A service can be declared to reflect a file
Because a running service does not re-read its configuration. Replace the file, find the service running, do nothing -- and the machine keeps behaving as it did while every check passes, because the file is right and the service is up. That is not hypothetical. It is how a third node joining a mesh left the first two carrying a private network that no longer existed, with every part of it reporting success. Declared state rather than a command: the declaration says the running service must reflect these files, and the host works out that it does not. A command to restart would be an action, and the link may not carry one -- the host refused precisely that when I tried it, correctly, which is how this shape was arrived at rather than the other. Scoped to one apply. A change from an earlier one has already been reflected, and restarting for it every time would make a steady machine bounce its services for ever. Also: the node generates its overlay key at enrolment and reports the public half, and the store waits three minutes rather than one for the database -- sixty seconds is not enough for a cold machine running initdb, and it failed that way three times, which is the worst kind of flake because a second run always fixed it.
This commit is contained in:
+16
-6
@@ -23,10 +23,19 @@ func QueueFor(node string) string { return "node." + node }
|
||||
|
||||
// EnrolRequest is what this node says when joining.
|
||||
type EnrolRequest struct {
|
||||
Node string `json:"node"`
|
||||
Secret string `json:"secret"`
|
||||
PublicKey []byte `json:"public_key"`
|
||||
Profile map[string]any `json:"profile,omitempty"`
|
||||
Node string `json:"node"`
|
||||
Secret string `json:"secret"`
|
||||
PublicKey []byte `json:"public_key"`
|
||||
|
||||
// OverlayKey is the public half of this node's key on the private network — a different key
|
||||
// from PublicKey above, generated at the same moment and for a different purpose.
|
||||
//
|
||||
// Sent with enrolment because the overlay is the first declaration a node receives, and the
|
||||
// mesh cannot compose it without this. Asking for it afterwards would mean a node is enrolled
|
||||
// and unreachable for a round trip, which is the state everything else here works to avoid.
|
||||
OverlayKey string `json:"overlay_key,omitempty"`
|
||||
|
||||
Profile map[string]any `json:"profile,omitempty"`
|
||||
}
|
||||
|
||||
// EnrolReply is what the mesh says back.
|
||||
@@ -56,7 +65,7 @@ var ErrRefused = errors.New("the mesh refused this enrolment")
|
||||
// says once it is in, and the secret travels again because the control plane must not have to ask
|
||||
// the broker who connected.
|
||||
func Enrol(ctx context.Context, address, pin, node, secret string, public []byte,
|
||||
profile map[string]any, timeout time.Duration) (EnrolReply, error) {
|
||||
overlayKey string, profile map[string]any, timeout time.Duration) (EnrolReply, error) {
|
||||
|
||||
config, err := PinnedConfig(pin)
|
||||
if err != nil {
|
||||
@@ -101,7 +110,8 @@ func Enrol(ctx context.Context, address, pin, node, secret string, public []byte
|
||||
return EnrolReply{}, err
|
||||
}
|
||||
|
||||
request := EnrolRequest{Node: node, Secret: secret, PublicKey: public, Profile: profile}
|
||||
request := EnrolRequest{Node: node, Secret: secret, PublicKey: public,
|
||||
OverlayKey: overlayKey, Profile: profile}
|
||||
body, err := json.Marshal(request)
|
||||
if err != nil {
|
||||
return EnrolReply{}, err
|
||||
|
||||
Reference in New Issue
Block a user