A machine is as big as the scenario says, and may reach the world
Three changes, found by one failing test. The forge failed three runs in a row as "status hangs", and it was diagnosed twice as contention — real defects, fixed, and not the cause. The heartbeats told the truth in the end: every exec on anchor crawled from 15s to 105s, because eleven containers plus a database pull were running in a 1GiB machine. Starvation presents as whatever you were doing when the page-outs start, which is why it wore two other bugs' clothes first. So machine size is now the scenario's to declare — memory and cpus per machine, default unchanged. The anchor that carries the whole substrate is bigger than the laptop that joins it, and the comment on the scenario says why in terms of what lands there. `egress: true` gives a machine one extra interface on a lab-supplied NAT network, addressed by DHCP because the one address a scenario has no business choosing is on the host's side of the fence. Declared per machine and off by default: a closed scenario stays the rule (novox/hq ADR 0016), and the exception exists because a first node fetches its images before any mesh can serve them — which is now the tested path (04-ISSUES/029), and a lab that can never reach upstream cannot prove the bootstrap it exists to prove. The uplink route is metric-4096, so it never shadows a route the scenario declared. A detached machine declaring egress is refused, not ignored. And settled() treats a poll that threw as a poll that missed. An exec timeout at minute four of a wait is "could not ask", not a verdict on the machine.
This commit is contained in:
@@ -85,6 +85,31 @@ export interface Machine {
|
||||
* v6-addressed machine. Without this, v6 addressing would imply reachability.
|
||||
*/
|
||||
inbound?: "allow" | "deny";
|
||||
/**
|
||||
* Whether this machine can reach the world outside the scenario.
|
||||
*
|
||||
* **Off unless asked for.** A scenario is a closed address space, and a machine that could
|
||||
* reach anything would make every test's result depend on what else was reachable that day.
|
||||
* It is declared for the same reason an address is: so what a run proves is what the scenario
|
||||
* says, and not what the workstation happened to have.
|
||||
*
|
||||
* What it is for is the one thing a mesh genuinely cannot do without an outside: a first node
|
||||
* fetching the images it starts from, before there is any mesh to serve them
|
||||
* (novox/hq 04-ISSUES/029).
|
||||
*/
|
||||
egress?: boolean;
|
||||
/**
|
||||
* How big the machine is. Absent means the lab's default, which suits a machine running a host
|
||||
* and a handful of containers.
|
||||
*
|
||||
* Declared, because it is a fact about the machine the scenario describes — the node that runs
|
||||
* the whole substrate is bigger than the laptop that joins it, and a test that starves its
|
||||
* anchor at the default answers questions about memory pressure, not about the mesh. The forge
|
||||
* test failed three times as "status hangs" before anyone counted the containers in 1GiB
|
||||
* (novox/hq 04-ISSUES/024 is the same lesson about a different resource).
|
||||
*/
|
||||
memory?: string;
|
||||
cpus?: number;
|
||||
}
|
||||
|
||||
/** Reachability between segments, as a segmented router enforces it. Asymmetric by design. */
|
||||
|
||||
Reference in New Issue
Block a user