Prove a machine filters what it was told to and nothing else
Written and loaded are different things, and loaded and enforcing are different again. The test opens two ports on a machine, declares one of them, and checks from the other machine that the declared one answers and the undeclared one does not — then removes the module and checks the port closes with nobody editing a rule. The base image gains nftables, read back through `nft --version` like the other three: a machine that cannot load a rule set applies the mesh's filtering, reports success and filters nothing, which is the exact fault the derivation exists to remove. Two earlier tests were asking for things that are not there. The lab's registry drops tags when it stocks, so `registry:2` is not served and the mirror test failed with "not found" — it now uses the pinned digest, which is what a declaration carries anyway.
This commit is contained in:
@@ -24,6 +24,10 @@ images:
|
||||
- postgres:17-alpine
|
||||
- cloudamqp/lavinmq:latest
|
||||
- mesh-control:development
|
||||
# So a module can mirror one into a registry of the mesh's own. The scenario's registry serves
|
||||
# what the mesh's registry is built from — the same chicken-and-egg the bootstrap has, resolved
|
||||
# the same way.
|
||||
- registry:2
|
||||
|
||||
place:
|
||||
all: [host, runtime]
|
||||
|
||||
Reference in New Issue
Block a user