a container may name its resolvers and its own address
Mailu's 2024.06 admin refuses to serve behind a resolver that does not validate DNSSEC, and the runtime's own forwarder (127.0.0.11) validates nothing — so a module shipping its own validating resolver had a resolver nothing could be pointed at. Found live, blocking a cutover: the admin sat unhealthy, submission answered 454, and the declaration language had no words for the fix. Two fields on a container, both handed to the runtime verbatim: dns — the resolvers it asks — and ip, its static address on its user-defined network, which exists for exactly one shape: a container others must reach before name resolution works, the resolver itself being the case that forced it. Both take only addresses and are refused on arrival otherwise — a name here would reach the runtime verbatim and be refused at create, after the old container was already gone.
This commit is contained in:
@@ -427,3 +427,27 @@ func TestASecretTheContentNeverUsesIsRefused(t *testing.T) {
|
||||
t.Fatal("a secret the content never mentions was accepted")
|
||||
}
|
||||
}
|
||||
|
||||
// The runtime's resolver and address flags take only addresses; a name would be refused at
|
||||
// create, after the old container was already gone. Refused on arrival instead — and an address
|
||||
// without a user-defined network is refused for the same reason.
|
||||
func TestAContainersResolverAndAddressAreAddressesOrRefused(t *testing.T) {
|
||||
refused := func(body string) []string {
|
||||
_, err := Parse([]byte(`{"declaration":1,"resources":[` + body + `]}`))
|
||||
if err == nil {
|
||||
return nil
|
||||
}
|
||||
return []string{err.Error()}
|
||||
}
|
||||
base := `"id":"c","type":"container","name":"x",` +
|
||||
`"image":"a@sha256:0000000000000000000000000000000000000000000000000000000000000000"`
|
||||
if p := refused(`{` + base + `,"network":"m","dns":["resolver.local"]}`); len(p) == 0 {
|
||||
t.Error("a resolver named by name was accepted; the runtime takes only addresses")
|
||||
}
|
||||
if p := refused(`{` + base + `,"ip":"192.168.203.7"}`); len(p) == 0 {
|
||||
t.Error("a static address with no network was accepted; the runtime refuses it")
|
||||
}
|
||||
if p := refused(`{` + base + `,"network":"m","dns":["192.168.203.254"],"ip":"192.168.203.7"}`); len(p) != 0 {
|
||||
t.Errorf("a well-formed resolver and address were refused: %v", p)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user