: broker.KindModule, Node: node, Module: m.Module,
|
||||||
Emits: m.Emits, Consumes: m.Consumes, Serves: m.Tools,
|
Emits: m.Emits, Consumes: m.Consumes, Serves: m.Tools,
|
||||||
}); needed {
|
}); needed {
|
||||||
js, err := broker.Dial(busAddress)
|
if busAddress == "" {
|
||||||
if err != nil {
|
fmt.Printf(" %s consumes; its consumer is created when the bus is reachable (`push`, then "+
|
||||||
return fmt.Errorf("the credential is minted and the mesh cannot reach the bus to create "+
|
"`rollout mint` again is harmless)\n", m.Module)
|
||||||
"how %s hears what it consumes: %w", m.Module, err)
|
} else {
|
||||||
}
|
js, err := broker.Dial(busAddress)
|
||||||
defer js.Close()
|
if err != nil {
|
||||||
if err := js.EnsureConsumer(consumer); err != nil {
|
return fmt.Errorf("the credential is minted and the mesh cannot reach the bus to create "+
|
||||||
return err
|
"how %s hears what it consumes: %w", m.Module, err)
|
||||||
|
}
|
||||||
|
defer js.Close()
|
||||||
|
if err := js.EnsureConsumer(consumer); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -537,6 +537,15 @@ func onTheNetwork(ctx context.Context, inv *inventory.Inventory,
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
// **With the seat holders on record**, or a machine running the next holder of a seat beside
|
||||||
|
// the current one resolves as two holders, is refused, and drops out of the map — taking the
|
||||||
|
// address every other machine composes for what it offers (novox/hq ADR 0131). Found live:
|
||||||
|
// the control node vanished from the private network the moment the new bus was assigned
|
||||||
|
// beside the old one.
|
||||||
|
holdings, err := inv.Holdings(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
var out []inventory.Overlay
|
var out []inventory.Overlay
|
||||||
for _, p := range places {
|
for _, p := range places {
|
||||||
if p.Address == "" {
|
if p.Address == "" {
|
||||||
@@ -549,7 +558,7 @@ func onTheNetwork(ctx context.Context, inv *inventory.Inventory,
|
|||||||
caps, _ := inv.ProfileOf(ctx, p.Name)
|
caps, _ := inv.ProfileOf(ctx, p.Name)
|
||||||
got, err := catalogue.Resolve(shelf, assigned,
|
got, err := catalogue.Resolve(shelf, assigned,
|
||||||
catalogue.Node{Name: p.Name, Site: p.Site, Capabilities: caps},
|
catalogue.Node{Name: p.Name, Site: p.Site, Capabilities: caps},
|
||||||
catalogue.World{Unchecked: true})
|
catalogue.World{Unchecked: true, Holdings: holdings})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -636,8 +636,13 @@ func renderingFor(ctx context.Context, open *stores, node string,
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return catalogue.Rendering{}, inventory.Node{}, err
|
return catalogue.Rendering{}, inventory.Node{}, err
|
||||||
}
|
}
|
||||||
|
memberships, err := inv.BusMemberships(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return catalogue.Rendering{}, inventory.Node{}, err
|
||||||
|
}
|
||||||
return catalogue.Rendering{
|
return catalogue.Rendering{
|
||||||
Settings: settings, Generators: gens, Grants: grants, Needed: needed, Ports: ports,
|
BusMembership: memberships[node],
|
||||||
|
Settings: settings, Generators: gens, Grants: grants, Needed: needed, Ports: ports,
|
||||||
Certificate: certificate, Authority: authority, Mesh: private, Names: names,
|
Certificate: certificate, Authority: authority, Mesh: private, Names: names,
|
||||||
Machines: machines,
|
Machines: machines,
|
||||||
Suffix: overlay.Suffix(), MeshRange: meshRange, Accounts: accounts, Foundation: foundation,
|
Suffix: overlay.Suffix(), MeshRange: meshRange, Accounts: accounts, Foundation: foundation,
|
||||||
|
|||||||
+80
-16
@@ -38,6 +38,33 @@ func reportUnhostable(node string, plan catalogue.Resolution) {
|
|||||||
// nothing in it was wrong, and no one edit was the one that should have been a new file.
|
// nothing in it was wrong, and no one edit was the one that should have been a new file.
|
||||||
|
|
||||||
// serve is the control plane running: one connection to the broker, one queue, one consumer.
|
// serve is the control plane running: one connection to the broker, one queue, one consumer.
|
||||||
|
// connectLink opens the controller's link over whichever bus this process is on (design 25: one
|
||||||
|
// variable moves it). The streams and this controller's consumers are raised first on the new bus,
|
||||||
|
// so nothing served here finds them missing.
|
||||||
|
func connectLink(ctx context.Context, inv *inventory.Inventory, enroller link.Enroller, listener link.Listener) (*link.Server, error) {
|
||||||
|
busAddress, onNATS, err := broker.OnNATS()
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if err := broker.MustBeOneBus(os.Getenv(broker.AMQPVarName), busAddress); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if !onNATS {
|
||||||
|
return link.Connect(enroller, listener)
|
||||||
|
}
|
||||||
|
if inv != nil {
|
||||||
|
if err := raiseTheBus(ctx, inv, busAddress); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
js, err := broker.Dial(busAddress)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("the mesh is on the bus at %s and this control plane cannot reach it: %w",
|
||||||
|
broker.BareAddress(busAddress), err)
|
||||||
|
}
|
||||||
|
return link.ConnectNats(js, enroller, listener), nil
|
||||||
|
}
|
||||||
|
|
||||||
func serve(ctx context.Context) error {
|
func serve(ctx context.Context) error {
|
||||||
open, err := openStores(ctx)
|
open, err := openStores(ctx)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -90,7 +117,7 @@ func serve(ctx context.Context) error {
|
|||||||
|
|
||||||
work := link.Enrolment{Inventory: inv, Identity: ident, Management: management, Broker: known,
|
work := link.Enrolment{Inventory: inv, Identity: ident, Management: management, Broker: known,
|
||||||
OnNATS: onNATS}
|
OnNATS: onNATS}
|
||||||
server, err := link.Connect(work, work)
|
server, err := connectLink(ctx, inv, work, work)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -100,11 +127,6 @@ func serve(ctx context.Context) error {
|
|||||||
// somebody deleted, a mesh raised from a restored backup, or a bus whose data directory was
|
// somebody deleted, a mesh raised from a restored backup, or a bus whose data directory was
|
||||||
// replaced all have records and no objects — and a node whose consumer is missing hears nothing
|
// replaced all have records and no objects — and a node whose consumer is missing hears nothing
|
||||||
// while everything else about it looks correct.
|
// while everything else about it looks correct.
|
||||||
if onNATS {
|
|
||||||
if err := raiseTheBus(ctx, inv, busAddress); err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
// And build results nobody was waiting for. A build triggered any other way than `build`
|
// And build results nobody was waiting for. A build triggered any other way than `build`
|
||||||
// would otherwise be reported into the void, which is the same as not reporting it.
|
// would otherwise be reported into the void, which is the same as not reporting it.
