Adoption mode: a node in use is adopted before it is converged (hq ADR 0100–0103) #20
@@ -103,8 +103,11 @@ type AdoptedRewrite struct {
|
||||
}
|
||||
|
||||
// RewriteAdopted makes the produced bundle one for an adopted machine: the foundation's own filter
|
||||
// taken out, and the mesh's guard put in its place, guarding the store's and the broker's
|
||||
// management ports on this node. The nftables package stays: the guard is loaded with it, and
|
||||
// taken out, and the mesh's guard put in its place, guarding on this node the store's port, the
|
||||
// broker's management port and the broker's plaintext port. The last is published on every
|
||||
// interface and the foundation's filter admits it from the private network only, so a found
|
||||
// firewall that filters only incoming traffic would leave it reachable from anywhere (novox/hq ADR
|
||||
// 0103). Every one is a port of a module genesis takes. The nftables package stays: the guard is loaded with it, and
|
||||
// installing a package loads no table. Openings are not the bundle's — the first push declares
|
||||
// them, once there is a controller to derive them.
|
||||
func RewriteAdopted(r *Rewritten, p FoundationPorts) (AdoptedRewrite, error) {
|
||||
@@ -122,11 +125,12 @@ func RewriteAdopted(r *Rewritten, p FoundationPorts) (AdoptedRewrite, error) {
|
||||
out.Removed = append(out.Removed, id)
|
||||
}
|
||||
|
||||
out.Guarded = []int{p.Store, p.Management}
|
||||
out.Guarded = []int{p.Store, p.Management, p.AMQP}
|
||||
var text bytes.Buffer
|
||||
text.WriteString(",\n // The mesh's guard (novox/hq ADR 0100): this machine is adopted, so its own firewall\n" +
|
||||
" // stays in force and the foundation's filter is not loaded. The guard only refuses: the\n" +
|
||||
" // store's and the broker's management ports, except from the machine and the private network.")
|
||||
" // store's port and the broker's management and plaintext ports, except from the machine and\n" +
|
||||
" // the private network.")
|
||||
for _, res := range guardResources(out.Guarded) {
|
||||
var one bytes.Buffer
|
||||
enc := json.NewEncoder(&one)
|
||||
|
||||
@@ -70,7 +70,7 @@ func TestTheGuardRefusesOnlyWhatIsAddressedToThisMachine(t *testing.T) {
|
||||
|
||||
func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) {
|
||||
r := producedBundle(t)
|
||||
p := FoundationPorts{Store: 5433, Management: 15673}
|
||||
p := FoundationPorts{Store: 5433, Management: 15673, AMQP: 5773}
|
||||
if _, err := RewritePorts(&r, p, ""); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
@@ -101,7 +101,9 @@ func TestAnAdoptedBundleLoadsNoDroppingTableAndExactlyTheGuard(t *testing.T) {
|
||||
if len(guards) != 1 {
|
||||
t.Fatalf("%d guard table(s)", len(guards))
|
||||
}
|
||||
if !strings.Contains(guards[0].Content, "tcp dport { 5433, 15673 } drop") {
|
||||
// The store's, the broker's plaintext and its management port: each one the filter admits
|
||||
// from the private network only (novox/hq ADR 0103).
|
||||
if !strings.Contains(guards[0].Content, "tcp dport { 5433, 5773, 15673 } drop") {
|
||||
t.Errorf("the guard does not refuse this node's ports: %s", guards[0].Content)
|
||||
}
|
||||
if strings.Count(guards[0].Content, "accept") != 1 || !strings.Contains(guards[0].Content, "policy accept") {
|
||||
|
||||
Reference in New Issue
Block a user