Prove a service is reached by a name under the machine it runs on
Through the path an application actually takes — nsswitch, files, then DNS — because the resolv.conf module is half of what is being tested and only that path goes through it. Asking a server directly would prove less. Both machines resolve, from their own copy: a mesh where one machine answers for all of them stops resolving when that machine does, which is the arrangement this design refuses everywhere else. The manifests are read from mesh-control's examples rather than written here, so what is proven is what ships. And dnsmasq joins the base image, read back through --version like the others: a machine that cannot answer names applies the resolver data, reports success, and resolves nothing.
This commit is contained in:
@@ -78,6 +78,13 @@ export async function buildBaseImage(
|
||||
log(" installing nftables, so a machine can enforce what the mesh computed");
|
||||
await incus(["exec", BUILDER, "--", "pacman", "-S", "--noconfirm", "nftables"], 600_000);
|
||||
|
||||
// And dnsmasq, because a service is named under the machine it runs on — postgres.novox.internal
|
||||
// — and only a resolver can answer a name the mesh was never told about. Installed and NOT
|
||||
// started: whether a machine resolves for the mesh is the mesh's decision, and a lab that
|
||||
// turned it on itself would be testing its own setup.
|
||||
log(" installing dnsmasq, so a machine can answer names under another machine");
|
||||
await incus(["exec", BUILDER, "--", "pacman", "-S", "--noconfirm", "dnsmasq"], 600_000);
|
||||
|
||||
// Trust the documentation ranges as plain-HTTP registries.
|
||||
//
|
||||
// A scenario's registry is scenery inside the scenario, serving over HTTP, and a runtime
|
||||
@@ -127,6 +134,17 @@ export async function buildBaseImage(
|
||||
}
|
||||
log(` ${nft.trim()}`);
|
||||
|
||||
// The same again for dnsmasq. A machine that cannot answer names applies the mesh's resolver
|
||||
// data, reports success, and resolves nothing — the shape of fault this lab exists to catch.
|
||||
const dns = await incusOk(["exec", BUILDER, "--", "dnsmasq", "--version"], 60_000);
|
||||
if (!dns?.trim()) {
|
||||
throw new BaseImageError(
|
||||
`dnsmasq was installed in ${BUILDER} and does not answer. Publishing this would give ` +
|
||||
`every scenario a machine that cannot resolve a name under another machine.`,
|
||||
);
|
||||
}
|
||||
log(` ${dns.trim().split("\n")[0]}`);
|
||||
|
||||
// Read back from the runtime, not from the package manager. An installed package is not a
|
||||
// capability (novox/hq 04-ISSUES/007), and this is the one place to catch that — after
|
||||
// publishing, every scenario pays for it instead.
|
||||
|
||||
Reference in New Issue
Block a user