The host says what filters the machine, with owners, and keeps the found firewall retired on every converged apply (hq ADR 0168)
Every table and chain that refuses traffic is reported with whose it is: the mesh's, the found firewall's, the container runtime's own, a ban, or other — the runtime's user chain is other, which is where both predecessors kept their rules, in the legacy filter on one machine and invisible to the mesh. Adoption's threshold does not move; a converged machine's report grows by its filters and its found firewall's state. Convergence is a state the host keeps: a found firewall enabled again is retired again and said; a reconcile that finds it inactive records that it was found so, never that the mesh did it; a step skipped after a failed apply is said. A retirement the mesh began and did not finish is finished. Fixtures are rulesets captured from three machines of the first mesh.
This commit is contained in:
@@ -110,6 +110,17 @@ type Report struct {
|
||||
// and the mesh's up in its place, and where the found configuration's original was kept.
|
||||
Tunnel *CarriedTunnel `json:"tunnel,omitempty"`
|
||||
|
||||
// Filters is what filters this machine now, every table and chain that refuses traffic with its
|
||||
// owner — the mesh's, the found firewall's, the container runtime's own, a ban list, or other
|
||||
// (novox/hq ADR 0168). Every node reports it, adopted or converged, so the mesh can say
|
||||
// truthfully what filters a converged machine and name what it did not write.
|
||||
Filters []Filter `json:"filters,omitempty"`
|
||||
|
||||
// FoundFirewall is the state of the firewall a converged machine was found with: whether it is
|
||||
// in force now, and how it came to be inactive — the mesh disabled it, or a reconcile found it so
|
||||
// (ADR 0168). Nil on a machine found with none, and on an adopted one, where Firewall says it.
|
||||
FoundFirewall *FoundFirewall `json:"found_firewall,omitempty"`
|
||||
|
||||
// Strays is what runs on the machine that the mesh neither wrote nor holds (novox/hq ADR
|
||||
// 0163): containers nobody declared and nobody holds, the ones a cutover leaves behind.
|
||||
Strays []Stray `json:"strays,omitempty"`
|
||||
@@ -233,3 +244,18 @@ type Reach struct {
|
||||
Published bool `json:"published,omitempty"`
|
||||
ContainerPort int `json:"container-port,omitempty"`
|
||||
}
|
||||
|
||||
// A Filter is one place on the machine that refuses traffic, with its owner (novox/hq ADR 0168):
|
||||
// the same shape the host's firewall package reads, carried as data.
|
||||
type Filter struct {
|
||||
Where string `json:"where"`
|
||||
Owner string `json:"owner"`
|
||||
Refuses string `json:"refuses"`
|
||||
}
|
||||
|
||||
// FoundFirewall is the state of a converged machine's found firewall (ADR 0168).
|
||||
type FoundFirewall struct {
|
||||
Kind string `json:"kind"`
|
||||
Active bool `json:"active"`
|
||||
RetiredBy string `json:"retired_by,omitempty"`
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user