The two-node bed stocks the packet filter's seat runtime
The filter module now serves its verbs from a runtime the mesh builds (novox/hq ADR 0170), and a bed registered its raw manifest, which the mesh refuses as unbuilt. The bed stocks mesh-runtime-nftables and the filter helper registers the module through the stocked image.
This commit is contained in:
@@ -376,11 +376,15 @@ function shellQuote(s: string): string {
|
||||
*/
|
||||
export async function deriveTheFilterOn(o: {
|
||||
machine: string; node: string; hubPort: number;
|
||||
/** The images the machines hold. Given, the filter module's runtime — the packet-filter seat's,
|
||||
* which the mesh would build (novox/hq ADR 0170) — is the stocked one, as for any catalogue
|
||||
* module a bed installs; the scenario must then stock `mesh-runtime-nftables:development`. */
|
||||
held?: HeldImage[];
|
||||
must: (machine: string, command: string, timeoutMs?: number) => Promise<string>;
|
||||
mesh: (command: string, timeoutMs?: number) => Promise<string>;
|
||||
on: (machine: string, command: string, timeoutMs?: number) => Promise<{ out: string; ok: boolean }>;
|
||||
}): Promise<string> {
|
||||
const manifest = readFileSync(catalogueManifest(FILTER_MODULE), "utf8");
|
||||
const manifest = o.held ? catalogueModule(FILTER_MODULE, o.held) : readFileSync(catalogueManifest(FILTER_MODULE), "utf8");
|
||||
await o.must(o.machine,
|
||||
`printf %s ${shellQuote(manifest)} > /tmp/${FILTER_MODULE}.json && docker cp /tmp/${FILTER_MODULE}.json mesh-controller:/${FILTER_MODULE}.json`);
|
||||
await o.mesh(`module add /${FILTER_MODULE}.json`);
|
||||
|
||||
Reference in New Issue
Block a user