The host says what filters the machine, with owners, and keeps the found firewall retired on every converged apply (hq ADR 0168)
Every table and chain that refuses traffic is reported with whose it is: the mesh's, the found firewall's, the container runtime's own, a ban, or other — the runtime's user chain is other, which is where both predecessors kept their rules, in the legacy filter on one machine and invisible to the mesh. Adoption's threshold does not move; a converged machine's report grows by its filters and its found firewall's state. Convergence is a state the host keeps: a found firewall enabled again is retired again and said; a reconcile that finds it inactive records that it was found so, never that the mesh did it; a step skipped after a failed apply is said. A retirement the mesh began and did not finish is finished. Fixtures are rulesets captured from three machines of the first mesh.
This commit is contained in:
+15
-2
@@ -27,6 +27,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/novox/mesh-host/internal/declaration"
|
||||
"github.com/novox/mesh-host/internal/firewall"
|
||||
"github.com/novox/mesh-host/internal/store"
|
||||
"github.com/novox/mesh-host/internal/system"
|
||||
)
|
||||
@@ -67,6 +68,10 @@ type Outcome struct {
|
||||
// Report is what an apply did, in the order it did it.
|
||||
type Report struct {
|
||||
Outcomes []Outcome `json:"outcomes"`
|
||||
// Firewall is what this apply did about the firewall a converged machine was found with, when
|
||||
// it did or declined anything: retired, retired again, or left in force and why (novox/hq ADR
|
||||
// 0168). Said rather than an outcome: the plan says the same step the same way.
|
||||
Firewall string `json:"firewall,omitempty"`
|
||||
// Tunnel is what this apply says about the tunnel the private network took over, when the
|
||||
// declaration names one (novox/hq ADR 0105).
|
||||
Tunnel *TakenTunnel `json:"tunnel,omitempty"`
|
||||
@@ -611,16 +616,24 @@ func ApplyKeeping(
|
||||
}
|
||||
|
||||
// A converged node whose found firewall was in force retires it only now, once everything —
|
||||
// the mesh's derived filter among it — applied cleanly (novox/hq ADR 0100).
|
||||
// the mesh's derived filter among it — applied cleanly (novox/hq ADR 0100), and on every
|
||||
// converged apply, not once (ADR 0168). Skipped, it is said: a step that does nothing is never
|
||||
// silent (issue 143).
|
||||
if len(failures) == 0 {
|
||||
if err := retireFirewall(ctx, d, origin, &known, run, log); err != nil {
|
||||
did, err := retireFirewall(ctx, d, origin, &known, run, log)
|
||||
if err != nil {
|
||||
return report, known, &Error{Resource: "the firewall found on this machine", Err: err, Done: report}
|
||||
}
|
||||
report.Firewall = did
|
||||
for _, orphan := range protecting {
|
||||
if err := removeOrphan(orphan); err != nil {
|
||||
return report, known, err
|
||||
}
|
||||
}
|
||||
} else if rec := known.Firewall; origin == store.OriginDeclared && d.Adoption == nil && rec != nil &&
|
||||
rec.Kind == string(firewall.UFW) && rec.WasActive && firewall.Active(ctx, run) {
|
||||
report.Firewall = fmt.Sprintf("left in force: %d resource(s) failed, and the found firewall is retired only after a clean apply", len(failures))
|
||||
log(" kept ufw in force: " + report.Firewall)
|
||||
}
|
||||
|
||||
if len(failures) > 0 {
|
||||
|
||||
+41
-12
@@ -54,20 +54,43 @@ func foundFirewall(ctx context.Context, d *declaration.Declaration, known *store
|
||||
return kind, nil
|
||||
}
|
||||
|
||||
// retireFirewall disables the found firewall once a converged declaration has applied cleanly,
|
||||
// which is when the mesh's derived filter has taken its place. Disabled, never flushed: its
|
||||
// configuration stays on disk for a return to adopted, and the container runtime's rules are not
|
||||
// its to take.
|
||||
// retireFirewall keeps the found firewall retired on a converged machine (novox/hq ADR 0100, ADR
|
||||
// 0168): disabled, never flushed, its configuration left on disk for a return to adopted, and the
|
||||
// container runtime's rules not its to take.
|
||||
//
|
||||
// **Convergence is a state the host keeps, not a step it takes once.** Every converged apply reads
|
||||
// whether the front end is in force; enabled again by a package, a boot or a hand, it is retired
|
||||
// again and said. The record says how it came to be inactive — the mesh disabled it, or a reconcile
|
||||
// found it so — and the two are never confused: a flip that did not take, followed by a hand that
|
||||
// did, used to be recorded as the mesh's doing (issue 143).
|
||||
//
|
||||
// Only a declaration from the mesh converges a node. A carried bundle never says a node is adopted
|
||||
// — it cannot — so its silence is not the controller's word that the node was converged, and an
|
||||
// adopted node re-applying its bundle keeps the firewall it was found with.
|
||||
//
|
||||
// Returned is what this apply did about the found firewall, for the report; empty when the machine
|
||||
// has none or is not converged.