|
||||||
server.Records(builds{inv})
|
server.Records(builds{inv})
|
||||||
@@ -158,13 +180,13 @@ func declare(ctx context.Context, args []string) error {
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
server, err := link.Connect(nil, nil)
|
server, err := connectLink(ctx, nil, nil, nil)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
defer server.Close()
|
defer server.Close()
|
||||||
|
|
||||||
if err := link.Declare(ctx, link.OverCurrent{Channel: server.Channel()}, ident, node, raw, 15*time.Second); err != nil {
|
if err := link.Declare(ctx, server.Bus(), ident, node, raw, 15*time.Second); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
fmt.Printf("sent %s a signed declaration (%d bytes)\n", node, len(raw))
|
fmt.Printf("sent %s a signed declaration (%d bytes)\n", node, len(raw))
|
||||||
@@ -271,7 +293,7 @@ func pushCommand(ctx context.Context, args []string) error {
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
server, err := link.Connect(nil, nil)
|
server, err := connectLink(ctx, nil, nil, nil)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -332,7 +354,7 @@ func pushCommand(ctx context.Context, args []string) error {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
if err := link.Declare(ctx, link.OverCurrent{Channel: server.Channel()}, ident, s.node, body, 15*time.Second); err != nil {
|
if err := link.Declare(ctx, server.Bus(), ident, s.node, body, 15*time.Second); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
// After it is away, not before. A digest recorded for something that failed to send would
|
// After it is away, not before. A digest recorded for something that failed to send would
|
||||||
@@ -415,7 +437,7 @@ func pushCommand(ctx context.Context, args []string) error {
|
|||||||
return declarationWith(held, open, node, plan, settings, gens, Allocating)
|
return declarationWith(held, open, node, plan, settings, gens, Allocating)
|
||||||
},
|
},
|
||||||
func(s readyNode, body []byte) error {
|
func(s readyNode, body []byte) error {
|
||||||
if err := link.Declare(ctx, link.OverCurrent{Channel: server.Channel()}, ident, s.node, body,
|
if err := link.Declare(ctx, server.Bus(), ident, s.node, body,
|
||||||
15*time.Second); err != nil {
|
15*time.Second); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -628,7 +650,7 @@ func sendTo(ctx context.Context, open *stores, names []string) error {
|
|||||||
len(refusals), strings.Join(refusals, "\n\n"))
|
len(refusals), strings.Join(refusals, "\n\n"))
|
||||||
}
|
}
|
||||||
|
|
||||||
server, err := link.Connect(nil, nil)
|
server, err := connectLink(ctx, nil, nil, nil)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -639,7 +661,7 @@ func sendTo(ctx context.Context, open *stores, names []string) error {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
if err := link.Declare(ctx, link.OverCurrent{Channel: server.Channel()}, ident, s.node, body, 15*time.Second); err != nil {
|
if err := link.Declare(ctx, server.Bus(), ident, s.node, body, 15*time.Second); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
record, err := inv.NodeByName(ctx, s.node)
|
record, err := inv.NodeByName(ctx, s.node)
|
||||||
@@ -704,7 +726,7 @@ func raiseTheBus(ctx context.Context, inv *inventory.Inventory, address string)
|
|||||||
js, err := broker.Dial(address)
|
js, err := broker.Dial(address)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("the mesh is on the bus at %s and this control plane cannot reach it: %w",
|
return fmt.Errorf("the mesh is on the bus at %s and this control plane cannot reach it: %w",
|
||||||
address, err)
|
broker.BareAddress(address), err)
|
||||||
}
|
}
|
||||||
defer js.Close()
|
defer js.Close()
|
||||||
|
|
||||||
@@ -739,10 +761,52 @@ func raiseTheBus(ctx context.Context, inv *inventory.Inventory, address string)
|
|||||||
// The work queues of the mesh's own roles (novox/hq ADR 0121). The queue before the holder,
|
// The work queues of the mesh's own roles (novox/hq ADR 0121). The queue before the holder,
|
||||||
// deliberately: work queues until somebody arrives to do it, so assigning a build machine a week
|
// deliberately: work queues until somebody arrives to do it, so assigning a build machine a week
|
||||||
// after something started asking for builds flushes the backlog instead of having lost it.
|
// after something started asking for builds flushes the backlog instead of having lost it.
|
||||||
if err := broker.RaiseSeats(js, inventory.MeshSeats(), nil); err != nil {
|
// With the seats' holders, so each role's work queue gets the consumer its holder takes
|
||||||
|
// work from. Passed as nil until the first live raise, which left the build machine bound to a
|
||||||
|
// consumer nothing had created (2026-09-28).
|
||||||
|
holders, err := seatHolders(ctx, inv)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if err := broker.RaiseSeats(js, inventory.MeshSeats(), holders); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
fmt.Printf("the bus at %s has its streams, and %d machine(s) can hear a declaration\n",
|
fmt.Printf("the bus at %s has its streams, and %d machine(s) can hear a declaration\n",
|
||||||
address, len(names))
|
broker.BareAddress(address), len(names))
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// seatHolders is who holds each of the mesh's seats, by seat name: the record where a handover
|
||||||
|
// wrote one, and the assigned module claiming the seat otherwise — the same derivation the
|
||||||
|
// resolver makes, read from the catalogue rather than re-resolved.
|
||||||
|
func seatHolders(ctx context.Context, inv *inventory.Inventory) (map[string]broker.Holder, error) {
|
||||||
|
out := map[string]broker.Holder{}
|
||||||
|
entries, err := inv.Catalogued(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
for _, e := range entries {
|
||||||
|
if len(e.On) == 0 {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
for _, c := range e.Manifest.Claims {
|
||||||
|
seat, known := catalogue.SeatNamed(c.Name)
|
||||||
|
if !known {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if _, taken := out[seat.Name]; !taken {
|
||||||
|
out[seat.Name] = broker.Holder{Node: e.On[0], Module: e.Manifest.Module}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
recorded, err := inv.Holdings(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
for _, h := range recorded {
|
||||||
|
if seat, known := catalogue.SeatNamed(h.Claim); known {
|
||||||
|
out[seat.Name] = broker.Holder{Node: h.Node, Module: h.Module}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return out, nil
|
||||||
|
}
|
||||||
|
|||||||
@@ -2,8 +2,10 @@ package main
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"encoding/json"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"os"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
@@ -12,6 +14,7 @@ import (
|
|||||||
"github.com/novox/mesh-controller/internal/broker"
|
"github.com/novox/mesh-controller/internal/broker"
|
||||||
"github.com/novox/mesh-controller/internal/catalogue"
|
"github.com/novox/mesh-controller/internal/catalogue"
|
||||||
"github.com/novox/mesh-controller/internal/inventory"
|
"github.com/novox/mesh-controller/internal/inventory"
|
||||||
|
"github.com/novox/mesh-controller/internal/secrets"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Moving the mesh's own traffic to the bus being built (novox/hq ADR 0116 step 5).
|
// Moving the mesh's own traffic to the bus being built (novox/hq ADR 0116 step 5).
|
||||||
@@ -31,12 +34,21 @@ import (
|
|||||||
// ability to change things, not the services its modules are serving — measured on 2026-09-27, when
|
// ability to change things, not the services its modules are serving — measured on 2026-09-27, when
|
||||||
// a seat emptied mid-change and the control plane looped for two hours while every service stayed up.
|
// a seat emptied mid-change and the control plane looped for two hours while every service stayed up.
|
||||||
|
|
||||||
const rolloutUsage = "rollout check | rollout --confirm"
|
const rolloutUsage = "rollout check | rollout mint [--again] | rollout hand <node> | rollout --confirm"
|
||||||
|
|
||||||
func rolloutCommand(ctx context.Context, args []string) error {
|
func rolloutCommand(ctx context.Context, args []string) error {
|
||||||
switch {
|
switch {
|
||||||
case len(args) == 1 && args[0] == "check":
|
case len(args) == 1 && args[0] == "check":
|
||||||
return rolloutCheck(ctx)
|
return rolloutCheck(ctx)
|
||||||
|
case len(args) == 1 && args[0] == "mint":
|
||||||
|
return rolloutMint(ctx, false)
|
||||||
|
case len(args) == 2 && args[0] == "hand":
|
||||||
|
return rolloutHand(ctx, args[1])
|
||||||
|
case len(args) == 2 && args[0] == "mint" && args[1] == "--again":
|
||||||
|
// Every credential minted afresh, whether or not one exists — for a mint that was wrong
|
||||||
|
// before anything was pushed. Afterwards nothing that received the old one still works,
|
||||||
|
// which is fine exactly when nothing received it.
|
||||||
|
return rolloutMint(ctx, true)
|
||||||
case len(args) == 1 && args[0] == "--confirm":
|
case len(args) == 1 && args[0] == "--confirm":
|
||||||
return errors.New(
|
return errors.New(
|
||||||
"the rollout itself is not built yet: `rollout check` answers whether it could run, and " +
|
"the rollout itself is not built yet: `rollout check` answers whether it could run, and " +
|
||||||
@@ -190,3 +202,250 @@ func wasSentTheUserList(ctx context.Context, inv *inventory.Inventory, node stri
|
|||||||
// notReadyOf is the readiness reasoning, named here so a test can reach it without the command's
|
// notReadyOf is the readiness reasoning, named here so a test can reach it without the command's
|
||||||
// printing. The reasoning itself is the broker package's, where it is pure.
|
// printing. The reasoning itself is the broker package's, where it is pure.
|
||||||
func notReadyOf(state broker.Readiness) []string { return broker.NotReady(state) }
|
func notReadyOf(state broker.Readiness) []string { return broker.NotReady(state) }
|
||||||
|
|
||||||
|
// rolloutMint gives every principal the new bus will have a credential it does not yet have, and
|
||||||
|
// puts each where its owner reads it (novox/hq design 28, task 5.2): a machine's as a membership
|
||||||
|
// sealed into its declaration, a module's as its broker secret, the control plane's own as its
|
||||||
|
// `bus` secret. Idempotent: what already has a hash is left alone, so running it again is harmless.
