Written and loaded are different things, and loaded and enforcing are different again. The test opens two ports on a machine, declares one of them, and checks from the other machine that the declared one answers and the undeclared one does not — then removes the module and checks the port closes with nobody editing a rule. The base image gains nftables, read back through `nft --version` like the other three: a machine that cannot load a rule set applies the mesh's filtering, reports success and filters nothing, which is the exact fault the derivation exists to remove. Two earlier tests were asking for things that are not there. The lab's registry drops tags when it stocks, so `registry:2` is not served and the mirror test failed with "not found" — it now uses the pinned digest, which is what a declaration carries anyway.
34 lines
1007 B
YAML
34 lines
1007 B
YAML
# Two machines, one mesh.
|
|
#
|
|
# The first raises everything from the bundle its host carries and joins the mesh it made. The
|
|
# second is an ordinary node: it has a host and nothing else, and a person carries it a token.
|
|
#
|
|
# This is the first scenario where the mesh is a mesh. Everything before it proved a machine could
|
|
# talk to a control plane on its own loopback, which proves less than it looks.
|
|
scenario: two-nodes
|
|
|
|
segments:
|
|
hosting:
|
|
kind: public
|
|
cidr: [192.0.2.0/24]
|
|
|
|
machines:
|
|
anchor:
|
|
at: { segment: hosting, address: [192.0.2.10] }
|
|
inbound: allow
|
|
laptop:
|
|
at: { segment: hosting, address: [192.0.2.20] }
|
|
inbound: allow
|
|
|
|
images:
|
|
- postgres:17-alpine
|
|
- cloudamqp/lavinmq:latest
|
|
- mesh-control:development
|
|
# So a module can mirror one into a registry of the mesh's own. The scenario's registry serves
|
|
# what the mesh's registry is built from — the same chicken-and-egg the bootstrap has, resolved
|
|
# the same way.
|
|
- registry:2
|
|
|
|
place:
|
|
all: [host, runtime]
|