Converge openings through the firewall an adopted node was found with, and retire it only when the node converges (hq ADR 0100)
This commit is contained in:
+29
-2
@@ -150,8 +150,21 @@ func ApplyKeeping(
|
||||
declared[r.Identity()] = true
|
||||
}
|
||||
|
||||
// Which firewall is found here, before anything else, since an unsupported one refuses the
|
||||
// whole declaration (novox/hq ADR 0100). Nothing for a converged node.
|
||||
fw, err := foundFirewall(ctx, d, &known, run, log)
|
||||
if err != nil {
|
||||
return report, known, &Error{Resource: "the firewall found on this machine", Err: err, Done: report}
|
||||
}
|
||||
|
||||
for _, orphan := range known.Orphans(declared, origin) {
|
||||
action, detail, err := remove(ctx, sys, orphan, run)
|
||||
var action, detail string
|
||||
var err error
|
||||
if declaration.Type(orphan.Type) == declaration.TypeOpening {
|
||||
action, detail, err = removeOpening(ctx, orphan, run, known.Firewall)
|
||||
} else {
|
||||
action, detail, err = remove(ctx, sys, orphan, run)
|
||||
}
|
||||
if err != nil {
|
||||
return report, known, &Error{Resource: orphan.ID, Err: err, Done: report}
|
||||
}
|
||||
@@ -235,7 +248,13 @@ func ApplyKeeping(
|
||||
}
|
||||
|
||||
was, _ := known.Find(resource.Identity())
|
||||
outcome, err := applyOne(ctx, sys, resource, run, changed, declares, was, unseal)
|
||||
var outcome Outcome
|
||||
var err error
|
||||
if o, isOpening := resource.(*declaration.Opening); isOpening {
|
||||
outcome, err = applyOpening(ctx, o, run, fw)
|
||||
} else {
|
||||
outcome, err = applyOne(ctx, sys, resource, run, changed, declares, was, unseal)
|
||||
}
|
||||
if err != nil {
|
||||
failed := &Error{Resource: resource.Identity(), Err: err, Done: report}
|
||||
failures = append(failures, failed)
|
||||
@@ -293,6 +312,14 @@ func ApplyKeeping(
|
||||
}
|
||||
}
|
||||
|
||||
// A converged node whose found firewall was in force retires it only now, once everything —
|
||||
// the mesh's derived filter among it — applied cleanly (novox/hq ADR 0100).
|
||||
if len(failures) == 0 {
|
||||
if err := retireFirewall(ctx, d, &known, run, log); err != nil {
|
||||
return report, known, &Error{Resource: "the firewall found on this machine", Err: err, Done: report}
|
||||
}
|
||||
}
|
||||
|
||||
if len(failures) > 0 {
|
||||
// The first, carrying everything that did happen. One error is what the caller reports
|
||||
// and what a person reads first; the rest are in the report, which is what the mesh
|
||||
|
||||
Reference in New Issue
Block a user