|
||||||
|
//
|
||||||
|
// **Before anything moves, and it is what makes moving possible.** A machine moved without a
|
||||||
|
// credential cannot come back, and afterwards there is no bus to tell it anything over — which is
|
||||||
|
// why `rollout check` refuses until this has run. The bus's address is worked out here, from where
|
||||||
|
// the module that provides it is assigned, rather than read from this process's environment: this
|
||||||
|
// process is still on the old bus when this runs, and must be.
|
||||||
|
func rolloutMint(ctx context.Context, again bool) error {
|
||||||
|
open, err := openStores(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
defer open.Close()
|
||||||
|
inv := open.inventory
|
||||||
|
|
||||||
|
known, err := broker.FromEnvironment()
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("the bus's certificate is not known to this process, and every membership "+
|
||||||
|
"must carry its fingerprint: %w", err)
|
||||||
|
}
|
||||||
|
shelf, err := inv.Catalogue(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
entries, err := inv.Catalogued(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
var busNode, controllerNode string
|
||||||
|
for _, e := range entries {
|
||||||
|
switch {
|
||||||
|
case e.Manifest.ClaimsSeat("mesh-broker") && providesBus(e.Manifest) && len(e.On) > 0:
|
||||||
|
busNode = e.On[0]
|
||||||
|
case e.Manifest.Module == "mesh-controller" && len(e.On) > 0:
|
||||||
|
controllerNode = e.On[0]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if busNode == "" {
|
||||||
|
return errors.New("no assigned module provides mesh-bus and claims mesh-broker, so there is no " +
|
||||||
|
"bus to mint credentials for — register and assign it first")
|
||||||
|
}
|
||||||
|
onNetwork, err := whereEveryoneIs(ctx, inv, shelf)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
busHost := onNetwork[busNode]
|
||||||
|
if busHost == "" {
|
||||||
|
// **The hub is not in that map.** The machine that took over the tunnel is where the current
|
||||||
|
// bus already answers, and every machine dials it at the address the mesh handed them — so
|
||||||
|
// when the new bus runs on the same machine, that address is the one to tell them, with the
|
||||||
|
// new port. Found live: the control node is the hub, and the map lists the machines placed
|
||||||
|
// around it.
|
||||||
|
// The host alone: no scheme (BareAddress adds one where none was, which is the wrong
|
||||||
|
// direction here — every URL built below adds its own) and no port.
|
||||||
|
_, _, host := broker.CredentialIn(known.Address)
|
||||||
|
if host == "" {
|
||||||
|
host = known.Address
|
||||||
|
}
|
||||||
|
if _, after, hasScheme := strings.Cut(host, "://"); hasScheme {
|
||||||
|
host = after
|
||||||
|
}
|
||||||
|
host = strings.TrimSpace(host)
|
||||||
|
if i := strings.LastIndex(host, ":"); i > 0 && !strings.Contains(host[i:], "]") {
|
||||||
|
host = host[:i]
|
||||||
|
}
|
||||||
|
if host == "" {
|
||||||
|
return fmt.Errorf("%s runs the new bus and has no address on the private network, and the "+
|
||||||
|
"current bus's address is unknown too, so no machine could be told where it is", busNode)
|
||||||
|
}
|
||||||
|
busHost = host
|
||||||
|
}
|
||||||
|
busAddress := busHost + ":4222"
|
||||||
|
|
||||||
|
records, err := inv.BusRecords(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
users, err := broker.Users(records)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
kept, err := inv.BusUsers(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
hashes := make(map[string]string, len(kept))
|
||||||
|
for name, u := range kept {
|
||||||
|
hashes[name] = u.PasswordHash
|
||||||
|
}
|
||||||
|
_, missing := broker.WithPasswords(users, hashes)
|
||||||
|
wanted := map[string]bool{}
|
||||||
|
for _, m := range missing {
|
||||||
|
wanted[m] = true
|
||||||
|
}
|
||||||
|
|
||||||
|
var machines, modules, skipped int
|
||||||
|
for _, p := range users {
|
||||||
|
if !again && !wanted[p.Username()] {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
switch p.Kind {
|
||||||
|
case broker.KindController:
|
||||||
|
if controllerNode == "" {
|
||||||
|
return errors.New("the control plane is not assigned anywhere, so its credential has nowhere to go")
|
||||||
|
}
|
||||||
|
password, err := inv.MintBusPassword(ctx, inventory.BusUser{Username: p.Username(), Kind: inventory.BusController})
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
url := "nats://" + p.Username() + ":" + password + "@" + busAddress
|
||||||
|
if err := inv.AcceptSecretForModule(ctx, controllerNode, "mesh-controller", "bus", url); err != nil {
|
||||||
|
return fmt.Errorf("the control plane's credential is minted and could not be sealed to %s: %w", controllerNode, err)
|
||||||
|
}
|
||||||
|
fmt.Printf("control plane: credential minted, sealed to %s as its `bus` secret\n", controllerNode)
|
||||||
|
|
||||||
|
case broker.KindNode:
|
||||||
|
password, err := inv.MintBusPassword(ctx, inventory.BusUser{Username: p.Username(), Kind: inventory.BusNode, Node: p.Node})
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
membership, _ := json.Marshal(map[string]string{
|
||||||
|
"broker": busAddress, "fingerprint": known.Fingerprint, "password": password, "transport": "nats",
|
||||||
|
})
|
||||||
|
key, err := inv.SealingKeyOf(ctx, p.Node)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("%s has no sealing key, so its membership cannot be sealed to it: %w", p.Node, err)
|
||||||
|
}
|
||||||
|
sealed, err := secrets.Seal(key, membership)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if err := inv.PutBusMembership(ctx, p.Node, sealed); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
machines++
|
||||||
|
|
||||||
|
case broker.KindModule:
|
||||||
|
if p.Module == "mesh-controller" {
|
||||||
|
// The control plane is a module too, and its `broker` secret is the old bus's
|
||||||
|
// credential it is still using while this runs. Writing the new bus's blob there
|
||||||
|
// cut the mesh off from its own old bus mid-move (2026-09-28). Its new-bus credential
|
||||||
|
// is the controller principal's `bus` secret above; nothing else is needed here.
|
||||||
|
skipped++
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
m, inShelf := shelf[p.Module]
|
||||||
|
if !inShelf {
|
||||||
|
skipped++
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if _, reads := m.OwnSecrets["broker"]; !reads {
|
||||||
|
fmt.Printf(" %s on %s speaks on the bus but declares no `broker` secret to receive a credential in; skipped\n", p.Module, p.Node)
|
||||||
|
skipped++
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
password, err := inv.MintBusPassword(ctx, inventory.BusUser{Username: p.Username(), Kind: inventory.BusModule, Node: p.Node, Module: p.Module})
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if err := issueWith(ctx, inv, m, p.Node, "", known, busAddress, p.Username(), password); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
modules++
|
||||||
|
|
||||||
|
default:
|
||||||
|
skipped++
|
||||||
|
}
|
||||||
|
}
|
||||||
|
fmt.Printf("minted for %d machine(s) and %d module runtime(s); %d skipped; the bus is at %s\n",
|
||||||
|
machines, modules, skipped, busAddress)
|
||||||
|
fmt.Println(" each machine's membership and each module's credential arrive with the next push of its machine;")
|
||||||
|
fmt.Println(" push the machine running the bus first, so the bus stands with its user list before anything dials it")
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// providesBus is whether a manifest provides the mesh's bus.
|
||||||
|
func providesBus(m catalogue.Manifest) bool {
|
||||||
|
for _, o := range m.Provides {
|
||||||
|
if o.Name == "mesh-bus" {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
// rolloutHand mints a machine its credential for the new bus afresh and prints its membership
|
||||||
|
// once, for an operator to carry by hand — the rescue for a machine that cannot be reached over
|
||||||
|
// any bus: rotated while it still held the old password, or reachable only by ssh. The plaintext
|
||||||
|
// exists on this terminal and then only where it is written; the store keeps the hash, and the
|
||||||
|
// sealed copy in the machine's declaration is replaced too, so the next push says the same.
|
||||||
|
func rolloutHand(ctx context.Context, node string) error {
|
||||||
|
open, err := openStores(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
defer open.Close()
|
||||||
|
inv := open.inventory
|
||||||
|
|
||||||
|
known, err := broker.FromEnvironment()
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("the bus's certificate is not known to this process: %w", err)
|
||||||
|
}
|
||||||
|
busAddress, _, err := broker.OnNATS()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if busAddress == "" {
|
||||||
|
return errors.New("this control plane is not on the new bus, so there is no membership to hand out")
|
||||||
|
}
|
||||||
|
_, _, bare := broker.CredentialIn(busAddress)
|
||||||
|
if _, after, has := strings.Cut(bare, "://"); has {
|
||||||
|
bare = after
|
||||||
|
}
|
||||||
|
if _, err := inv.NodeByName(ctx, node); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
p := broker.Principal{Kind: broker.KindNode, Node: node}
|
||||||
|
password, err := inv.MintBusPassword(ctx, inventory.BusUser{Username: p.Username(), Kind: inventory.BusNode, Node: node})
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
membership, _ := json.Marshal(map[string]string{
|
||||||
|
"broker": bare, "fingerprint": known.Fingerprint, "password": password, "transport": "nats",
|
||||||
|
})
|
||||||
|
key, err := inv.SealingKeyOf(ctx, node)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
sealed, err := secrets.Seal(key, membership)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if err := inv.PutBusMembership(ctx, node, sealed); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
// The one line of output is the membership itself, so it can be piped to the machine without
|
||||||
|
// being read on the way. Everything else goes to stderr.
