Internal names are written to the machine's hosts file, which serves the machine and not what the machine runs: a container gets its own hosts file holding only its own hostname. So every name the mesh wrote was invisible to the majority of things that need one — and on the machine it always worked, which is exactly what made it easy to miss. It was hit for real in the lab, and worked around by resolving the address on the machine and passing it in. That workaround is now removed, and its absence is the assertion. A file rather than a resolver, which is the decision the mesh already made about names and this extends rather than overturns: it works on every runtime, needs no package and has no failure mode of its own. The stated trigger for a resolver — names that are not one-per-node, service names, wildcards — is still not met. Given by the mesh, not chosen by a module: a module that listed the machines would go stale the day one joins, and one that did not would be a module whose containers cannot reach anything by name. A container that named its own keeps them and gets the mesh's beside them. Only containers, and not the ones on the machine's own network: a runtime refuses to write a hosts file for those, and a file or a service given the field is a declaration the host refuses outright — so getting it wrong breaks the whole machine for something that was never about names.
144 lines
5.4 KiB
Go
144 lines
5.4 KiB
Go
package catalogue
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
func containersOf(t *testing.T, r Resolution, with Rendering) []map[string]any {
|
|
t.Helper()
|
|
out, err := r.Declaration(with)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
var found []map[string]any
|
|
for _, res := range out {
|
|
if res["type"] == "container" {
|
|
found = append(found, res)
|
|
}
|
|
}
|
|
return found
|
|
}
|
|
|
|
func namesOf(r map[string]any) []string {
|
|
var out []string
|
|
if given, ok := r["hosts"].([]any); ok {
|
|
for _, h := range given {
|
|
out = append(out, h.(string))
|
|
}
|
|
}
|
|
return out
|
|
}
|
|
|
|
// A container does not inherit the machine's names, so the mesh gives them to it.
|
|
//
|
|
// It gets its own hosts file holding only its own hostname — every internal name the mesh wrote
|
|
// for the machine is invisible to what the machine runs. A database client on one node could not
|
|
// resolve another node, on a mesh where both names were correct and present on both machines.
|
|
func TestEveryContainerIsGivenTheMeshsNames(t *testing.T) {
|
|
got := containersOf(t, Resolution{Node: "laptop", Modules: []Manifest{{
|
|
Module: "app",
|
|
Resources: []map[string]any{{"id": "web", "type": "container", "name": "web",
|
|
"image": "registry.example/web@sha256:" + strings.Repeat("a", 64)}},
|
|
}}}, Rendering{Names: map[string]string{
|
|
"anchor.internal": "10.42.0.1", "laptop.internal": "10.42.0.2",
|
|
}})
|
|
if len(got) != 1 {
|
|
t.Fatalf("expected one container, got %d", len(got))
|
|
}
|
|
given := namesOf(got[0])
|
|
if len(given) != 2 {
|
|
t.Fatalf("the container was given %d name(s): %v", len(given), given)
|
|
}
|
|
if given[0] != "anchor.internal:10.42.0.1" {
|
|
t.Fatalf("the name is not in the form a runtime writes: %v", given)
|
|
}
|
|
}
|
|
|
|
// A container that named its own keeps them and gets the mesh's beside them.
|
|
//
|
|
// The mesh does not know what else a workload needs to reach, and taking something away in order
|
|
// to add something is not what "also" means.
|
|
func TestAContainersOwnNamesAreKept(t *testing.T) {
|
|
got := containersOf(t, Resolution{Node: "laptop", Modules: []Manifest{{
|
|
Module: "app",
|
|
Resources: []map[string]any{{"id": "web", "type": "container", "name": "web",
|
|
"image": "registry.example/web@sha256:" + strings.Repeat("a", 64),
|
|
"hosts": []any{"something.else:203.0.113.9"}}},
|
|
}}}, Rendering{Names: map[string]string{"anchor.internal": "10.42.0.1"}})
|
|
|
|
given := namesOf(got[0])
|
|
if len(given) != 2 || given[0] != "something.else:203.0.113.9" {
|
|
t.Fatalf("the container's own names were lost: %v", given)
|
|
}
|
|
}
|
|
|
|
// A container on the machine's own network already shares its hosts file, and a runtime refuses
|
|
// to write one for it — so adding names there fails the whole container for something it did not
|
|
// need.
