A taken tunnel's found configuration is retired once the take is proven (hq ADR 0119)
Kept on disk it was the take's fallback; once the mesh's interface is up in its place and a peer has handshaken with it, it is an unmaintained way back onto the network, held for ever. It is now removed from where its unit reads it, its kept original verified first and left as it is, and the hold ends. Until proven — no handshake, or wg not answering — it is kept and the report says why. The retirement is recorded apart from holds, so later applies, an undeclare, and a reassignment find it retired rather than missing, and nothing writes it back.
This commit is contained in:
@@ -21,6 +21,10 @@ type machine struct {
|
||||
asked []string
|
||||
// wgUp is what `wg show interfaces` answers: the tunnels up on the machine.
|
||||
wgUp string
|
||||
// handshakes is what `wg show <interface> latest-handshakes` answers, and handshakesFail the
|
||||
// error it fails with instead — a machine with no `wg`, say (novox/hq ADR 0119).
|
||||
handshakes string
|
||||
handshakesFail error
|
||||
|
||||
// units are service units by name, as systemd would report them; volumes are the runtime's
|
||||
// named volumes.
|
||||
@@ -101,6 +105,9 @@ func (m *machine) run(_ context.Context, name string, args ...string) (string, e
|
||||
return m.systemctl(args)
|
||||
}
|
||||
if name == "wg" {
|
||||
if len(args) > 0 && args[len(args)-1] == "latest-handshakes" {
|
||||
return m.handshakes, m.handshakesFail
|
||||
}
|
||||
return m.wgUp, nil
|
||||
}
|
||||
if name == "getent" {
|
||||
|
||||
Reference in New Issue
Block a user