|
||||||
|
fmt.Fprintf(os.Stderr, "%s's credential is minted afresh. Write this to %s on it and restart its host; "+
|
||||||
|
"then push the machine running the bus so the user list carries the new hash.\n",
|
||||||
|
node, catalogue.BusMembershipPath)
|
||||||
|
fmt.Println(string(membership))
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,8 +1,14 @@
|
|||||||
package broker
|
package broker
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"crypto/sha256"
|
||||||
|
"crypto/tls"
|
||||||
|
"crypto/x509"
|
||||||
|
"encoding/hex"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"os"
|
||||||
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/nats-io/nats.go"
|
"github.com/nats-io/nats.go"
|
||||||
@@ -24,21 +30,78 @@ type JetStream struct {
|
|||||||
|
|
||||||
// Dial connects and returns the controller's JetStream handle.
|
// Dial connects and returns the controller's JetStream handle.
|
||||||
func Dial(url string, opts ...nats.Option) (*JetStream, error) {
|
func Dial(url string, opts ...nats.Option) (*JetStream, error) {
|
||||||
// A name, because a connection nobody can identify in the server's own monitoring is one
|
|
||||||
// nobody can attribute a problem to.
|
|
||||||
opts = append(opts, nats.Name("mesh-controller"), nats.Timeout(10*time.Second))
|
opts = append(opts, nats.Name("mesh-controller"), nats.Timeout(10*time.Second))
|
||||||
|
// **Pinned, not named.** The bus presents the mesh's own certificate, which names nothing a
|
||||||
|
// public verifier would accept (design 25 §4: a host pins the server's exact certificate and
|
||||||
|
// checks nothing else, and so does this). Without this, the first connection failed with
|
||||||
|
// "certificate is not valid for any names" against a bus that was answering (2026-09-28).
|
||||||
|
if path := strings.TrimSpace(os.Getenv(CertificateVar)); path != "" {
|
||||||
|
pinned, err := pinnedTo(path)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
opts = append(opts, nats.Secure(pinned))
|
||||||
|
}
|
||||||
|
// **Its own inbox, and nothing wider.** Every principal is granted `_INBOX.<its user>.>` and
|
||||||
|
// no other inbox; the client's default prefix is random, and the server refused the first
|
||||||
|
// subscription to it (2026-09-28). The user is in the URL, so the prefix follows from it.
|
||||||
|
if user, _, _ := CredentialIn(url); user != "" {
|
||||||
|
opts = append(opts, nats.CustomInboxPrefix("_INBOX."+user))
|
||||||
|
}
|
||||||
|
// The address in an error is the address alone. The URL carries this controller's password,
|
||||||
|
// and an error here is written on the assumption it will be logged.
|
||||||
|
where := BareAddress(url)
|
||||||
conn, err := nats.Connect(url, opts...)
|
conn, err := nats.Connect(url, opts...)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, fmt.Errorf("connecting to the bus at %s: %w", url, err)
|
return nil, fmt.Errorf("connecting to the bus at %s: %w", where, err)
|
||||||
}
|
}
|
||||||
js, err := conn.JetStream()
|
js, err := conn.JetStream()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
conn.Close()
|
conn.Close()
|
||||||
return nil, fmt.Errorf("the bus at %s has no JetStream: %w", url, err)
|
return nil, fmt.Errorf("the bus at %s has no JetStream: %w", where, err)
|
||||||
}
|
}
|
||||||
return &JetStream{conn: conn, js: js}, nil
|
return &JetStream{conn: conn, js: js}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// pinnedTo is a TLS configuration that accepts exactly the certificate in the file and no other:
|
||||||
|
// the leaf's SHA-256, compared on every handshake, with the name and the chain deliberately not
|
||||||
|
// consulted — a self-signed certificate with no names is the ordinary case for a mesh's bus.
|
||||||
|
func pinnedTo(path string) (*tls.Config, error) {
|
||||||
|
want, err := FingerprintOf(path)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return PinnedToFingerprint(want), nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// DialPinned is Dial with the server's certificate pinned by a fingerprint the caller already holds
|
||||||
|
// — a module or a build machine that was handed one beside its credential, and has no file.
|
||||||
|
func DialPinned(url, fingerprint string, opts ...nats.Option) (*JetStream, error) {
|
||||||
|
if strings.TrimSpace(fingerprint) != "" {
|
||||||
|
opts = append(opts, nats.Secure(PinnedToFingerprint(fingerprint)))
|
||||||
|
}
|
||||||
|
return Dial(url, opts...)
|
||||||
|
}
|
||||||
|
|
||||||
|
// PinnedToFingerprint accepts exactly the certificate with this SHA-256 and no other.
|
||||||
|
func PinnedToFingerprint(want string) *tls.Config {
|
||||||
|
return &tls.Config{
|
||||||
|
InsecureSkipVerify: true, //nolint:gosec // replaced by the pin below, which is stricter
|
||||||
|
MinVersion: tls.VersionTLS12,
|
||||||
|
VerifyPeerCertificate: func(rawCerts [][]byte, _ [][]*x509.Certificate) error {
|
||||||
|
if len(rawCerts) == 0 {
|
||||||
|
return errors.New("the bus presented no certificate")
|
||||||
|
}
|
||||||
|
sum := sha256.Sum256(rawCerts[0])
|
||||||
|
got := "sha256:" + hex.EncodeToString(sum[:])
|
||||||
|
if got != want {
|
||||||
|
return fmt.Errorf("the bus presented a certificate this mesh does not know (%s…), expected %s…", got[:23], want[:23])
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Conn is the connection itself, for what the mesh keeps off JetStream on purpose — a heartbeat,
|
// Conn is the connection itself, for what the mesh keeps off JetStream on purpose — a heartbeat,
|
||||||
// a tool call — where a lost message is answered by the next one or by a timeout the caller
|
// a tool call — where a lost message is answered by the next one or by a timeout the caller
|
||||||
// already handles (design 25 §3).
|
// already handles (design 25 §3).
|
||||||
|
|||||||
+29
-4
@@ -169,7 +169,11 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
|||||||
// The controller owns the mesh's own traffic and the streams. It is the only writer of
|
// The controller owns the mesh's own traffic and the streams. It is the only writer of
|
||||||
// stream definitions (design 25 §3), so it alone reaches the JetStream API.
|
// stream definitions (design 25 §3), so it alone reaches the JetStream API.
|
||||||
pub = []string{"mesh.control.>", "mesh.node.>", "$JS.API.>"}
|
pub = []string{"mesh.control.>", "mesh.node.>", "$JS.API.>"}
|
||||||
sub = []string{"mesh.control.>", "$JS.API.>"}
|
// **And where its consumers deliver.** A push consumer delivers on `_DELIVER.<its name>`,
|
||||||
|
// and a client bound to it subscribes exactly that; the server refused it for every
|
||||||
|
// principal the first time one bound a consumer (2026-09-28). Each kind below is granted
|
||||||
|
// its own consumers' delivery subjects and no other's.
|
||||||
|
sub = []string{"mesh.control.>", "$JS.API.>", "_DELIVER." + ControllerName, "_DELIVER." + ControllerName + ".>"}
|
||||||
|
|
||||||
// Work the mesh's own flows submit to a role, and the outcomes they wait on (ADR 0121). A
|
// Work the mesh's own flows submit to a role, and the outcomes they wait on (ADR 0121). A
|
||||||
// build is the one today: the controller asks, and reads the answer from the seat's event
|
// build is the one today: the controller asks, and reads the answer from the seat's event
|
||||||
@@ -244,8 +248,15 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
|||||||
case KindNode:
|
case KindNode:
|
||||||
// A host publishes its own node's control traffic and subscribes its own declaration —
|
// A host publishes its own node's control traffic and subscribes its own declaration —
|
||||||
// and nothing of any other node's.
|
// and nothing of any other node's.
