The host says what filters the machine, with owners, and keeps the found firewall retired on every converged apply (hq ADR 0168)
Every table and chain that refuses traffic is reported with whose it is: the mesh's, the found firewall's, the container runtime's own, a ban, or other — the runtime's user chain is other, which is where both predecessors kept their rules, in the legacy filter on one machine and invisible to the mesh. Adoption's threshold does not move; a converged machine's report grows by its filters and its found firewall's state. Convergence is a state the host keeps: a found firewall enabled again is retired again and said; a reconcile that finds it inactive records that it was found so, never that the mesh did it; a step skipped after a failed apply is said. A retirement the mesh began and did not finish is finished. Fixtures are rulesets captured from three machines of the first mesh.
This commit is contained in:
+27
-1
@@ -1141,6 +1141,16 @@ func adoptionFingerprint(r link.Report) string {
|
||||
for _, h := range r.Held {
|
||||
parts = append(parts, "held "+h.ID+"="+h.Changed)
|
||||
}
|
||||
// And what filters the machine, with the found firewall's state (novox/hq ADR 0168): a rule the
|
||||
// operator removes between declarations, or a front end enabled again, is said at the next
|
||||
// reconcile rather than at the next push.
|
||||
for _, f := range r.Filters {
|
||||
parts = append(parts, "filter "+f.Owner+" "+f.Where+" "+f.Refuses)
|
||||
}
|
||||
if r.FoundFirewall != nil {
|
||||
parts = append(parts, fmt.Sprintf("found-firewall %s active=%v retired-by=%s", r.FoundFirewall.Kind,
|
||||
r.FoundFirewall.Active, r.FoundFirewall.RetiredBy))
|
||||
}
|
||||
for _, reach := range r.Reachable {
|
||||
parts = append(parts, fmt.Sprintf("reach %s %s:%d %s %v %d", reach.Protocol, reach.Address,
|
||||
reach.Port, reach.By, reach.Published, reach.ContainerPort))
|
||||
@@ -1289,7 +1299,8 @@ func worthSaying(report link.Report) bool {
|
||||
if report.Refused != "" {
|
||||
return false
|
||||
}
|
||||
return len(report.Held) > 0 || report.Firewall != "" || len(report.Outward) > 0
|
||||
return len(report.Held) > 0 || report.Firewall != "" || len(report.Outward) > 0 ||
|
||||
len(report.Filters) > 0 || report.FoundFirewall != nil
|
||||
}
|
||||
|
||||
// applyDeclared applies a declaration that has already been proved to come from the mesh.
|
||||
@@ -1440,6 +1451,21 @@ func applyAndKeep(ctx context.Context, opts options, raw []byte, signed *store.D
|
||||
report.Strays = append(report.Strays, link.Stray{Kind: s.Kind, Name: s.Name, Detail: s.Detail})
|
||||
}
|
||||
}
|
||||
// What filters this machine, with owners, whatever its mode (novox/hq ADR 0168): the mesh says
|
||||
// truthfully what filters a converged machine, and names what it did not write.
|
||||
ufwActive := firewall.Active(ctx, apply.ExecRunner)
|
||||
if filters, err := firewall.Collect(ctx, apply.ExecRunner, ufwActive); err != nil {
|
||||
fmt.Fprintf(os.Stderr, "mesh-host: applied, and could not read what filters this machine: %v\n", err)
|
||||
} else {
|
||||
for _, f := range filters {
|
||||
report.Filters = append(report.Filters, link.Filter{Where: f.Where, Owner: f.Owner, Refuses: f.Refuses})
|
||||
}
|
||||
}
|
||||
if declared.Adoption == nil && updated.Firewall != nil && updated.Firewall.Kind == string(firewall.UFW) && updated.Firewall.WasActive {
|
||||
// And, converged, the state of the firewall it was found with and who retired it.
|
||||
report.FoundFirewall = &link.FoundFirewall{Kind: updated.Firewall.Kind, Active: ufwActive,
|
||||
RetiredBy: updated.Firewall.RetiredBy}
|
||||
}
|
||||
if declared.Adoption != nil {
|
||||
if updated.Firewall != nil {
|
||||
report.Firewall = updated.Firewall.Kind
|
||||
|
||||
@@ -171,6 +171,22 @@ func TestAReconcileSpeaksOnlyWhenWhatIsHeldChanged(t *testing.T) {
|
||||
if !w.changed(link.Report{Firewall: "none", Held: rewritten.Held}) {
|
||||
t.Error("a changed firewall was not said")
|
||||
}
|
||||
// What filters the machine is part of it (novox/hq ADR 0168): a predecessor's chain removed by
|
||||
// hand, or the found firewall enabled again, is said without being asked.
|
||||
filtered := link.Report{Firewall: "none", Held: rewritten.Held,
|
||||
Filters: []link.Filter{{Where: "chain HAL-MESH-ONLY (iptables-legacy)", Owner: "other", Refuses: "-j DROP"}}}
|
||||
if !w.changed(filtered) {
|
||||
t.Error("a filter appearing was not said")
|
||||
}
|
||||
if !w.changed(link.Report{Firewall: "none", Held: rewritten.Held}) {
|
||||
t.Error("a filter removed was not said")
|
||||
}
|
||||
if !w.changed(link.Report{Firewall: "none", Held: rewritten.Held, FoundFirewall: &link.FoundFirewall{Kind: "ufw", Active: true}}) {
|
||||
t.Error("the found firewall coming back was not said")
|
||||
}
|
||||
if !worthSaying(link.Report{Filters: filtered.Filters}) {
|
||||
t.Error("a report carrying only what filters the machine is not worth saying")
|
||||
}
|
||||
}
|
||||
|
||||
func TestWhatTheLinkPublishedCountsAsSaid(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user