A scenario is a closed address space: two raised from the same declaration hold the same addresses and never meet, which is what lets two run at once and why the lab talks to machines through the hypervisor rather than over IP. Reaching in from outside breaks that, so it is opt-in, one scenario at a time, and reversible. `connect` takes an address on the scenario's public link and writes a resolver rule answering everything under each machine's name. `disconnect` gives both back. `connected` says what is true right now, for somebody who cannot remember. It refuses rather than guessing when more than one scenario is standing — the failure being avoided is not an error but one scenario's traffic arriving in another. It also refuses when a machine's name is already answered here for something real, because connecting would point that name at the lab, and the damage would land on the real thing. Names answer with the segment address rather than the overlay one. Inside the mesh a name gives a machine's private address; from here that would need this workstation on the overlay, which is a much larger door. The segment address reaches the same machine and the same ports, which is what opening a board in a browser actually needs. Proven against a live two-node scenario: registry.internal:5000/v2/ answered 200 from this workstation, and so did a wildcard name under the same machine. Disconnect put the address back, stopped answering, and left the real mesh's own names alone. One thing measured rather than assumed: it restarts dnsmasq instead of reloading it. A reload is SIGHUP, which re-reads the hosts file and clears the cache but not the configuration — the rule was written, the reload reported success, and nothing resolved. The daemon's start time was nine days old afterwards.
15 lines
686 B
TypeScript
15 lines
686 B
TypeScript
import { test } from "node:test";
|
|
import assert from "node:assert/strict";
|
|
|
|
import { RULE } from "../src/lifecycle/connect.ts";
|
|
|
|
// The rule goes in its own file, beside the one this workstation already has.
|
|
//
|
|
// **Not into it.** The file next to this belongs to the mesh that really runs here, and it is
|
|
// generated — writing into it would be edited-away at best and would break real name resolution
|
|
// at worst. novox/hq: never edit a file something else owns.
|
|
test("the rule is its own file, not the one already there", () => {
|
|
assert.match(RULE, /^\/etc\/dnsmasq\.d\/mesh-lab\.conf$/);
|
|
assert.doesNotMatch(RULE, /hal/, "it would be writing into something else's file");
|
|
});
|