|
||||||
pub = []string{"mesh.control." + p.Node + ".>"}
|
// And binding to its consumer, which asks the server about it (CONSUMER.INFO) — the one
|
||||||
sub = []string{"mesh.node." + p.Node + ".declare"}
|
// thing the host does that nothing granted. Found the first time a machine dialled a
|
||||||
|
// permissioned server: "this node cannot read its declarations" (2026-09-28). The ack and
|
||||||
|
// the inbox are granted below with every principal's.
|
||||||
|
pub = []string{
|
||||||
|
"mesh.control." + p.Node + ".>",
|
||||||
|
"$JS.API.CONSUMER.INFO.NODES." + p.Node,
|
||||||
|
}
|
||||||
|
sub = []string{"mesh.node." + p.Node + ".declare", "_DELIVER." + p.Node}
|
||||||
|
|
||||||
case KindModule:
|
case KindModule:
|
||||||
// 1. Its own namespace: it publishes its events there and serves its tools there. Nothing
|
// 1. Its own namespace: it publishes its events there and serves its tools there. Nothing
|
||||||
@@ -278,7 +289,18 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// 3. Seats it holds: full participation.
|
// 3. Seats it holds: full participation.
|
||||||
|
// Its consumer's name, not ConsumerFor: that asks for these permissions to build the
|
||||||
|
// consumer, and would ask forever. A subject for a consumer that turns out not to exist
|
||||||
|
// grants nothing anybody can use.
|
||||||
|
sub = append(sub, "_DELIVER."+consumerDurable(p))
|
||||||
for _, s := range p.Holds {
|
for _, s := range p.Holds {
|
||||||
|
// Taking work from the role's queue: the worker consumer it binds (asked about,
|
||||||
|
// delivered on, acknowledged), each on the seat's own stream. The first machine to
|
||||||
|
// take work over the new bus was refused the asking (2026-09-28).
|
||||||
|
worker := "SEAT_" + upperSnake(s.Name) + "_worker"
|
||||||
|
stream := seatStreamName(s.Name)
|
||||||
|
sub = append(sub, "_DELIVER."+worker)
|
||||||
|
pub = append(pub, "$JS.API.CONSUMER.INFO."+stream+"."+worker, "$JS.ACK."+stream+"."+worker+".>")
|
||||||
for _, a := range s.Accepts {
|
for _, a := range s.Accepts {
|
||||||
sub = append(sub, seatSubject(s, "accept", a))
|
sub = append(sub, seatSubject(s, "accept", a))
|
||||||
}
|
}
|
||||||
@@ -514,7 +536,10 @@ func ComposeAccounts(principals []Principal) (string, error) {
|
|||||||
// One account for the mesh: accounts in NATS isolate subject spaces entirely, and the mesh is
|
// One account for the mesh: accounts in NATS isolate subject spaces entirely, and the mesh is
|
||||||
// one space (design 25 §4). The cost of that — that permissions are the only isolation — is
|
// one space (design 25 §4). The cost of that — that permissions are the only isolation — is
|
||||||
// paid in the scoping of every inbox and every ack subject.
|
// paid in the scoping of every inbox and every ack subject.
|
||||||
b.WriteString("accounts {\n MESH {\n users = [\n")
|
// JetStream is enabled per account once accounts exist at all: with only the global block set,
|
||||||
|
// a user in MESH is told "JetStream not enabled for account" the first time it binds a
|
||||||
|
// consumer, which is the first thing every host does (2026-09-28).
|
||||||
|
b.WriteString("accounts {\n MESH {\n jetstream: enabled\n users = [\n")
|
||||||
for _, p := range sorted {
|
for _, p := range sorted {
|
||||||
perms, err := PermissionsFor(p)
|
perms, err := PermissionsFor(p)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|||||||
+8
-7
@@ -21,10 +21,11 @@ jetstream {
|
|||||||
|
|
||||||
accounts {
|
accounts {
|
||||||
MESH {
|
MESH {
|
||||||
|
jetstream: enabled
|
||||||
users = [
|
users = [
|
||||||
{ user: "controller", password: "$2a$11$cccccccccccccccccccccc", permissions: {
|
{ user: "controller", password: "$2a$11$cccccccccccccccccccccc", permissions: {
|
||||||
publish: { allow: ["$JS.ACK.CONTROL.controller.>", "$JS.ACK.EVENTS.controller.>", "$JS.API.>", "_INBOX.enrol.>", "mesh.control.>", "mesh.node.>", "mesh.seat.mesh-build-machine.accept.>"] }
|
publish: { allow: ["$JS.ACK.CONTROL.controller.>", "$JS.ACK.EVENTS.controller.>", "$JS.API.>", "_INBOX.enrol.>", "mesh.control.>", "mesh.node.>", "mesh.seat.mesh-build-machine.accept.>"] }
|
||||||
subscribe: { allow: ["$JS.API.>", "_INBOX.controller.>", "mesh.control.>", "mesh.mod.mesh-catalog.event.catching-up", "mesh.mod.mesh-catalog.event.upgraded", "mesh.seat.mesh-build-machine.event.built"] }
|
subscribe: { allow: ["$JS.API.>", "_DELIVER.controller", "_DELIVER.controller.>", "_INBOX.controller.>", "mesh.control.>", "mesh.mod.mesh-catalog.event.catching-up", "mesh.mod.mesh-catalog.event.upgraded", "mesh.seat.mesh-build-machine.event.built"] }
|
||||||
allow_responses: { max: 1, ttl: "1m" }
|
allow_responses: { max: 1, ttl: "1m" }
|
||||||
} }
|
} }
|
||||||
{ user: "enrol.one", password: "$2a$11$eeeeeeeeeeeeeeeeeeeeee", permissions: {
|
{ user: "enrol.one", password: "$2a$11$eeeeeeeeeeeeeeeeeeeeee", permissions: {
|
||||||
@@ -32,21 +33,21 @@ accounts {
|
|||||||
subscribe: { allow: ["_INBOX.enrol.one.>"] }
|
subscribe: { allow: ["_INBOX.enrol.one.>"] }
|
||||||
} }
|
} }
|
||||||
{ user: "node.one", password: "$2a$11$nnnnnnnnnnnnnnnnnnnnnn", permissions: {
|
{ user: "node.one", password: "$2a$11$nnnnnnnnnnnnnnnnnnnnnn", permissions: {
|
||||||
publish: { allow: ["$JS.ACK.NODES.one.>", "mesh.control.one.>"] }
|
publish: { allow: ["$JS.ACK.NODES.one.>", "$JS.API.CONSUMER.INFO.NODES.one", "mesh.control.one.>"] }
|
||||||
subscribe: { allow: ["_INBOX.node.one.>", "mesh.node.one.declare"] }
|
subscribe: { allow: ["_DELIVER.one", "_INBOX.node.one.>", "mesh.node.one.declare"] }
|
||||||
} }
|
} }
|
||||||
{ user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: {
|
{ user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: {
|
||||||
publish: { allow: ["$JS.ACK.EVENTS.one_telegram.>", "mesh.seat.telegram-sender.event.delivered", "mesh.seat.telegram-sender.event.failed"] }
|
publish: { allow: ["$JS.ACK.EVENTS.one_telegram.>", "$JS.ACK.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker.>", "$JS.API.CONSUMER.INFO.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker", "mesh.seat.telegram-sender.event.delivered", "mesh.seat.telegram-sender.event.failed"] }
|
||||||
subscribe: { allow: ["_INBOX.one.telegram.>", "mesh.mod.telegram.tool.status", "mesh.seat.telegram-sender.accept.send"] }
|
subscribe: { allow: ["_DELIVER.SEAT_TELEGRAM_SENDER_worker", "_DELIVER.one_telegram", "_INBOX.one.telegram.>", "mesh.mod.telegram.tool.status", "mesh.seat.telegram-sender.accept.send"] }
|
||||||
allow_responses: { max: 1, ttl: "1m" }
|
allow_responses: { max: 1, ttl: "1m" }
|
||||||
} }
|
} }
|
||||||
{ user: "two.audit", password: "$2a$11$aaaaaaaaaaaaaaaaaaaaaa", permissions: {
|
{ user: "two.audit", password: "$2a$11$aaaaaaaaaaaaaaaaaaaaaa", permissions: {
|
||||||
publish: { allow: ["$JS.ACK.EVENTS.two_audit.>"] }
|
publish: { allow: ["$JS.ACK.EVENTS.two_audit.>"] }
|
||||||
subscribe: { allow: ["_INBOX.two.audit.>", "mesh.mod.shop.event.order.placed"] }
|
subscribe: { allow: ["_DELIVER.two_audit", "_INBOX.two.audit.>", "mesh.mod.shop.event.order.placed"] }
|
||||||
} }
|
} }
|
||||||
{ user: "two.shop", password: "$2a$11$ssssssssssssssssssssss", permissions: {
|
{ user: "two.shop", password: "$2a$11$ssssssssssssssssssssss", permissions: {
|
||||||
publish: { allow: ["$JS.ACK.EVENTS.two_shop.>", "mesh.mod.shop.event.order.placed", "mesh.seat.telegram-sender.accept.send"] }
|
publish: { allow: ["$JS.ACK.EVENTS.two_shop.>", "mesh.mod.shop.event.order.placed", "mesh.seat.telegram-sender.accept.send"] }
|
||||||
subscribe: { allow: ["_INBOX.two.shop.>"] }
|
subscribe: { allow: ["_DELIVER.two_shop", "_INBOX.two.shop.>"] }
|
||||||
} }
|
} }
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -186,7 +186,13 @@ func TestWhatTheMeshWritesIsUsersAndNothingAboutTheServer(t *testing.T) {
|
|||||||
}
|
}
|
||||||
// None of the server's own settings. Each of these in the mesh's file is a value the controller
|
// None of the server's own settings. Each of these in the mesh's file is a value the controller
|
||||||
// would then own, and the module could no longer change its own image without the mesh agreeing.
