daemon.json and docker.service belong to the docker module, which holds node-container-runtime
and now states the registry itself through ${seat:mesh-artifact-store:reach} (hq ADR 0222). The
overlay stops generating registry-trust and registry-trust-reload. A generated resource is now
held to the collision check every module is, so a second writer cannot come back through
computed code; resolution never saw what a generator declares.
31 lines
1.0 KiB
Go
31 lines
1.0 KiB
Go
package overlay
|
|
|
|
import (
|
|
"testing"
|
|
)
|
|
|
|
// novox/hq ADR 0222, issue 190: the runtime's file and service are the runtime's module's. The
|
|
// private network writes nothing into either — being on it still grants the right to pull from the
|
|
// mesh's store in the clear (ADR 0082), and the runtime's module states that trust itself.
|
|
func TestTheNetworkWritesNothingOfTheRuntimes(t *testing.T) {
|
|
nodes := []Node{
|
|
{Name: "anchor", Site: "lab", Hub: true, Endpoint: "192.0.2.10:51820", Key: "k1", Address: "10.42.0.1"},
|
|
{Name: "node2", Site: "lab", Key: "k2", Address: "10.42.0.2"},
|
|
}
|
|
g, err := From(nodes, "10.42.0.0/16", "")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
for _, node := range []string{"anchor", "node2"} {
|
|
resources, part, err := g.Resources(node)
|
|
if err != nil || !part {
|
|
t.Fatalf("%s: resources: %v part=%v", node, err, part)
|
|
}
|
|
for _, r := range resources {
|
|
if r["path"] == "/etc/docker/daemon.json" || r["unit"] == "docker.service" {
|
|
t.Errorf("%s: the private network declares the runtime's %v", node, r)
|
|
}
|
|
}
|
|
}
|
|
}
|