Connectivity was code beside the module system doing the module system's
job: every machine with an address was on the private network and there
was no way to keep one off.
A manifest can now say its resources are computed by the control plane,
which is what a peer list needs — it is derived from every machine at
once, so nothing could be written in advance. The network is a module
from there on: assigned, resolved, settled, and absent from a machine
nobody gave it to.
Three modules rather than one, because WireGuard is one VPN of several:
mesh-wireguard provides private-network, mesh-addressing
claims the-private-network, one per node
mesh-names provides name-resolution, requires mesh-addressing
networking requires both, and ships no files of its own
The last is the point. Most people want the network up and do not want
to choose a VPN, so `assign networking` takes the only answer to each
requirement silently. The day the catalogue holds a second one there are
two answers, the resolver refuses and names them, and choosing is
assigning the one you want. No flavor field, nothing to configure.
Names left the WireGuard declaration for their own module. They would be
identical over a different private network, and bundling them made one
module out of two things.
Three faults the walk found:
- choosing tailscale still installed WireGuard, dragged back in by the
names needing the mesh's own addresses. Caught now by a claim: running
two VPNs is fine, being *the* mesh network is singular.
- a requirement wanted by two modules was reported twice, identically.
- "this mesh has no hub" was reported when the real cause was that a
node could not be resolved at all. It now names the node and the why.
And a test that asserts the manifests actually shipped, after the claim
went missing from the real one while every test stayed green.
62 lines
2.1 KiB
Go
62 lines
2.1 KiB
Go
package overlay
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// Names are their own module.
|
|
//
|
|
// They used to arrive inside the WireGuard declaration, on the argument that a machine with peers
|
|
// and no names is half on the network. True, and the wrong place to fix it: names would be
|
|
// identical over a different private network, so bundling them made one module out of two things.
|
|
|
|
func TestAMachineNotOnTheNetworkGetsNoNames(t *testing.T) {
|
|
// Names resolve to addresses on the private wire. Giving them to a machine that is not on it
|
|
// would point every lookup somewhere it cannot reach — worse than having no names at all.
|
|
g := NamesFor([]Node{at("anchor", "dc", "10.42.0.1", "198.51.100.10:51820", true)})
|
|
_, part, err := g.Resources("laptop")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if part {
|
|
t.Fatal("a machine that is not on the private network was given the mesh's names")
|
|
}
|
|
}
|
|
|
|
func TestTheNamesAreOneFileAndSayWhoIsAsking(t *testing.T) {
|
|
g := NamesFor([]Node{
|
|
at("anchor", "dc", "10.42.0.1", "198.51.100.10:51820", true),
|
|
at("workstation", "house", "10.42.0.2", "", false),
|
|
})
|
|
out, part, err := g.Resources("workstation")
|
|
if err != nil || !part {
|
|
t.Fatalf("part=%v err=%v", part, err)
|
|
}
|
|
if len(out) != 1 || out[0]["path"] != HostsPath {
|
|
t.Fatalf("got %v", out)
|
|
}
|
|
content := out[0]["content"].(string)
|
|
if !strings.Contains(content, "anchor.internal") {
|
|
t.Fatalf("another machine on the network has no name here:\n%s", content)
|
|
}
|
|
if !strings.Contains(content, "this machine") {
|
|
t.Fatalf("the file does not say which machine it is on:\n%s", content)
|
|
}
|
|
}
|
|
|
|
func TestTheWireGuardDeclarationNoLongerCarriesTheNames(t *testing.T) {
|
|
// The split, asserted. Two modules, so a machine can have the peers from one and the names
|
|
// from another — which is what makes a second VPN possible at all.
|
|
raw, err := Declaration(
|
|
at("workstation", "house", "10.42.0.2", "", false),
|
|
[]Peer{{Name: "anchor", Key: "PUB", Allowed: "10.42.0.0/16",
|
|
Endpoint: "198.51.100.10:51820"}}, "")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if strings.Contains(string(raw), HostsPath) {
|
|
t.Fatalf("the WireGuard declaration still writes %s", HostsPath)
|
|
}
|
|
}
|