The token says what the mesh calls this machine
Found by raising a mesh end to end for the first time. Enrolment's own help says the token "is the only thing it needs", and it also needed --name, with no default. Without it the failure is: cannot reach the broker at 192.0.2.10:5671 as : username or password not allowed An empty username, and nothing about the cause. The node cannot work its own name out. The broker account it authenticates as is named after it and exists before this machine has been told anything, so the name has to arrive with the rest. It is not a secret and the issuer already knows it. --name stays, as an override for a token issued before the name travelled in one, and says so when it is needed rather than failing at the broker. Also corrects the bundle example, which claimed to stop before the control plane runs and has raised one for some time. A comment about what something does not do is a comment nobody updates.
This commit is contained in:
@@ -377,3 +377,22 @@ func TestASealingKeyOnDiskSurvivesATrailingNewline(t *testing.T) {
|
||||
t.Fatalf("a round trip through the disk changed the key")
|
||||
}
|
||||
}
|
||||
|
||||
func TestATokenSaysWhatTheMeshCallsThisMachine(t *testing.T) {
|
||||
// The node cannot work its own name out. The broker account it authenticates as is named
|
||||
// after it and exists before this machine has been told anything — so without the name in the
|
||||
// token, enrolment is a connection refused with an empty username, which names nothing about
|
||||
// the cause. That is exactly how the first end-to-end raise went.
|
||||
raw := base64.RawURLEncoding.EncodeToString([]byte(
|
||||
`{"v":1,"node":"anchor","broker":"192.0.2.10:5671",` +
|
||||
`"fingerprint":"sha256:` + strings.Repeat("ab", 32) + `",` +
|
||||
`"signer":"` + base64.StdEncoding.EncodeToString(make([]byte, 32)) + `",` +
|
||||
`"secret":"a-one-time-secret"}`))
|
||||
token, err := ParseToken(raw)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if token.Node != "anchor" {
|
||||
t.Fatalf("the name did not survive the token: %q", token.Node)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -18,7 +18,14 @@ import (
|
||||
// so they are held together by a test on each side asserting the exact field names rather than by
|
||||
// a shared type. If a field is renamed here and not there, that test fails on both sides.
|
||||
type Token struct {
|
||||
Version int `json:"v"`
|
||||
Version int `json:"v"`
|
||||
|
||||
// Node is what the mesh calls this machine, and it arrives here because the node cannot work
|
||||
// it out. The broker account it must authenticate as is named after it, so it has to be known
|
||||
// before the mesh can say anything — and without it enrolment is a connection refused with an
|
||||
// empty username, which names nothing.
|
||||
Node string `json:"node,omitempty"`
|
||||
|
||||
Broker string `json:"broker,omitempty"`
|
||||
Fingerprint string `json:"fingerprint,omitempty"`
|
||||
Signer []byte `json:"signer,omitempty"`
|
||||
|
||||
Reference in New Issue
Block a user