Being on the private network is what grants a machine the right to pull from the mesh's artifact store, so the module that puts a machine on the network writes the runtime's trust — a merged /etc/docker/daemon.json naming the store's internal name under insecure-registries, and a docker.service restart when that fact first lands. The registry speaks plain HTTP because every path to it is already inside the overlay's encryption; the provider is found, not configured — whichever module serves artifact-store, on whichever machine holds it — and with no store on the network nothing is written, which is genesis. https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
57 lines
1.7 KiB
Go
57 lines
1.7 KiB
Go
package overlay
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
func TestTheNetworkCarriesRegistryTrust(t *testing.T) {
|
|
// novox/hq ADR 0082: being on the network is what grants a machine the right to pull from the
|
|
// mesh's artifact store in the clear, so the network module writes the runtime's trust — and
|
|
// writes nothing when the mesh has no store to trust.
|
|
nodes := []Node{
|
|
{Name: "anchor", Site: "lab", Hub: true, Endpoint: "192.0.2.10:51820", Key: "k1", Address: "10.42.0.1"},
|
|
{Name: "node2", Site: "lab", Key: "k2", Address: "10.42.0.2"},
|
|
}
|
|
g, err := From(nodes, "10.42.0.0/16", "")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
plain, _, err := g.Resources("node2")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
for _, r := range plain {
|
|
if r["id"] == "registry-trust" {
|
|
t.Fatal("trust was written with no artifact store to trust")
|
|
}
|
|
}
|
|
|
|
g.TrustRegistry("anchor.internal:5000")
|
|
trusted, part, err := g.Resources("node2")
|
|
if err != nil || !part {
|
|
t.Fatalf("resources: %v part=%v", err, part)
|
|
}
|
|
var file, service map[string]any
|
|
for _, r := range trusted {
|
|
switch r["id"] {
|
|
case "registry-trust":
|
|
file = r
|
|
case "registry-trust-reload":
|
|
service = r
|
|
}
|
|
}
|
|
if file == nil || service == nil {
|
|
t.Fatalf("the trust file or its reload is missing: %v", trusted)
|
|
}
|
|
if file["path"] != "/etc/docker/daemon.json" || file["merge"] != "json" {
|
|
t.Fatalf("the trust is not a merged daemon.json: %v", file)
|
|
}
|
|
if content, _ := file["content"].(string); !strings.Contains(content, `"anchor.internal:5000"`) {
|
|
t.Fatalf("the trust does not name the store: %v", file["content"])
|
|
}
|
|
if service["unit"] != "docker.service" {
|
|
t.Fatalf("the reload does not restart the runtime: %v", service)
|
|
}
|
|
}
|