Files
cloud-ip-validator/configs/validator-agent.example.yaml
ayurishchevandClaude Sonnet 5.5 abbee9a08a Add self-check via control-api (self_check.methods)
control-api is hosted outside the cloud and validators reach it directly,
so it sees the floating IP as the connection's source address. New open
route GET /api/v1/agents/{id}/observed-ip returns that address (taken only
from the TCP peer; forwarding headers are ignored so a validator cannot
forge it).

The agent gets self_check.methods, a priority-ordered list of ip_echo
(unchanged) and control_api; the default stays [ip_echo]. The self-check
passes when any method confirms the address; the next method is tried on
no answer and on a mismatch. Each method has its own timeout so a hung
first method cannot starve the fallback, and control_api uses a new TCP
connection per call (a connection opened before the floating IP was
attached would keep reporting the old address).

Also: docker agent template/env, example config, docs, plan in
docs/changes, e2e script switch E2E_SELF_CHECK_METHODS, rebuilt
bin/control-api and bin/validator-agent.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-02 03:24:20 +03:00

47 lines
3.0 KiB
YAML
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Validator-agent configuration. Runs on each validator VM. validator_id
# must match one of the control-api config's `validators[].validator_id`.
validator_id: "validator_01"
control_api_url: "http://control-api.internal:8080"
# Имя переменной окружения с токеном агентов control-api (тот же, что у
# prober; CONTROL_API_AGENT_TOKEN на стороне control-api). Нужен для записи
# результатов/событий; register/heartbeat/получение задания работают без него.
# Токен отправляется только в control-api — не на ip_echo_urls и не на цели
# проверок.
control_api_token_env: "CONTROL_API_AGENT_TOKEN"
poll_interval_seconds: 5
self_check:
timeout_seconds: 10
# Способы самопроверки в порядке приоритета (допустимо: ip_echo,
# control_api); по умолчанию [ip_echo]. Самопроверка успешна, если адрес
# подтвердил любой способ: пробуются по порядку, остановка на первом
# успешном, к следующему переходим и при отсутствии ответа, и при
# несовпадении адреса. Таймаут timeout_seconds действует на каждый способ
# отдельно (зависший первый способ не лишает второй времени). control_api спрашивает у control-api, с какого адреса он видит
# это соединение; рекомендуется [control_api, ip_echo], когда control-api
# стоит вне облака и валидатор ходит к нему напрямую (через внешнюю сеть).
# Ограничение: если control-api достижим по внутренней сети облака, он
# увидит частный адрес валидатора и control_api всегда даст несовпадение —
# тогда оставьте только ip_echo (или он сработает вторым в списке).
methods: [control_api, ip_echo]
# Used by the ip_echo method. Must be a resource genuinely outside the cloud project — OpenStack only
# applies floating-IP SNAT to traffic leaving via the external network,
# so anything reachable over the project's internal network (including
# control-api itself, if it's on the same internal network) would report
# this validator's private address instead, regardless of whether the
# floating IP is correctly attached. Tried in order; falls through to the
# next URL only on error/timeout, never on a genuine mismatch. Defaults
# to these two public services if omitted.
ip_echo_urls:
- "https://api.ipify.org"
- "https://ifconfig.me/ip"
checks:
https_timeout_seconds: 10
icmp_timeout_seconds: 5
icmp_count: 3
ssh:
enabled: false
timeout_seconds: 5