bootstrap: the mesh hearing from a machine is not an agent running on it
Enrolling IS the machine speaking to the mesh, so straight after it the mesh has always heard from this node — and the step took that as proof an agent was running and skipped starting one. The cost is silent and total. Everything after is the control plane being told things, and nothing it is told reaches a machine with no agent to collect it: the registry push at step 7 was accepted, the module recorded, and no container ever created. It surfaced three minutes later as 'the registry is not there at all', one step from its cause and looking nothing like it. Both halves are asked now. A process may be wedged and collect nothing, which is why the mesh is asked at all; and the mesh may have heard once from a machine running nothing, which is why the machine is asked too. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -59,12 +59,17 @@ func TestAMachineThatHasAlreadyEnrolledIsNotEnrolledAgain(t *testing.T) {
|
||||
switch {
|
||||
case strings.Contains(joined, "node list"):
|
||||
return "anchor here 01J0\n", nil
|
||||
// An agent is running here too. Both halves are needed: enrolling makes the mesh hear from
|
||||
// a machine once, so the first answer alone also describes a machine with no agent at all.
|
||||
case name == "pgrep":
|
||||
return "4242\n", nil
|
||||
}
|
||||
return "", fmt.Errorf("unexpected: %s %v", name, args)
|
||||
}}
|
||||
|
||||
out, err := Enrol(context.Background(), Options{
|
||||
Node: "anchor", State: alreadyEnrolled(t, "anchor"), Timeout: time.Second,
|
||||
Host: "/usr/local/bin/mesh-host", HostInBackground: true,
|
||||
}, arch(t), controlPlane{container: "temp-mesh-control", run: runtime.run, timeout: time.Second},
|
||||
func(string) {})
|
||||
if err != nil {
|
||||
@@ -82,6 +87,41 @@ func TestAMachineThatHasAlreadyEnrolledIsNotEnrolledAgain(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// The mesh having heard from a machine is not the same as an agent running on it, and enrolling is
|
||||
// itself the thing that makes the mesh hear. Taken as proof of life it ends the step believing an
|
||||
// agent it never started, and everything after is the control plane being told things that never
|
||||
// reach the machine: the next push is accepted, recorded, and applied by nobody.
|
||||
func TestAMeshThatHasHeardFromAMachineWithNoAgentStartsOne(t *testing.T) {
|
||||
runtime := &asked{answer: func(name string, args []string) (string, error) {
|
||||
joined := strings.Join(args, " ")
|
||||
switch {
|
||||
case strings.Contains(joined, "node list"):
|
||||
// Exactly what enrolling leaves behind, with nothing running.
|
||||
return "anchor here 01J0\n", nil
|
||||
case name == "pgrep":
|
||||
return "", fmt.Errorf("exit status 1")
|
||||
case name == "sh":
|
||||
return "", nil
|
||||
}
|
||||
return "", fmt.Errorf("unexpected: %s %v", name, args)
|
||||
}}
|
||||
|
||||
out, err := Enrol(context.Background(), Options{
|
||||
Node: "anchor", State: alreadyEnrolled(t, "anchor"), Timeout: time.Second,
|
||||
Host: "/usr/local/bin/mesh-host", HostInBackground: true,
|
||||
}, arch(t), controlPlane{container: "temp-mesh-control", run: runtime.run, timeout: time.Second},
|
||||
func(string) {})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if out.Agent == "already running" {
|
||||
t.Fatal("a machine with no agent was reported as already running it")
|
||||
}
|
||||
if !runtime.ran("nohup") {
|
||||
t.Errorf("no agent was started on a machine that has none: %v", runtime.commands)
|
||||
}
|
||||
}
|
||||
|
||||
// A machine already enrolled under ANOTHER name is refused, with what to do about it. Re-enrolling
|
||||
// replaces the identity the mesh recorded, which is a deliberate act and not something an
|
||||
// installer does on its own.
|
||||
|
||||
Reference in New Issue
Block a user