Compare commits
4
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c171c64d3a | ||
|
|
0dc5515099 | ||
|
|
58c0e715c7 | ||
|
|
c5b229f95d |
@@ -152,7 +152,7 @@
|
|||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/var/lib/mesh-bus-conf/accounts.conf",
|
"path": "/var/lib/mesh-bus-conf/accounts.conf",
|
||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "// The first user list, carried by the installer because at genesis there is no mesh to\n// compose one. A bootstrap credential, rotated with the store's and replaced by the\n// controller's own composition from its first start onward.\naccounts {\n MESH {\n jetstream: enabled\n users = [\n { user: \"controller\", password: \"$2a$10$AHqJgOifIVbU41KmATiMhuXFs8xa7Wl2HuN4UVBCXdN2jIQzjqApy\", permissions: {\n publish: { allow: [\"$JS.API.>\", \"$JS.ACK.CONTROL.controller.>\", \"$JS.ACK.EVENTS.controller.>\", \"_INBOX.enrol.>\", \"mesh.control.>\", \"mesh.mod.*.tool.>\", \"mesh.node.>\", \"mesh.seat.mesh-build-machine.accept.>\"] }\n subscribe: { allow: [\"$JS.API.>\", \"_DELIVER.controller\", \"_DELIVER.controller.>\", \"_INBOX.controller.>\", \"mesh.control.>\", \"mesh.mod.mesh-catalog.event.catching-up\", \"mesh.mod.mesh-catalog.event.upgraded\", \"mesh.mod.gitea.event.pull.merged\", \"mesh.seat.mesh-build-machine.event.built\"] }\n allow_responses: { max: 1, ttl: \"1m\" }\n } }\n ]\n }\n}\n"
|
"content": "// The first user list, carried by the installer because at genesis there is no mesh to\n// compose one. A bootstrap credential, rotated with the store's and replaced by the\n// controller's own composition from its first start onward.\naccounts {\n MESH {\n jetstream: enabled\n users = [\n { user: \"controller\", password: \"$2a$10$AHqJgOifIVbU41KmATiMhuXFs8xa7Wl2HuN4UVBCXdN2jIQzjqApy\", permissions: {\n publish: { allow: [\"$JS.API.>\", \"$JS.ACK.CONTROL.controller.>\", \"$JS.ACK.EVENTS.controller.>\", \"_INBOX.enrol.>\", \"mesh.control.>\", \"mesh.mod.*.tool.>\", \"mesh.node.>\", \"mesh.seat.mesh-build-machine.accept.>\", \"mesh.seat.mesh-controller.event.applied\", \"mesh.seat.mesh-controller.event.built-before\", \"mesh.seat.mesh-controller.event.refused\"] }\n subscribe: { allow: [\"$JS.API.>\", \"_DELIVER.controller\", \"_DELIVER.controller.>\", \"_INBOX.controller.>\", \"mesh.control.>\", \"mesh.mod.mesh-catalog.event.catching-up\", \"mesh.mod.mesh-catalog.event.upgraded\", \"mesh.mod.gitea.event.pull.merged\", \"mesh.seat.mesh-build-machine.event.built\"] }\n allow_responses: { max: 1, ttl: \"1m\" }\n } }\n ]\n }\n}\n"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "broker",
|
"id": "broker",
|
||||||
|
|||||||
+12
-6
@@ -2281,16 +2281,22 @@ func meshMadeUnits(known store.State) map[string]bool {
|
|||||||
|
|
||||||
// moduleOf is the module a declared resource belongs to.
|
// moduleOf is the module a declared resource belongs to.
|
||||||
//
|
//
|
||||||
// The mesh composes a module's resource ids as `<module>.<id>`, so the part before the first dot is
|
// The mesh composes a module's resource ids as `<module>.<its own id>`, and **a module's name may
|
||||||
// the module. False for what the mesh declares in its own right — a guard, an opening, the adoption's
|
// contain a dot** — `novox.be` is one on this mesh — while a resource's own id never does. So the
|
||||||
// own resources — which belongs to no module, and whose gate is therefore the machine's.
