Adoption mode: a node in use is adopted before it is converged (hq ADR 0100–0103) #44

Merged
jschoubben merged 33 commits from feat/adoption-mode into main 2026-09-22 19:01:51 +00:00
Showing only changes of commit fad8b30e43 - Show all commits
+10
View File
@@ -159,6 +159,16 @@ func Published(resources []map[string]any) map[string]map[int]int {
// prerouting, ahead of the runtime's destination translation, so it matches the port the packet // prerouting, ahead of the runtime's destination translation, so it matches the port the packet
// was sent to; in the inet family, so both address families. // was sent to; in the inet family, so both address families.
// //
// **The machine's own interfaces are named, where the derived filter names address ranges.** The
// filter accepts the container runtime's networks by CIDR; this excludes its bridges by name — lo,
// docker0, the br-* a compose network gets, and the mesh's own mesh0. A runtime whose bridge is
// named anything else (a podman or libvirt bridge, or a docker network created with a fixed name)
// would have its containers' traffic to a guarded port refused, which reads as the port being
// down. Names rather than addresses is deliberate: a source address can be claimed by whoever
// sends the packet, and this table exists to refuse what the found firewall never sees. Widening
// it means adding names here and in the installer's copy together, which the golden test holds to
// one text.
//
// The same text the installer raises on an adopted genesis; a test holds both to it. // The same text the installer raises on an adopted genesis; a test holds both to it.
func AsGuard(ports []int) string { func AsGuard(ports []int) string {
sorted := append([]int{}, ports...) sorted := append([]int{}, ports...)