|
// would then own, and the module could no longer change its own image without the mesh agreeing.
|
||||||
for _, absent := range []string{"port:", "http:", "jetstream", "tls {", "store_dir", "cert_file"} {
|
// `jetstream {` is the server's block (its store, its limits); `jetstream: enabled` inside the
|
||||||
|
// account is the account's, and the mesh owns the account — a user in it is told "JetStream
|
||||||
|
// not enabled for account" without it (2026-09-28).
|
||||||
|
if !strings.Contains(got, "jetstream: enabled") {
|
||||||
|
t.Errorf("the account does not enable JetStream, so no user in it can bind a consumer")
|
||||||
|
}
|
||||||
|
for _, absent := range []string{"port:", "http:", "jetstream {", "tls {", "store_dir", "cert_file"} {
|
||||||
if strings.Contains(got, absent) {
|
if strings.Contains(got, absent) {
|
||||||
t.Errorf("the accounts file contains %q, which belongs to the module that raises the "+
|
t.Errorf("the accounts file contains %q, which belongs to the module that raises the "+
|
||||||
"server, not to the mesh", absent)
|
"server, not to the mesh", absent)
|
||||||
|
|||||||
@@ -103,6 +103,11 @@ type Rendering struct {
|
|||||||
// **Only the users, never the server's own settings**: those are the module's, in its image and
|
// **Only the users, never the server's own settings**: those are the module's, in its image and
|
||||||
// its mounts (Manifest.BusUsers).
|
// its mounts (Manifest.BusUsers).
|
||||||
BusUsers string
|
BusUsers string
|
||||||
|
// BusMembership is this machine's membership for the bus the mesh is moving to, sealed to it
|
||||||
|
// (design 28, task 5.2). Empty for a machine not being moved. Written as a file the host reads
|
||||||
|
// after the declaration has applied, so the bus it names is standing before the machine leaves
|
||||||
|
// the one it is on.
|
||||||
|
BusMembership string
|
||||||
|
|
||||||
// MeshRange is the private network's CIDR (the range node addresses are allocated from), for a
|
// MeshRange is the private network's CIDR (the range node addresses are allocated from), for a
|
||||||
// module that must name the whole mesh rather than one machine — an intrusion filter that must
|
// module that must name the whole mesh rather than one machine — an intrusion filter that must
|
||||||
@@ -238,9 +243,23 @@ func (r Resolution) Compose(with Rendering) (Composed, error) {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return Composed{}, err
|
return Composed{}, err
|
||||||
}
|
}
|
||||||
|
if with.BusMembership != "" {
|
||||||
|
// The machine's own, not any module's: how it reaches the mesh from now on. Sealed like a
|
||||||
|
// secret and placed where the host looks for exactly this (design 28, task 5.2).
|
||||||
|
resources = append(resources, map[string]any{
|
||||||
|
"id": BusMembershipID(), "type": "file", "path": BusMembershipPath,
|
||||||
|
"sealed": with.BusMembership, "mode": "0600",
|
||||||
|
})
|
||||||
|
}
|
||||||
return Composed{Resources: resources, Owner: owner}, nil
|
return Composed{Resources: resources, Owner: owner}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// BusMembershipID names the resource carrying a machine's membership for the new bus, and
|
||||||
|
// BusMembershipPath is where the host reads it — the same constant on both sides.
|
||||||
|
func BusMembershipID() string { return "bus-membership" }
|
||||||
|
|
||||||
|
const BusMembershipPath = "/var/lib/mesh/membership-next.json"
|
||||||
|
|
||||||
func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[string]any, error) {
|
func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[string]any, error) {
|
||||||
// Every manifest is placed first (novox/hq ADR 0112): the maps naming where its bindings,
|
// Every manifest is placed first (novox/hq ADR 0112): the maps naming where its bindings,
|
||||||
// credentials and contributions land are resolved against this node's directories, so every
|
// credentials and contributions land are resolved against this node's directories, so every
|
||||||
|
|||||||
@@ -114,3 +114,47 @@ func TestCanHoldJudgesClaimScopeAndWhatTheSeatDelivers(t *testing.T) {
|
|||||||
t.Fatalf("with the row saying amqp, an amqp provider was refused: %v", err)
|
t.Fatalf("with the row saying amqp, an amqp provider was refused: %v", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// A machine being moved is handed its membership for the new bus as a sealed file in its own
|
||||||
|
// declaration — the machine's, not any module's (design 28, task 5.2).
|
||||||
|
func TestAMembershipForTheNewBusIsComposedAsASealedFile(t *testing.T) {
|
||||||
|
r := Resolution{Node: "anchor"}
|
||||||
|
got, err := r.Compose(Rendering{BusMembership: "sealed-blob"})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
var found map[string]any
|
||||||
|
for _, res := range got.Resources {
|
||||||
|
if res["id"] == BusMembershipID() {
|
||||||
|
found = res
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if found == nil {
|
||||||
|
t.Fatalf("no membership resource in %v", got.Resources)
|
||||||
|
}
|
||||||
|
if found["path"] != BusMembershipPath || found["sealed"] != "sealed-blob" || found["mode"] != "0600" {
|
||||||
|
t.Fatalf("the membership is not a sealed 0600 file where the host reads it: %v", found)
|
||||||
|
}
|
||||||
|
// And a machine not being moved is handed nothing.
|
||||||
|
got, _ = r.Compose(Rendering{})
|
||||||
|
for _, res := range got.Resources {
|
||||||
|
if res["id"] == BusMembershipID() {
|
||||||
|
t.Fatal("a machine with no membership on record was handed one")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// The store's seat rows have no protocol columns yet; loading them must not drop the protocol the
|
||||||
|
// bus is derived from, or no role's work queue is ever raised (found live, 2026-09-28).
