The host says what filters the machine, with owners, and keeps the found firewall retired on every converged apply (hq ADR 0168)
Every table and chain that refuses traffic is reported with whose it is: the mesh's, the found firewall's, the container runtime's own, a ban, or other — the runtime's user chain is other, which is where both predecessors kept their rules, in the legacy filter on one machine and invisible to the mesh. Adoption's threshold does not move; a converged machine's report grows by its filters and its found firewall's state. Convergence is a state the host keeps: a found firewall enabled again is retired again and said; a reconcile that finds it inactive records that it was found so, never that the mesh did it; a step skipped after a failed apply is said. A retirement the mesh began and did not finish is finished. Fixtures are rulesets captured from three machines of the first mesh.
This commit is contained in:
@@ -189,13 +189,33 @@ func TestConvergingRetiresTheFoundFirewallAndReturningRestoresIt(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// Converged again: nothing more to retire.
|
||||
// Converged again: nothing more to retire — the node asks ufw whether it is in force, which is
|
||||
// what keeps convergence a state rather than a step taken once (novox/hq ADR 0168), and touches
|
||||
// nothing else.
|
||||
u.asked = nil
|
||||
if _, state, err = applyWith(t, converged, state, u.run); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if u.index("ufw") >= 0 {
|
||||
t.Errorf("a converged node kept talking to a retired ufw: %v", u.asked)
|
||||
for _, a := range u.asked {
|
||||
if strings.HasPrefix(a, "ufw") && a != "ufw status" {
|
||||
t.Errorf("a converged node kept talking to a retired ufw: %v", u.asked)
|
||||
}
|
||||
}
|
||||
if state.Firewall.RetiredBy != "mesh" {
|
||||
t.Errorf("the record does not say the mesh retired it: %+v", state.Firewall)
|
||||
}
|
||||
// Enabled again by a hand: retired again, and said.
|
||||
u.active = true
|
||||
u.asked = nil
|
||||
report, state, err := applyWith(t, converged, state, u.run)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if u.active || u.index("ufw disable") < 0 {
|
||||
t.Fatalf("ufw enabled again on a converged node was not retired again: %v", u.asked)
|
||||
}
|
||||
if !strings.Contains(report.Firewall, "disabled again") {
|
||||
t.Errorf("retiring it again was not said: %q", report.Firewall)
|
||||
}
|
||||
|
||||
// Returned to adopted: ufw is enabled before the opening is converged through it.
|
||||
|
||||
Reference in New Issue
Block a user