|
// owner is everything before the *last* dot; reading to the first one would make `novox.be.server`
|
||||||
|
// belong to a module called "novox", and a gate would then skip whatever else happened to start that
|
||||||
|
// way.
|
||||||
|
//
|
||||||
|
// False for what the mesh declares in its own right: the foundation's resources carry no dot at all,
|
||||||
|
// and the adoption's are named for the mesh rather than for a module. Both belong to no module, and
|
||||||
|
// their gate is therefore the machine's.
|
||||||
func moduleOf(identity string) (string, bool) {
|
func moduleOf(identity string) (string, bool) {
|
||||||
if strings.HasPrefix(identity, declaration.AdoptionPrefix) {
|
if strings.HasPrefix(identity, declaration.AdoptionPrefix) {
|
||||||
return "", false
|
return "", false
|
||||||
}
|
}
|
||||||
module, _, ok := strings.Cut(identity, ".")
|
at := strings.LastIndex(identity, ".")
|
||||||
if !ok || module == "" {
|
if at <= 0 {
|
||||||
return "", false
|
return "", false
|
||||||
}
|
}
|
||||||
return module, true
|
return identity[:at], true
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -343,7 +343,7 @@ func TestAFailedStepGatesItsModuleAndNotTheMachine(t *testing.T) {
|
|||||||
return "", nil
|
return "", nil
|
||||||
}
|
}
|
||||||
d := parseTrusted(t, `{"declaration":1,"resources":[
|
d := parseTrusted(t, `{"declaration":1,"resources":[
|
||||||
{"id":"mesh-catalog.runtime.prepare","type":"container","name":"catalogue-prepare","image":"`+pinned+`","run-once":true},
|
{"id":"mesh-catalog.runtime-prepare","type":"container","name":"catalogue-prepare","image":"`+pinned+`","run-once":true},
|
||||||
{"id":"mesh-catalog.runtime","type":"container","name":"catalogue","image":"`+pinned+`"},
|
{"id":"mesh-catalog.runtime","type":"container","name":"catalogue","image":"`+pinned+`"},
|
||||||
{"id":"gitea.server","type":"container","name":"forge","image":"`+pinned+`"}
|
{"id":"gitea.server","type":"container","name":"forge","image":"`+pinned+`"}
|
||||||
]}`)
|
]}`)
|
||||||
@@ -374,3 +374,27 @@ func TestAFailedStepGatesItsModuleAndNotTheMachine(t *testing.T) {
|
|||||||
t.Errorf("the report does not say what was not attempted: %q", skipped)
|
t.Errorf("the report does not say what was not attempted: %q", skipped)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestAResourcesOwnerIsReadToTheLastDot(t *testing.T) {
|
||||||
|
// **A module's name may contain a dot.** `novox.be` is one on this mesh, so reading a resource's
|
||||||
|
// owner to the first dot would make its resources belong to something called "novox" — and a gate
|
||||||
|
// would skip whatever else happened to start that way. A resource's own id never contains one,
|
||||||
|
// which is what makes the last dot the boundary.
|
||||||
|
for identity, want := range map[string]string{
|
||||||
|
"novox.be.server": "novox.be",
|
||||||
|
"mesh-catalog.runtime-prepare": "mesh-catalog",
|
||||||
|
"gitea.admin-bootstrap": "gitea",
|
||||||
|
} {
|
||||||
|
got, ours := moduleOf(identity)
|
||||||
|
if !ours || got != want {
|
||||||
|
t.Errorf("%q belongs to %q (%v), want %q", identity, got, ours, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// What the mesh declares in its own right belongs to no module: the foundation's resources carry
|
||||||
|
// no dot, and the adoption's are the mesh's.
|
||||||
|
for _, identity := range []string{"container-runtime", "store-ready", "adoption.guard", ".server"} {
|
||||||
|
if _, ours := moduleOf(identity); ours {
|
||||||
|
t.Errorf("%q was read as a module's", identity)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user