|
||||
func retireFirewall(ctx context.Context, d *declaration.Declaration, origin string, known *store.State,
|
||||
run Runner, log func(string)) error {
|
||||
run Runner, log func(string)) (string, error) {
|
||||
rec := known.Firewall
|
||||
if origin != store.OriginDeclared || d.Adoption != nil || rec == nil || rec.Kind != string(firewall.UFW) || !rec.WasActive ||
|
||||
rec.DisabledByMesh {
|
||||
return nil
|
||||
if origin != store.OriginDeclared || d.Adoption != nil || rec == nil || rec.Kind != string(firewall.UFW) || !rec.WasActive {
|
||||
return "", nil
|
||||
}
|
||||
active := firewall.Active(ctx, run)
|
||||
if !active && !(rec.Forward != nil && !rec.DisabledByMesh) {
|
||||
// Inactive, and either the mesh's doing already or nobody's recorded here: said as found,
|
||||
// never as done (issue 143's second fault). A retirement the mesh began and did not finish —
|
||||
// the forward policy recorded, ufw down, the restore failed — is the one inactive state that
|
||||
// is still the mesh's to complete, below.
|
||||
if rec.RetiredBy == "" {
|
||||
if rec.DisabledByMesh {
|
||||
rec.RetiredBy = firewall.RetiredByMesh
|
||||
} else {
|
||||
rec.RetiredBy = firewall.RetiredFoundSo
|
||||
log(" ufw is inactive on this converged node, and not by the mesh; recorded as found so")
|
||||
}
|
||||
}
|
||||
return "", nil
|
||||
}
|
||||
// **Nothing is retired until what replaces it is in force** (novox/hq ADR 0100). The flip
|
||||
// loads the mesh's derived filter in ufw's place; disabling ufw before that table is actually
|
||||
@@ -75,10 +98,10 @@ func retireFirewall(ctx context.Context, d *declaration.Declaration, origin stri
|
||||
// no filter at all.
|
||||
loaded, err := firewall.MeshTableLoaded(ctx, run)
|
||||
if err != nil {
|
||||
return err
|
||||
return "", err
|
||||
}
|
||||
if !loaded {
|
||||
return fmt.Errorf("this node is converged and the mesh's own filter (table %s) is not loaded on "+
|
||||
return "", fmt.Errorf("this node is converged and the mesh's own filter (table %s) is not loaded on "+
|
||||
"this machine, so ufw was left in force: retiring it would leave the machine filtering "+
|
||||
"nothing. Assign a filter module to this node, or return it to adopted", firewall.MeshTable)
|
||||
}
|
||||
@@ -88,11 +111,17 @@ func retireFirewall(ctx context.Context, d *declaration.Declaration, origin stri
|
||||
rec.Forward = firewall.ForwardPolicies(ctx, run)
|
||||
}
|
||||
if err := firewall.Disable(ctx, run, rec.Forward); err != nil {
|
||||
return err
|
||||
return "", err
|
||||
}
|
||||
again := rec.DisabledByMesh || rec.RetiredBy != ""
|
||||
rec.DisabledByMesh = true
|
||||
rec.RetiredBy = firewall.RetiredByMesh
|
||||
if again {
|
||||
log(" disabled ufw again: it had been enabled since the mesh retired it; this node is converged and filtered by the mesh")
|
||||
return "disabled again: ufw had been enabled since the mesh retired it", nil
|
||||
}
|
||||
log(" disabled ufw: this node is converged and filtered by the mesh; ufw's configuration is left on disk")
|
||||
return nil
|
||||
return "disabled: this node is converged and filtered by the mesh; ufw's configuration is left on disk", nil
|
||||
}
|
||||
|
||||
// applyOpening makes one opening true through the firewall found here.
|
||||
|
||||
@@ -189,13 +189,33 @@ func TestConvergingRetiresTheFoundFirewallAndReturningRestoresIt(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// Converged again: nothing more to retire.
|
||||
// Converged again: nothing more to retire — the node asks ufw whether it is in force, which is
|
||||
// what keeps convergence a state rather than a step taken once (novox/hq ADR 0168), and touches
|
||||
// nothing else.
|
||||
u.asked = nil
|
||||
if _, state, err = applyWith(t, converged, state, u.run); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if u.index("ufw") >= 0 {
|
||||
t.Errorf("a converged node kept talking to a retired ufw: %v", u.asked)
|
||||
for _, a := range u.asked {
|
||||
if strings.HasPrefix(a, "ufw") && a != "ufw status" {
|
||||
t.Errorf("a converged node kept talking to a retired ufw: %v", u.asked)
|
||||
}
|
||||
}
|
||||
if state.Firewall.RetiredBy != "mesh" {
|
||||
t.Errorf("the record does not say the mesh retired it: %+v", state.Firewall)
|
||||
}
|
||||
// Enabled again by a hand: retired again, and said.
|
||||
u.active = true
|
||||
u.asked = nil
|
||||
report, state, err := applyWith(t, converged, state, u.run)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if u.active || u.index("ufw disable") < 0 {
|
||||
t.Fatalf("ufw enabled again on a converged node was not retired again: %v", u.asked)
|
||||
}
|
||||
if !strings.Contains(report.Firewall, "disabled again") {
|
||||
t.Errorf("retiring it again was not said: %q", report.Firewall)
|
||||
}
|
||||
|
||||
// Returned to adopted: ufw is enabled before the opening is converged through it.
|
||||
|
||||
Reference in New Issue
Block a user