Implements adoption mode for the host and the installer, per hq ADRs 0100, 0101, 0102 and 0103.
Merge first. Hosts must be upgraded before the controller sends adoption, opening, into or reload-on, because the host parses declarations strictly. Merge order: mesh-host, then mesh-controller, then mesh-catalog.
What it does:
Declarations carry the adoption state. A declaration says whether the node is adopted and which modules are taken or not yet taken. Nothing changes for a declaration without it.
Found things are held. "Found" means present with no record. On an adopted node, anything found for a module not yet taken is held until that module is taken: files (the original is kept), containers, directories, running or enabled services, containers that would mount found data, archives, processes, users, and actions inside held containers. Held things are reported and never removed. A change to them is reported, not reverted.
Openings go through the found firewall. Openings are converged through the ufw found on the machine, marked, and re-checked on every reconcile. If an existing rule already admits the opening, it counts as satisfied: the mesh adds nothing and later removes nothing. A rule ufw would merge with the mesh's that is not a plain allow refuses the opening.
The found firewall is retired only on the flip. It is disabled only on a declared, converged apply; FORWARD policies are read before disabling and restored after. Returning to adopted enables it again.
Report: held things, the firewall found, and what is reachable. A reconcile report is published only when one of these changed.
Shared files are written into, not over (ADR 0102). A file with into: json has only the mesh's keys set, and list members are added rather than replacing the list. Undeclaring gives back exactly what the file held. A service with reload-on is reloaded rather than restarted.
systemd: the host reloads unit files before restarting a service whose reflected file changed.
Written-over files are kept. Before the host writes over a file it has no record of, it keeps the original once.
Installer:
it refuses a machine in use, ignoring the operating system's own network daemons (ADR 0101);
the foundation's ports are inputs: they are checked free, rewritten in the bundle and set as node settings; the overlay range is checked;
--adopted replaces the base filter with the refusal-only guard (only traffic addressed to this machine, store/AMQP/management ports), and takes the foundation modules;
a re-run keeps the adoption state it finds on the machine.
Measured on lab machines, not imagined:
ufw rule forms, and deleting route rules;
ufw merging rules that differ only in comment or action;
ufw disable opening FORWARD;
fail2ban's tables;
a fresh machine's listeners;
the container runtime reloading its registry trust with no container restart.
Tests: go build ./... && go vet ./... && go test ./... all pass. The adoption lab bed (mesh-lab, same branch) passed 18 of 19 checks. The one failure tested the found firewall's inbound policy rather than the mesh. That check was rewritten, and the new form was verified by hand on the kept machine.
Three independent reviews were done, and every finding is fixed. Follow-ups are recorded as hq issues 085 and 086.
Implements adoption mode for the host and the installer, per hq ADRs 0100, 0101, 0102 and 0103.
**Merge first.** Hosts must be upgraded before the controller sends `adoption`, `opening`, `into` or `reload-on`, because the host parses declarations strictly. Merge order: mesh-host, then mesh-controller, then mesh-catalog.
What it does:
- **Declarations carry the adoption state.** A declaration says whether the node is adopted and which modules are taken or not yet taken. Nothing changes for a declaration without it.
- **Found things are held.** "Found" means present with no record. On an adopted node, anything found for a module not yet taken is held until that module is taken: files (the original is kept), containers, directories, running or enabled services, containers that would mount found data, archives, processes, users, and actions inside held containers. Held things are reported and never removed. A change to them is reported, not reverted.
- **Openings go through the found firewall.** Openings are converged through the ufw found on the machine, marked, and re-checked on every reconcile. If an existing rule already admits the opening, it counts as satisfied: the mesh adds nothing and later removes nothing. A rule ufw would merge with the mesh's that is not a plain allow refuses the opening.
- **The found firewall is retired only on the flip.** It is disabled only on a declared, converged apply; FORWARD policies are read before disabling and restored after. Returning to adopted enables it again.
- **Report:** held things, the firewall found, and what is reachable. A reconcile report is published only when one of these changed.
- **Shared files are written into, not over (ADR 0102).** A file with `into: json` has only the mesh's keys set, and list members are added rather than replacing the list. Undeclaring gives back exactly what the file held. A service with `reload-on` is reloaded rather than restarted.
- **systemd:** the host reloads unit files before restarting a service whose reflected file changed.
- **Written-over files are kept.** Before the host writes over a file it has no record of, it keeps the original once.
- **Installer:**
- it refuses a machine in use, ignoring the operating system's own network daemons (ADR 0101);
- the foundation's ports are inputs: they are checked free, rewritten in the bundle and set as node settings; the overlay range is checked;
- `--adopted` replaces the base filter with the refusal-only guard (only traffic addressed to this machine, store/AMQP/management ports), and takes the foundation modules;
- a re-run keeps the adoption state it finds on the machine.
Measured on lab machines, not imagined:
- ufw rule forms, and deleting route rules;
- ufw merging rules that differ only in comment or action;
- `ufw disable` opening FORWARD;
- fail2ban's tables;
- a fresh machine's listeners;
- the container runtime reloading its registry trust with no container restart.
Tests: `go build ./... && go vet ./... && go test ./...` all pass. The adoption lab bed (mesh-lab, same branch) passed 18 of 19 checks. The one failure tested the found firewall's inbound policy rather than the mesh. That check was rewritten, and the new form was verified by hand on the kept machine.
Three independent reviews were done, and every finding is fixed. Follow-ups are recorded as hq issues 085 and 086.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements adoption mode for the host and the installer, per hq ADRs 0100, 0101, 0102 and 0103.
Merge first. Hosts must be upgraded before the controller sends
adoption,opening,intoorreload-on, because the host parses declarations strictly. Merge order: mesh-host, then mesh-controller, then mesh-catalog.What it does:
into: jsonhas only the mesh's keys set, and list members are added rather than replacing the list. Undeclaring gives back exactly what the file held. A service withreload-onis reloaded rather than restarted.--adoptedreplaces the base filter with the refusal-only guard (only traffic addressed to this machine, store/AMQP/management ports), and takes the foundation modules;Measured on lab machines, not imagined:
ufw disableopening FORWARD;Tests:
go build ./... && go vet ./... && go test ./...all pass. The adoption lab bed (mesh-lab, same branch) passed 18 of 19 checks. The one failure tested the found firewall's inbound policy rather than the mesh. That check was rewritten, and the new form was verified by hand on the kept machine.Three independent reviews were done, and every finding is fixed. Follow-ups are recorded as hq issues 085 and 086.