|
||||||
|
func TestAStoreRowWithoutAProtocolKeepsTheCompiledOne(t *testing.T) {
|
||||||
|
was := Seats()
|
||||||
|
t.Cleanup(func() { UseSeats(was) })
|
||||||
|
UseSeats([]Seat{{Name: "mesh-build-machine", Scope: ScopeMesh, Decision: "row"}})
|
||||||
|
got, ok := SeatNamed("mesh-build-machine")
|
||||||
|
if !ok || len(got.Accepts) == 0 {
|
||||||
|
t.Fatalf("the build machine's seat lost what it accepts when loaded from the store: %+v", got)
|
||||||
|
}
|
||||||
|
if got.Decision != "row" {
|
||||||
|
t.Fatalf("the store's own columns were not kept: %+v", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -13,7 +13,6 @@ func TestASeatPlaceholderAnswersWhereThisMachinePutTheHolder(t *testing.T) {
|
|||||||
"type": "container", "id": "server", "name": "mesh-controller",
|
"type": "container", "id": "server", "name": "mesh-controller",
|
||||||
"env": map[string]any{
|
"env": map[string]any{
|
||||||
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
||||||
"MESH_BROKER_AMQP_PORT": "${seat:mesh-broker:5672}",
|
|
||||||
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
|
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
|
||||||
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
|
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
|
||||||
},
|
},
|
||||||
@@ -27,7 +26,6 @@ func TestASeatPlaceholderAnswersWhereThisMachinePutTheHolder(t *testing.T) {
|
|||||||
env := control["env"].(map[string]any)
|
env := control["env"].(map[string]any)
|
||||||
for key, want := range map[string]string{
|
for key, want := range map[string]string{
|
||||||
"MESH_STORE_INVENTORY_PORT": "6852",
|
"MESH_STORE_INVENTORY_PORT": "6852",
|
||||||
"MESH_BROKER_AMQP_PORT": "5679",
|
|
||||||
"MESH_BROKER_ADDRESS_PORT": "5671",
|
"MESH_BROKER_ADDRESS_PORT": "5671",
|
||||||
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
|
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
|
||||||
} {
|
} {
|
||||||
@@ -146,7 +144,6 @@ func TestTheControlPlanesOwnAddressesFollowTheNodesPorts(t *testing.T) {
|
|||||||
"MESH_STORE_INVENTORY_PORT": "6852",
|
"MESH_STORE_INVENTORY_PORT": "6852",
|
||||||
"MESH_STORE_IDENTITY_PORT": "6852",
|
"MESH_STORE_IDENTITY_PORT": "6852",
|
||||||
"MESH_STORE_LICENCES_PORT": "6852",
|
"MESH_STORE_LICENCES_PORT": "6852",
|
||||||
"MESH_BROKER_AMQP_PORT": "5679",
|
|
||||||
"MESH_BROKER_MANAGEMENT_PORT": "15673",
|
"MESH_BROKER_MANAGEMENT_PORT": "15673",
|
||||||
"MESH_BROKER_ADDRESS_PORT": "5671",
|
"MESH_BROKER_ADDRESS_PORT": "5671",
|
||||||
} {
|
} {
|
||||||
@@ -164,7 +161,7 @@ func TestTheControlPlanesOwnAddressesFollowTheNodesPorts(t *testing.T) {
|
|||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
env, _ = fileNamed(out, "mesh-controller.server")["env"].(map[string]any)
|
env, _ = fileNamed(out, "mesh-controller.server")["env"].(map[string]any)
|
||||||
if env["MESH_STORE_INVENTORY_PORT"] != "" || env["MESH_BROKER_AMQP_PORT"] != "" {
|
if env["MESH_STORE_INVENTORY_PORT"] != "" {
|
||||||
t.Errorf("with no settings, the control plane is told %v", env)
|
t.Errorf("with no settings, the control plane is told %v", env)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -175,7 +172,6 @@ var SeatPorts = map[string]string{
|
|||||||
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
||||||
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
|
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
|
||||||
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
|
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
|
||||||
"MESH_BROKER_AMQP_PORT": "${seat:mesh-broker:5672}",
|
|
||||||
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
|
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
|
||||||
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
|
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -109,9 +109,30 @@ func DefaultSeats() []Seat { return append([]Seat(nil), defaultSeats...) }
|
|||||||
// than running on the set the binary shipped with. So the store can only ever *replace* the set with
|
// than running on the set the binary shipped with. So the store can only ever *replace* the set with
|
||||||
// a non-empty one, never erase it.
|
// a non-empty one, never erase it.
|
||||||
func UseSeats(s []Seat) {
|
func UseSeats(s []Seat) {
|
||||||
if len(s) > 0 {
|
if len(s) == 0 {
|
||||||
seats = s
|
return
|
||||||
}
|
}
|
||||||
|
// **The store's rows carry no protocol yet, and the protocol is what the bus is derived
|
||||||
|
// from.** ADR 0129 gives a seat what it accepts, emits and serves; ADR 0122 moved the set into
|
||||||
|
// a table that has name, scope, delivers and decision and nothing else, and the columns for
|
||||||
|
// the rest are not there yet. So a row replacing a compiled entry would silently drop the
|
||||||
|
// protocol, and the roles' work queues would never be raised — found live as "no response
|
||||||
|
// from stream" the first time a build was submitted over the new bus (2026-09-28). Until the
|
||||||
|
// table gains the columns, a row without a protocol keeps the compiled one of the same name.
|
||||||
|
byName := map[string]Seat{}
|
||||||
|
for _, d := range defaultSeats {
|
||||||
|
byName[d.Name] = d
|
||||||
|
}
|
||||||
|
merged := make([]Seat, 0, len(s))
|
||||||
|
for _, row := range s {
|
||||||
|
if len(row.Accepts)+len(row.Emits)+len(row.Serves) == 0 {
|
||||||
|
if d, known := byName[row.Name]; known {
|
||||||
|
row.Accepts, row.Emits, row.Serves = d.Accepts, d.Emits, d.Serves
|
||||||
|
}
|
||||||
|
}
|
||||||
|
merged = append(merged, row)
|
||||||
|
}
|
||||||
|
seats = merged
|
||||||
}
|
}
|
||||||
|
|
||||||
// aliases maps a seat's former names to its current canonical name (novox/hq ADR 0122). Loaded from
|
// aliases maps a seat's former names to its current canonical name (novox/hq ADR 0122). Loaded from
|
||||||
|
|||||||
@@ -230,3 +230,35 @@ func (i *Inventory) ForgetPerson(ctx context.Context, name string) error {
|
|||||||
}
|
}
|
||||||
return i.ForgetBusUser(ctx, "person."+name)
|
return i.ForgetBusUser(ctx, "person."+name)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// PutBusMembership records a machine's membership for the new bus, sealed to it (design 28, 5.2).
|
||||||
|
// Replaces any earlier one: a machine has one membership per bus, and re-minting is re-telling.
|
||||||
|
func (i *Inventory) PutBusMembership(ctx context.Context, nodeName, sealed string) error {
|
||||||
|
node, err := i.NodeByName(ctx, nodeName)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
_, err = i.store.Pool().Exec(ctx,
|
||||||
|
`insert into bus_membership (node, sealed) values ($1, $2)
|
||||||
|
on conflict (node) do update set sealed = excluded.sealed, since = now()`, node.ID, sealed)
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
// BusMemberships is every machine's sealed membership for the new bus, by node name.
|
||||||
|
func (i *Inventory) BusMemberships(ctx context.Context) (map[string]string, error) {
|
||||||
|
rows, err := i.store.Pool().Query(ctx,
|
||||||
|
`select n.name, b.sealed from bus_membership b join node n on n.id = b.node`)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
defer rows.Close()
|
||||||
|
out := map[string]string{}
|
||||||
|
for rows.Next() {
|
||||||
|
var name, sealed string
|
||||||
|
if err := rows.Scan(&name, &sealed); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
out[name] = sealed
|
||||||
|
}
|
||||||
|
return out, rows.Err()
|
||||||
|
}
|
||||||
|
|||||||
@@ -80,3 +80,20 @@ func TestUnassigningTheHolderTakesTheHoldingWithIt(t *testing.T) {
|
|||||||
t.Fatalf("the holding outlived the assignment it pointed at: %+v", held)
|
t.Fatalf("the holding outlived the assignment it pointed at: %+v", held)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestAMachinesMembershipIsOneRowReplacedAndGoesWithTheMachine(t *testing.T) {
|
||||||
|
inv, ctx := twoBrokersOnTwoNodes(t)
|
||||||
|
if err := inv.PutBusMembership(ctx, "anchor", "first"); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := inv.PutBusMembership(ctx, "anchor", "second"); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
got, err := inv.BusMemberships(ctx)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if got["anchor"] != "second" || len(got) != 1 {
|
||||||
|
t.Fatalf("a re-told membership did not replace the first: %v", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
+11
@@ -0,0 +1,11 @@
|
|||||||
|
-- A machine already enrolled is moved to the new bus by being told its membership for it
|
||||||
|
-- (novox/hq design 28, task 5.2). Until this, a membership — bus address, fingerprint, password,
|
||||||
|
-- transport — existed only in the enrolment reply, and nothing could hand one to a machine that
|
||||||
|
-- had already joined. The row is the membership sealed to that machine, composed into its
|
||||||
|
-- declaration as a file it reads after applying; the plaintext exists once, at minting, and then
|
||||||
|
-- only on the machine. One per node: the mesh moves to one bus.
|
||||||
|
create table bus_membership (
|
||||||
|
node uuid primary key references node(id) on delete cascade,
|
||||||
|
sealed text not null,
|
||||||
|
since timestamptz not null default now()
|
||||||
|
);
|
||||||
@@ -0,0 +1,73 @@
|
|||||||
|
package link
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"fmt"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/nats-io/nats.go"
|
||||||
|
|
||||||
|
"github.com/novox/mesh-controller/internal/broker"
|
||||||
|
)
|
||||||
|
|
||||||
|
// OverNats is the controller's outbound on the bus being built: the same three acts the other
|
||||||
|
// transport has, on the subjects the permissions were derived for (design 25). A declaration is a
|
||||||
|
// JetStream publish into NODES, where the node's own consumer waits for it; an event is announced on
|
||||||
|
// the subject its name derives to; a tool is asked by request and reply on the module's tool subject.
