Put the workaround back where the container is not the mesh's
The mesh gives its names to the containers it declares. This one is started by the test with `docker run` — nothing declared it, so nothing configured it, and removing the workaround here was claiming a reach the change does not have. The boundary is the right one: a container somebody runs by hand is not the mesh's to configure. Reaching into every container on a machine, declared or not, is what a resolver in resolv.conf would be for — and that remains the case for wanting one. The proof that names work inside containers is its own test, against a container the mesh declared, and it passes.
This commit is contained in:
@@ -816,14 +816,23 @@ test("rotating a credential moves both ends, and the old one stops working", {
|
|||||||
// As the role the provisioner made, into the database it made. The provisioner names a role
|
// As the role the provisioner made, into the database it made. The provisioner names a role
|
||||||
// after the machine and a database after what the module asked for — which is the contract, and
|
// after the machine and a database after what the module asked for — which is the contract, and
|
||||||
// getting it wrong here made the test fail against a provisioner that had done its job.
|
// getting it wrong here made the test fail against a provisioner that had done its job.
|
||||||
// **By name, from inside the container.** This used to resolve the address on the machine and
|
// By address, resolved on the machine.
|
||||||
// pass it in, because a container does not inherit its host's /etc/hosts and the name failed as
|
//
|
||||||
// "could not translate host name" — which reads like a mesh that never wrote the name. The mesh
|
// **This container is not the mesh's.** The mesh gives its names to the containers it declares,
|
||||||
// now gives every container the names it knows, so the workaround is gone and its absence is
|
// and this one is started by the test with `docker run` — nothing declared it, so nothing
|
||||||
// the assertion.
|
// configured it. That boundary is the right one: a container somebody runs by hand is not the
|
||||||
|
// mesh's to configure, and reaching into every container on a machine is what a resolver in
|
||||||
|
// resolv.conf would be for.
|
||||||
|
//
|
||||||
|
// So the workaround stays here, and the proof that names work inside containers is its own
|
||||||
|
// test, against a container the mesh declared.
|
||||||
|
const where = (await must("laptop",
|
||||||
|
`getent hosts anchor.internal | head -1 | cut -d' ' -f1`)).trim();
|
||||||
|
assert.match(where, /^[0-9.]+$/, `the mesh's name for anchor does not resolve here: ${where}`);
|
||||||
|
|
||||||
const login = async (password: string) =>
|
const login = async (password: string) =>
|
||||||
await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` +
|
await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` +
|
||||||
`${pinned("postgres")} psql -h anchor.internal -p 5433 -U mesh_laptop ` +
|
`${pinned("postgres")} psql -h ${where} -p 5433 -U mesh_laptop ` +
|
||||||
`-d realapp -qAt -c "select 1"`, 120_000);
|
`-d realapp -qAt -c "select 1"`, 120_000);
|
||||||
|
|
||||||
const diagnostics = async () =>
|
const diagnostics = async () =>
|
||||||
|
|||||||
Reference in New Issue
Block a user