fix public ip selfcheck logic

This commit is contained in:
ayurishchev committed 2026-08-21 11:04:49 +03:00
1 parent a6f9646da5
commit 67adc6670e
18 files changed
+209 -90

No files matched your search

+24 -4
View File
@@ -1,12 +1,24 @@
// Command httpstub is a trivial "always 200 OK" HTTP server used only by
// scripts/run-local-e2e.sh, standing in for the real internet targets
// (hub.docker.com, github.com, packages.ubuntu.com) so the offline
// end-to-end harness needs no real internet access.
// Command httpstub is a trivial local HTTP server used only by
// scripts/run-local-e2e.sh, standing in for two kinds of real internet
// resources so the offline end-to-end harness needs no real internet
// access:
// - "/" always returns 200 OK — stands in for the real outbound egress
// targets (hub.docker.com, github.com, packages.ubuntu.com).
// - "/ip" echoes the caller's remote address as plain text — stands in
// for the external IP-echo service the validator-agent's self-check
// queries in production (see internal/agentcore.detectPublicIP and
// config.SelfCheckCfg.IPEchoURLs). Because httpstub runs locally, this
// only produces a meaningful self-check signal in the harness because
// the "floating IP" under test is itself the loopback address the
// caller genuinely connects from — it is not a stand-in for OpenStack's
// SNAT behavior.
package main
import (
"flag"
"fmt"
"log"
"net"
"net/http"
)
@@ -18,6 +30,14 @@ func main() {
w.WriteHeader(http.StatusOK)
_, _ = w.Write([]byte("stub ok\n"))
})
http.HandleFunc("/ip", func(w http.ResponseWriter, r *http.Request) {
host, _, err := net.SplitHostPort(r.RemoteAddr)
if err != nil {
host = r.RemoteAddr
}
w.Header().Set("Content-Type", "text/plain")
fmt.Fprintln(w, host)
})
log.Printf("httpstub listening on %s", *addr)
log.Fatal(http.ListenAndServe(*addr, nil))
}
+6
View File
@@ -102,6 +102,12 @@ control_api_url: "http://127.0.0.1:28080"
poll_interval_seconds: 1
self_check:
timeout_seconds: 5
# Points at the local httpstub's /ip echo route rather than a real
# internet IP-echo service — self-check only produces a meaningful
# signal here because the "floating IP" under test (127.0.0.1) is
# genuinely the address this process connects from; there's no real
# OpenStack SNAT involved in this offline harness. See docs/LOCAL_E2E.md.
ip_echo_urls: ["http://127.0.0.1:29091/ip"]
checks:
https_timeout_seconds: 5
icmp_timeout_seconds: 3