a container may name its resolvers and its own address
Mailu's 2024.06 admin refuses to serve behind a resolver that does not validate DNSSEC, and the runtime's own forwarder (127.0.0.11) validates nothing — so a module shipping its own validating resolver had a resolver nothing could be pointed at. Found live, blocking a cutover: the admin sat unhealthy, submission answered 454, and the declaration language had no words for the fix. Two fields on a container, both handed to the runtime verbatim: dns — the resolvers it asks — and ip, its static address on its user-defined network, which exists for exactly one shape: a container others must reach before name resolution works, the resolver itself being the case that forced it. Both take only addresses and are refused on arrival otherwise — a name here would reach the runtime verbatim and be refused at create, after the old container was already gone.
This commit is contained in:
@@ -403,3 +403,35 @@ func TestAContainerIsGivenItsEnvironmentFiles(t *testing.T) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// A container may name its resolvers and its own address — the shape a module shipping its own
|
||||
// validating DNS needs: the resolver pinned where its siblings can find it, the siblings pointed
|
||||
// at it. Both flags take addresses, so both reach the runtime verbatim.
|
||||
func TestAContainerIsGivenItsResolverAndItsAddress(t *testing.T) {
|
||||
var ran []string
|
||||
run := func(_ context.Context, name string, args ...string) (string, error) {
|
||||
ran = append(ran, name+" "+strings.Join(args, " "))
|
||||
if len(args) > 0 && args[0] == "container" {
|
||||
return "", fmt.Errorf("no such container")
|
||||
}
|
||||
return "", nil
|
||||
}
|
||||
d := declare(t, `{"id":"imap","type":"container","name":"mailu-imap",`+
|
||||
`"image":"dovecot@sha256:0000000000000000000000000000000000000000000000000000000000000000",`+
|
||||
`"network":"mailu","dns":["192.168.203.254"],"ip":"192.168.203.7"}`)
|
||||
|
||||
_, _, _ = Apply(context.Background(), archHost(t), d, store.State{},
|
||||
store.OriginDeclared, run, nil, nil)
|
||||
|
||||
var started string
|
||||
for _, line := range ran {
|
||||
if strings.Contains(line, "run ") {
|
||||
started = line
|
||||
}
|
||||
}
|
||||
for _, want := range []string{"--dns 192.168.203.254", "--ip 192.168.203.7"} {
|
||||
if !strings.Contains(started, want) {
|
||||
t.Errorf("the container was started without %q:\n%s", want, started)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user