|
|
func TestAContainerOnTheMachinesNetworkIsLeftAlone(t *testing.T) {
|
|
got := containersOf(t, Resolution{Node: "anchor", Modules: []Manifest{{
|
|
Module: "control",
|
|
Resources: []map[string]any{{"id": "c", "type": "container", "name": "c",
|
|
"image": "registry.example/c@sha256:" + strings.Repeat("a", 64), "network": "host"}},
|
|
}}}, Rendering{Names: map[string]string{"anchor.internal": "10.42.0.1"}})
|
|
|
|
if len(namesOf(got[0])) != 0 {
|
|
t.Fatalf("a host-networked container was given names a runtime will refuse: %v", got[0])
|
|
}
|
|
}
|
|
|
|
// A mesh with no private network gives nothing, rather than a name with no address behind it.
|
|
func TestAMeshWithNoNamesGivesNone(t *testing.T) {
|
|
got := containersOf(t, Resolution{Node: "alone", Modules: []Manifest{{
|
|
Module: "app",
|
|
Resources: []map[string]any{{"id": "web", "type": "container", "name": "web",
|
|
"image": "registry.example/web@sha256:" + strings.Repeat("a", 64)}},
|
|
}}}, Rendering{})
|
|
if len(namesOf(got[0])) != 0 {
|
|
t.Fatalf("names were invented for a mesh that has none: %v", got[0])
|
|
}
|
|
}
|
|
|
|
// The catalogue's copy is not edited: these maps come from a manifest, and mutating one would
|
|
// change what every other machine running that module is given.
|
|
func TestGivingNamesDoesNotChangeTheCatalogue(t *testing.T) {
|
|
held := map[string]any{"id": "web", "type": "container", "name": "web",
|
|
"image": "registry.example/web@sha256:" + strings.Repeat("a", 64)}
|
|
module := Manifest{Module: "app", Resources: []map[string]any{held}}
|
|
|
|
for _, node := range []string{"one", "two"} {
|
|
containersOf(t, Resolution{Node: node, Modules: []Manifest{module}},
|
|
Rendering{Names: map[string]string{"anchor.internal": "10.42.0.1"}})
|
|
}
|
|
if _, changed := held["hosts"]; changed {
|
|
t.Fatal("the manifest the catalogue holds was edited, so every machine now carries this")
|
|
}
|
|
}
|
|
|
|
// Only containers. A file or a service given a `hosts` key is a declaration the host refuses
|
|
// outright — it takes no unknown field — so getting this wrong breaks the whole machine rather
|
|
// than one resource, and breaks it for something that was never about names.
|
|
func TestNothingButAContainerIsGivenNames(t *testing.T) {
|
|
out, err := Resolution{Node: "laptop", Modules: []Manifest{{
|
|
Module: "app",
|
|
Resources: []map[string]any{
|
|
{"id": "conf", "type": "file", "path": "/etc/app.conf", "content": "x", "mode": "0644"},
|
|
{"id": "run", "type": "service", "unit": "app.service", "state": "running"},
|
|
{"id": "web", "type": "container", "name": "web",
|
|
"image": "registry.example/web@sha256:" + strings.Repeat("a", 64)},
|
|
},
|
|
}}}.Declaration(Rendering{Names: map[string]string{"anchor.internal": "10.42.0.1"}})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
for _, r := range out {
|
|
if r["type"] == "container" {
|
|
continue
|
|
}
|
|
if _, given := r["hosts"]; given {
|
|
t.Fatalf("a %v was given names, which the host will refuse: %v", r["type"], r)
|
|
}
|
|
}
|
|
}
|