Add the mesh's members to a list found in a file written into, and take back only those (hq ADR 0102)

This commit is contained in:
2026-09-22 18:27:51 +02:00
parent 48a8f4cf9d
commit facf6af46a
3 changed files with 224 additions and 9 deletions
+73 -3
View File
@@ -56,8 +56,8 @@ func TestWritingIntoKeepsEveryKeyTheMachineHad(t *testing.T) {
if fmt.Sprint(o["log-opts"]) != "map[max-size:10m]" {
t.Errorf("the machine's logging settings were not kept: %v", o)
}
if fmt.Sprint(o["insecure-registries"]) != "[10.42.0.1:5000]" {
t.Errorf("the mesh's key was not written: %v", o)
if fmt.Sprint(o["insecure-registries"]) != "[192.0.2.7:5000 10.42.0.1:5000]" {
t.Errorf("the mesh's member was not added beside the machine's own: %v", o)
}
if info, _ := os.Stat(path); info.Mode().Perm() != 0o600 {
t.Errorf("the machine's file mode was changed to %o", info.Mode().Perm())
@@ -179,7 +179,7 @@ func TestAFileWrittenIntoIsNeverHeldOnAnAdoptedNode(t *testing.T) {
t.Errorf("something was held: %+v", state.Held)
}
o := readObject(t, path)
if o["data-root"] != "/srv/docker" || fmt.Sprint(o["insecure-registries"]) != "[10.42.0.1:5000]" {
if o["data-root"] != "/srv/docker" || fmt.Sprint(o["insecure-registries"]) != "[192.0.2.7:5000 10.42.0.1:5000]" {
t.Errorf("the adopted node's file was not written into: %v", o)
}
}
@@ -211,3 +211,73 @@ func somethingElse(t *testing.T) *declaration.Declaration {
{"id":"other","type":"directory","path":%q}
]}`, filepath.Join(t.TempDir(), "other")))
}
func TestAListIsAddedToNeverReplaced(t *testing.T) {
// The predecessor's own trusted registries are kept; the mesh adds its own and, undeclared,
// takes back only what it added (novox/hq ADR 0102).
path := filepath.Join(t.TempDir(), "daemon.json")
_ = os.WriteFile(path, []byte(`{"insecure-registries":["192.0.2.7:5000","10.42.0.9:5000"]}`), 0o644)
// 10.42.0.9 is declared too, and was already the machine's: it is never the mesh's to remove.
d := parse(t, intoDecl(t, path, `{"insecure-registries":["10.42.0.1:5000","10.42.0.9:5000"]}`))
_, state, err := Apply(context.Background(), archHost(t), d, store.State{}, store.OriginDeclared, nil, nil, nil)
if err != nil {
t.Fatal(err)
}
if got := fmt.Sprint(readObject(t, path)["insecure-registries"]); got != "[192.0.2.7:5000 10.42.0.9:5000 10.42.0.1:5000]" {
t.Fatalf("the list after writing into it: %s", got)
}
rec, _ := state.Find("networking.registry-trust")
if added := rec.Into.Added["insecure-registries"]; len(added) != 1 || canonical(added[0]) != `"10.42.0.1:5000"` {
t.Errorf("recorded as added: %s", added)
}
// The predecessor adds a member of its own: not the mesh's drift.
o := readObject(t, path)
o["insecure-registries"] = append(o["insecure-registries"].([]any), "198.51.100.3:5000")
raw, _ := json.Marshal(o)
_ = os.WriteFile(path, raw, 0o644)
report, state, err := Apply(context.Background(), archHost(t), d, state, store.OriginDeclared, nil, nil, nil)
if err != nil {
t.Fatal(err)
}
if got := report.Outcomes[0].Action; got != "unchanged" {
t.Errorf("a member the machine added was taken for drift: %q", got)
}
// Somebody takes the mesh's member out: that is drift, and it is put back.
o = readObject(t, path)
o["insecure-registries"] = []any{"192.0.2.7:5000", "10.42.0.9:5000", "198.51.100.3:5000"}
raw, _ = json.Marshal(o)
_ = os.WriteFile(path, raw, 0o644)
report, state, err = Apply(context.Background(), archHost(t), d, state, store.OriginDeclared, nil, nil, nil)
if err != nil {
t.Fatal(err)
}
if got := report.Outcomes[0].Action; got != "corrected" {
t.Errorf("the mesh's member removed by hand was %q", got)
}
// Undeclared: only the member the mesh added goes.
if _, _, err := Apply(context.Background(), archHost(t), somethingElse(t), state, store.OriginDeclared, nil, nil, nil); err != nil {
t.Fatal(err)
}
if got := fmt.Sprint(readObject(t, path)["insecure-registries"]); got != "[192.0.2.7:5000 10.42.0.9:5000 198.51.100.3:5000]" {
t.Errorf("undeclaring took more than the mesh added: %s", got)
}
}
func TestAListTheMeshCreatedGoesWhenEmptied(t *testing.T) {
path := filepath.Join(t.TempDir(), "daemon.json")
_ = os.WriteFile(path, []byte(`{"data-root":"/srv/docker"}`), 0o644)
d := parse(t, intoDecl(t, path, `{"insecure-registries":["10.42.0.1:5000"]}`))
_, state, err := Apply(context.Background(), archHost(t), d, store.State{}, store.OriginDeclared, nil, nil, nil)
if err != nil {
t.Fatal(err)
}
if _, _, err := Apply(context.Background(), archHost(t), somethingElse(t), state, store.OriginDeclared, nil, nil, nil); err != nil {
t.Fatal(err)
}
if o := readObject(t, path); fmt.Sprint(o) != "map[data-root:/srv/docker]" {
t.Errorf("the key the mesh created was not removed: %v", o)
}
}