events: an e2e test — an emitted event reaches the audit trail over the mesh's broker #2
@@ -1195,12 +1195,15 @@ test("the hub can be filtered without severing the mesh", {
|
||||
// The failure this guards against is not subtle and is very hard to recover from: a rule set
|
||||
// that closes the hub's own port takes the private network down, and the mesh's way of fixing
|
||||
// anything is to send a declaration over it.
|
||||
const rules = "/etc/mesh/hub-filter.nft";
|
||||
// Its own directory. Another module on this machine already declares /etc/mesh, and the mesh
|
||||
// refuses two modules declaring one path rather than letting the second quietly win — which it
|
||||
// did here, correctly, the first time this ran.
|
||||
const rules = "/etc/mesh-hub/filter.nft";
|
||||
await must("anchor", `printf %s '{"module":"hubfilter","version":"1",` +
|
||||
`"capabilities":["firewall"],` +
|
||||
`"filtering":{"into":"${rules}"},` +
|
||||
`"resources":[{"id":"nftables","type":"package","package":"nftables"},` +
|
||||
`{"id":"dir","type":"directory","path":"/etc/mesh","mode":"0755"},` +
|
||||
`{"id":"dir","type":"directory","path":"/etc/mesh-hub","mode":"0755"},` +
|
||||
`{"id":"unit","type":"file","path":"/etc/systemd/system/hub-filter.service",` +
|
||||
`"mode":"0644","content":"[Unit]\\nDescription=What the mesh computed for the hub\\n` +
|
||||
`[Service]\\nType=oneshot\\nRemainAfterExit=yes\\n` +
|
||||
@@ -1218,7 +1221,9 @@ test("the hub can be filtered without severing the mesh", {
|
||||
const written = await must("anchor", `cat ${rules}`);
|
||||
assert.match(written, /udp dport 51820 accept/,
|
||||
`the hub's rule set closes the private network it is the way onto:\n${written}`);
|
||||
assert.match(written, /# networking/,
|
||||
// The module that provides the private network, not the requirement it answers: `networking`
|
||||
// is the domain a module offers, and what caused a rule is the module itself.
|
||||
assert.match(written, /# mesh-wireguard — the private network/,
|
||||
`the rule does not name what caused it:\n${written}`);
|
||||
|
||||
// Loaded, and the mesh still works: a declaration reaches the other machine, which it cannot if
|
||||
|
||||
Reference in New Issue
Block a user