The forward chain blocked everything passing through the machine and then allowed the machine's own containers back by naming their address ranges: 172.16.0.0/12 and 192.168.128.0/17 fixed here, the rest recorded per machine by 0043. Every way of keeping that list correct fails — a constant describes one machine, a recorded range goes stale in silence and cannot tell a network the mesh made from one a predecessor left behind, and generating it from the modules would put half the rule set on the machine. The mesh has no position on a container reaching outward: that is not a port opened to anybody. So both chains are written around the links traffic arrives on. What did not arrive from outside is accepted in one line; what did meets the declared rules. The tunnel is named beside the outward links rather than treated as inside, or a port nothing declares would be reachable from every machine in the mesh. A machine that has not reported an outward link is sent no filter and keeps the one it has, refused where a person reads it rather than as a rule set that will not load. Removes the two constants, `node networks`, and the column behind it. novox/hq ADR 0140, superseding 0137 and 0139.
27 lines
1.7 KiB
SQL
27 lines
1.7 KiB
SQL
-- Which of a machine's links face outside it, replacing the networks it was told to say it routes.
|
|
--
|
|
-- novox/hq ADR 0140, superseding 0137 and 0139. The derived filter blocked everything passing
|
|
-- through a machine and then allowed the machine's own containers back by naming the address ranges
|
|
-- they sit on: two ranges fixed in the controller's source, the rest recorded by 0043's column.
|
|
--
|
|
-- Every route to a correct list fails. A constant describes one machine. A recorded range goes stale
|
|
-- in silence, and cannot tell a network the mesh made from one a predecessor left behind — measured
|
|
-- on the control-node, where six ranges fall outside the constants and two of the six belong to
|
|
-- services the mesh does not run. Generating the list from the modules put half the rule set on the
|
|
-- machine.
|
|
--
|
|
-- The list should not exist, because the mesh has no position on a container reaching outward: that
|
|
-- is not a port opened to anybody. The filter constrains what arrives from OUTSIDE the machine and
|
|
-- says nothing about what did not, which needs one fact instead of a list — which links "outside"
|
|
-- arrives on.
|
|
--
|
|
-- Reported by the machine on every apply, never recorded by hand, so it cannot go stale. Null for a
|
|
-- machine that has not reported yet; the mesh composes no filter for such a machine and leaves the
|
|
-- one it has, because a rule written around a link with no name is a rule set that does not load.
|
|
alter table node add column outward_links jsonb;
|
|
|
|
-- What 0043 recorded is not migrated into it. The ranges answered a question that no longer exists,
|
|
-- and every machine that named one keeps working without it: the traffic those ranges allowed is now
|
|
-- allowed by not having arrived from outside.
|
|
alter table node drop column routed_networks;
|