Raise a machine in use adopted: keep its firewall, load no dropping table, guard the mesh's own ports, and take only the mesh's own modules (hq ADR 0100)
This commit is contained in:
@@ -34,6 +34,8 @@ import (
|
||||
"fmt"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/novox/mesh-host/internal/firewall"
|
||||
)
|
||||
|
||||
// Step names one stage. A failure says which one, because "the bootstrap failed" is a sentence
|
||||
@@ -377,6 +379,23 @@ func Run(ctx context.Context, o Options, d Deps, say func(string)) (Result, erro
|
||||
|
||||
// Which half of the host applies things here. Asked of the machine and proved, because
|
||||
// `mesh-host` pins this at link time and an installer run by hand has no link time.
|
||||
// An adopted machine keeps the firewall it was found with, so the mesh must speak it; one no
|
||||
// host speaks is refused here, before anything changes (novox/hq ADR 0100).
|
||||
if o.Adopted {
|
||||
kind, name, err := firewall.Detect(ctx, d.Run)
|
||||
if err != nil {
|
||||
return result, failed(StepPreflight, err)
|
||||
}
|
||||
if kind == firewall.Unsupported {
|
||||
return result, failed(StepPreflight, fmt.Errorf(
|
||||
"this machine is filtered by %s, and no host speaks that firewall yet. An adopted "+
|
||||
"machine keeps its firewall in force, so the mesh could neither open what it needs "+
|
||||
"through it nor say what it would close. Nothing was changed", name))
|
||||
}
|
||||
result.Firewall = string(kind)
|
||||
say(" adopted what is on this machine is kept; its firewall (" + string(kind) + ") stays in force")
|
||||
}
|
||||
|
||||
sys, err := WorkOutSystem(ctx, d.Run, o.System)
|
||||
if err != nil {
|
||||
return result, failed(StepPreflight, err)
|
||||
@@ -444,6 +463,14 @@ func Run(ctx context.Context, o Options, d Deps, say func(string)) (Result, erro
|
||||
if moved.Places > 0 {
|
||||
say(fmt.Sprintf(" ports %d place(s) rewritten to this node's foundation ports", moved.Places))
|
||||
}
|
||||
if o.Adopted {
|
||||
adopted, err := RewriteAdopted(&rewritten, o.Ports)
|
||||
if err != nil {
|
||||
return result, failed(StepBundle, err)
|
||||
}
|
||||
say(fmt.Sprintf(" adopted bundle the foundation's filter is not loaded (%s); the mesh's guard refuses %v from outside",
|
||||
strings.Join(adopted.Removed, ", "), adopted.Guarded))
|
||||
}
|
||||
for _, c := range []struct {
|
||||
what, path string
|
||||
made bool
|
||||
@@ -718,7 +745,9 @@ func Run(ctx context.Context, o Options, d Deps, say func(string)) (Result, erro
|
||||
|
||||
// ---- 17. filter -----------------------------------------------------------------------
|
||||
say("filter — required, so the question is which, not whether")
|
||||
if err := ChooseAndInstallFilter(ctx, o, permanentControl, say); err != nil {
|
||||
filter, err := ChooseAndInstallFilter(ctx, o, permanentControl, say)
|
||||
result.Filter = filter
|
||||
if err != nil {
|
||||
return result, failed(StepFilter, err)
|
||||
}
|
||||
|
||||
@@ -736,6 +765,12 @@ func Run(ctx context.Context, o Options, d Deps, say func(string)) (Result, erro
|
||||
return result, failed(StepExport, err)
|
||||
}
|
||||
|
||||
if o.Adopted {
|
||||
say("\nthis machine is a mesh of one adopted node: it builds its own software, holds its graph " +
|
||||
"and sits on its private network, and what it ran before is kept as it was, behind the firewall " +
|
||||
"it was found with. Take each module on it once its data has moved; converge it when done.")
|
||||
return result, nil
|
||||
}
|
||||
say("\nthis machine is a mesh of one node: it builds its own software, holds its graph, " +
|
||||
"sits on its private network, and filters what modules declared.")
|
||||
say("what remains is somebody else's: adding nodes, and assigning what they should run.")
|
||||
|
||||
Reference in New Issue
Block a user