A bed that raises the foundation from the bundle derives the anchor's filter before it relies on the hub
The base ruleset (ADR 0088) admits ssh, the bus and the registry and nothing else until the mesh derives one, and the mesh derives one only where the filter module is assigned — which genesis does and these beds did not. Without it the hub's WireGuard port stayed closed, no joined node's tunnel formed, and every module dialling the anchor by its overlay name timed out fetching the broker's certificate; the model-usage bed showed it as a login that failed for a role never made.
This commit is contained in:
@@ -38,7 +38,7 @@ import { loadScenario } from "../../src/declaration/parse.ts";
|
||||
import { raise } from "../../src/lifecycle/raise.ts";
|
||||
import { destroy, exec } from "../../src/lifecycle/operate.ts";
|
||||
import { hostBinaryPath, HOST_PATH } from "../../src/lifecycle/place.ts";
|
||||
import { labIsUsable, destroyAll, foundationBundle, onTheMachine } from "./harness.ts";
|
||||
import { labIsUsable, destroyAll, foundationBundle, onTheMachine, deriveTheFilterOn } from "./harness.ts";
|
||||
import type { HeldImage } from "../../src/pinning.ts";
|
||||
|
||||
const capability = await labIsUsable();
|
||||
@@ -286,6 +286,9 @@ test("usage events are upserted into model-usage's store — latest-per-key, bot
|
||||
await mesh(`overlay place ${NODE} --site lab`);
|
||||
await mesh("assign anchor networking");
|
||||
await mesh(`assign ${NODE} networking`);
|
||||
// The anchor's derived filter, admitting the hub's port — what genesis does on the control-node,
|
||||
// and what a bed raised from the bundle must do itself (ADR 0088; see the harness).
|
||||
await deriveTheFilterOn({ machine: "anchor", node: "anchor", hubPort: 51820, must, mesh, on });
|
||||
|
||||
await addIssueAssign("postgres", postgresManifest);
|
||||
await addIssueAssign("model-usage", modelUsageManifest);
|
||||
|
||||
Reference in New Issue
Block a user