Retire the found firewall only on a converged declaration from the mesh, never on a carried apply (hq ADR 0100)
This commit is contained in:
@@ -57,10 +57,14 @@ func foundFirewall(ctx context.Context, d *declaration.Declaration, known *store
|
||||
// which is when the mesh's derived filter has taken its place. Disabled, never flushed: its
|
||||
// configuration stays on disk for a return to adopted, and the container runtime's rules are not
|
||||
// its to take.
|
||||
func retireFirewall(ctx context.Context, d *declaration.Declaration, known *store.State, run Runner,
|
||||
log func(string)) error {
|
||||
//
|
||||
// Only a declaration from the mesh converges a node. A carried bundle never says a node is adopted
|
||||
// — it cannot — so its silence is not the controller's word that the node was converged, and an
|
||||
// adopted node re-applying its bundle keeps the firewall it was found with.
|
||||
func retireFirewall(ctx context.Context, d *declaration.Declaration, origin string, known *store.State,
|
||||
run Runner, log func(string)) error {
|
||||
rec := known.Firewall
|
||||
if d.Adoption != nil || rec == nil || rec.Kind != string(firewall.UFW) || !rec.WasActive ||
|
||||
if origin != store.OriginDeclared || d.Adoption != nil || rec == nil || rec.Kind != string(firewall.UFW) || !rec.WasActive ||
|
||||
rec.DisabledByMesh {
|
||||
return nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user