Put the workaround back where the container is not the mesh's

The mesh gives its names to the containers it declares. This one is started by
the test with `docker run` — nothing declared it, so nothing configured it, and
removing the workaround here was claiming a reach the change does not have.

The boundary is the right one: a container somebody runs by hand is not the
mesh's to configure. Reaching into every container on a machine, declared or
not, is what a resolver in resolv.conf would be for — and that remains the
case for wanting one.

The proof that names work inside containers is its own test, against a
container the mesh declared, and it passes.
This commit is contained in:
2026-08-31 11:28:38 +02:00
parent 4726a51986
commit 8bc5f498cd
+15 -6
View File
@@ -816,14 +816,23 @@ test("rotating a credential moves both ends, and the old one stops working", {
// As the role the provisioner made, into the database it made. The provisioner names a role // As the role the provisioner made, into the database it made. The provisioner names a role
// after the machine and a database after what the module asked for — which is the contract, and // after the machine and a database after what the module asked for — which is the contract, and
// getting it wrong here made the test fail against a provisioner that had done its job. // getting it wrong here made the test fail against a provisioner that had done its job.
// **By name, from inside the container.** This used to resolve the address on the machine and // By address, resolved on the machine.
// pass it in, because a container does not inherit its host's /etc/hosts and the name failed as //
// "could not translate host name" — which reads like a mesh that never wrote the name. The mesh // **This container is not the mesh's.** The mesh gives its names to the containers it declares,
// now gives every container the names it knows, so the workaround is gone and its absence is // and this one is started by the test with `docker run` — nothing declared it, so nothing
// the assertion. // configured it. That boundary is the right one: a container somebody runs by hand is not the
// mesh's to configure, and reaching into every container on a machine is what a resolver in
// resolv.conf would be for.
//
// So the workaround stays here, and the proof that names work inside containers is its own
// test, against a container the mesh declared.
const where = (await must("laptop",
`getent hosts anchor.internal | head -1 | cut -d' ' -f1`)).trim();
assert.match(where, /^[0-9.]+$/, `the mesh's name for anchor does not resolve here: ${where}`);
const login = async (password: string) => const login = async (password: string) =>
await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` + await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` +
`${pinned("postgres")} psql -h anchor.internal -p 5433 -U mesh_laptop ` + `${pinned("postgres")} psql -h ${where} -p 5433 -U mesh_laptop ` +
`-d realapp -qAt -c "select 1"`, 120_000); `-d realapp -qAt -c "select 1"`, 120_000);
const diagnostics = async () => const diagnostics = async () =>