|
||||||
|
type OverNats struct{ JS *broker.JetStream }
|
||||||
|
|
||||||
|
// declareSubject is where one node's declaration lands — the NODES stream's subject for it, and the
|
||||||
|
// only subject that node's consumer delivers. The host subscribes exactly this.
|
||||||
|
func declareSubject(node string) string { return "mesh.node." + node + ".declare" }
|
||||||
|
|
||||||
|
func (b OverNats) PublishDeclaration(ctx context.Context, node string, body []byte) error {
|
||||||
|
publish, cancel := context.WithTimeout(ctx, 15*time.Second)
|
||||||
|
defer cancel()
|
||||||
|
if _, err := b.JS.Context().Publish(declareSubject(node), body, nats.Context(publish)); err != nil {
|
||||||
|
return fmt.Errorf("declaring to %s: %w", node, err)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (b OverNats) PublishEvent(ctx context.Context, key, source, node string, body []byte) error {
|
||||||
|
// The key is the subject: the controller's own events are named in full, and what a module
|
||||||
|
// emits is derived before it reaches here. Headers carry the envelope the other transport put
|
||||||
|
// in message properties (ADR 0042), so a consumer reads who and when without the payload.
|
||||||
|
msg := nats.NewMsg(key)
|
||||||
|
msg.Data = body
|
||||||
|
msg.Header.Set("x-source", source)
|
||||||
|
msg.Header.Set("x-node", node)
|
||||||
|
msg.Header.Set("x-time", time.Now().UTC().Format(time.RFC3339Nano))
|
||||||
|
if err := b.JS.Conn().PublishMsg(msg); err != nil {
|
||||||
|
return fmt.Errorf("announcing %s: %w", key, err)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (b OverNats) AskTool(ctx context.Context, module, tool string, args []byte, timeout time.Duration) ([]byte, error) {
|
||||||
|
ask, cancel := context.WithTimeout(ctx, timeout)
|
||||||
|
defer cancel()
|
||||||
|
reply, err := b.JS.Conn().RequestWithContext(ask, "mesh.mod."+module+".tool."+tool, args)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("asking %s.%s: %w", module, tool, err)
|
||||||
|
}
|
||||||
|
return reply.Data, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// ConnectNats is Connect for the bus being built: the controller's inbound and outbound over one
|
||||||
|
// JetStream connection the caller has already raised the streams on. Nothing is declared here —
|
||||||
|
// the streams and the controller's consumers are asserted by Raise, before anything is served.
|
||||||
|
func ConnectNats(js *broker.JetStream, enroller Enroller, listener Listener) *Server {
|
||||||
|
return &Server{
|
||||||
|
inbound: Nats(js),
|
||||||
|
bus: OverNats{JS: js},
|
||||||
|
js: js,
|
||||||
|
enroller: enroller,
|
||||||
|
listener: listener,
|
||||||
|
log: newLog(),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Bus is the controller's outbound, whichever transport it connected over. Callers that send a
|
||||||
|
// declaration or ask a tool use this rather than the channel, which one transport does not have.
|
||||||
|
func (s *Server) Bus() Bus { return s.bus }
|
||||||
@@ -7,6 +7,7 @@ import (
|
|||||||
"encoding/json"
|
"encoding/json"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"github.com/novox/mesh-controller/internal/broker"
|
||||||
"log"
|
"log"
|
||||||
"os"
|
"os"
|
||||||
"time"
|
"time"
|
||||||
@@ -70,6 +71,7 @@ type Server struct {
|
|||||||
bus Bus
|
bus Bus
|
||||||
conn *amqp.Connection
|
conn *amqp.Connection
|
||||||
channel *amqp.Channel
|
channel *amqp.Channel
|
||||||
|
js *broker.JetStream
|
||||||
|
|
||||||
enroller Enroller
|
enroller Enroller
|
||||||
listener Listener
|
listener Listener
|
||||||
@@ -180,10 +182,12 @@ func Connect(enroller Enroller, listener Listener) (*Server, error) {
|
|||||||
channel: channel,
|
channel: channel,
|
||||||
enroller: enroller,
|
enroller: enroller,
|
||||||
listener: listener,
|
listener: listener,
|
||||||
log: log.New(os.Stdout, "", log.LstdFlags),
|
log: newLog(),
|
||||||
}, nil
|
}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func newLog() *log.Logger { return log.New(os.Stdout, "", log.LstdFlags) }
|
||||||
|
|
||||||
// Channel is the controller's channel, for the command line's own publishing.
|
// Channel is the controller's channel, for the command line's own publishing.
|
||||||
func (s *Server) Channel() *amqp.Channel { return s.channel }
|
func (s *Server) Channel() *amqp.Channel { return s.channel }
|
||||||
|
|
||||||
@@ -197,6 +201,9 @@ func (s *Server) Close() {
|
|||||||
if s.conn != nil {
|
if s.conn != nil {
|
||||||
_ = s.conn.Close()
|
_ = s.conn.Close()
|
||||||
}
|
}
|
||||||
|
if s.js != nil {
|
||||||
|
s.js.Close()
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Serve acts on what arrives until the context ends.
|
// Serve acts on what arrives until the context ends.
|
||||||
|
|||||||
+5
-4
@@ -23,7 +23,8 @@
|
|||||||
"licences": "/var/lib/mesh/mesh-controller/licences",
|
"licences": "/var/lib/mesh/mesh-controller/licences",
|
||||||
"broker": "/var/lib/mesh/mesh-controller/broker",
|
"broker": "/var/lib/mesh/mesh-controller/broker",
|
||||||
"broker-management": "/var/lib/mesh/mesh-controller/broker-management",
|
"broker-management": "/var/lib/mesh/mesh-controller/broker-management",
|
||||||
"broker-address": "/var/lib/mesh/mesh-controller/broker-address"
|
"broker-address": "/var/lib/mesh/mesh-controller/broker-address",
|
||||||
|
"bus": "/var/lib/mesh/mesh-controller/bus"
|
||||||
},
|
},
|
||||||
"secrets-owner": "65534:65534",
|
"secrets-owner": "65534:65534",
|
||||||
"resources": [
|
"resources": [
|
||||||
@@ -46,15 +47,14 @@
|
|||||||
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
|
"MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
|
||||||
"MESH_STORE_IDENTITY_FILE": "/run/secrets/identity",
|
"MESH_STORE_IDENTITY_FILE": "/run/secrets/identity",
|
||||||
"MESH_STORE_LICENCES_FILE": "/run/secrets/licences",
|
"MESH_STORE_LICENCES_FILE": "/run/secrets/licences",
|
||||||
"MESH_BROKER_AMQP_FILE": "/run/secrets/broker",
|
|
||||||
"MESH_BROKER_MANAGEMENT_FILE": "/run/secrets/broker-management",
|
"MESH_BROKER_MANAGEMENT_FILE": "/run/secrets/broker-management",
|
||||||
"MESH_BROKER_ADDRESS_FILE": "/run/secrets/broker-address",
|
"MESH_BROKER_ADDRESS_FILE": "/run/secrets/broker-address",
|
||||||
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
||||||
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
|
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
|
||||||
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
|
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
|
||||||
"MESH_BROKER_AMQP_PORT": "${seat:mesh-broker:5672}",
|
|
||||||
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
|
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
|
||||||
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}"
|
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
|
||||||
|
"MESH_BUS_NATS_FILE": "/run/secrets/bus"
|
||||||
},
|
},
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/mesh-broker-tls:/broker-tls:ro",
|
"/var/lib/mesh-broker-tls:/broker-tls:ro",
|
||||||
@@ -62,6 +62,7 @@
|
|||||||
"/var/lib/mesh/mesh-controller/identity:/run/secrets/identity:ro",
|
"/var/lib/mesh/mesh-controller/identity:/run/secrets/identity:ro",
|
||||||
"/var/lib/mesh/mesh-controller/licences:/run/secrets/licences:ro",
|
"/var/lib/mesh/mesh-controller/licences:/run/secrets/licences:ro",
|
||||||
"/var/lib/mesh/mesh-controller/broker:/run/secrets/broker:ro",
|
"/var/lib/mesh/mesh-controller/broker:/run/secrets/broker:ro",
|
||||||
|
"/var/lib/mesh/mesh-controller/bus:/run/secrets/bus:ro",
|
||||||
"/var/lib/mesh/mesh-controller/broker-management:/run/secrets/broker-management:ro",
|
"/var/lib/mesh/mesh-controller/broker-management:/run/secrets/broker-management:ro",
|
||||||
"/var/lib/mesh/mesh-controller/broker-address:/run/secrets/broker-address:ro"
|
"/var/lib/mesh/mesh-controller/broker-address:/run/secrets/broker-address:ro"
|
||||||
],
|
],
|
||||||
|
|||||||
Reference in New Issue
Block a user